Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

38 results about "Security association" patented technology

A security association (SA) is the establishment of shared security attributes between two network entities to support secure communication. An SA may include attributes such as: cryptographic algorithm and mode; traffic encryption key; and parameters for the network data to be passed over the connection. The framework for establishing security associations is provided by the Internet Security Association and Key Management Protocol (ISAKMP). Protocols such as Internet Key Exchange (IKE) and Kerberized Internet Negotiation of Keys (KINK) provide authenticated keying material.

Systems and methods for security association enabling make-before-break-roaming (MBBR)

ActiveUS12563388B2Network topologiesConnection managementStationSecurity association
A system and method are provided for generating a pairwise transient key security association (PTKSA) by: providing a first media access control (MAC) address that is shared by multiple access points (APs), the first MAC address corresponding to an infrastructure comprising the multiple APs, and each AP of the multiple APs having a respective AP MAC address; providing a second MAC address to a station (STA); and establishing a secure link between the STA and the infrastructure using the first MAC address and the second MAC address to derive a pairwise transit key (PTK) for the secure link, wherein the secure link is between the STA and the multiple APs.
Owner:CISCO TECHNOLOGY INC

Network security situation awareness method and system based on large model and threat assessment

InactiveCN121907597ASecuring communicationHigh level techniquesLinguistic modelSecurity association
The invention relates to the technical field of network security, in particular to a network security situation awareness method and system based on a large model and threat assessment. The method comprises the following steps: firstly, acquiring and standardizing multi-modal security data in a cloud service environment in real time, distributing a behavior modal cluster for security event metadata through clustering analysis, and generating a security feature vector containing business semantics and behavior dynamic features based on a cluster center relocation technology; then constructing a local situation map reflecting asset topology and an access link by using a cloud security association model; semantic reasoning is performed on the atlas through a large language model, an attack intention is recognized, and an attack path is predicted; and finally, combining the path probability, the asset value and the vulnerability feature to quantitatively calculate a risk index, and automatically generating a response strategy. Semantic compression of massive logs is realized through modal clustering, and the calculation bottleneck of processing original data by a large model is overcome; and in combination with graph correlation and large model reasoning, the crossing from passive warning to active intention prediction is realized.
Owner:BEIJING ZHONGCHUANG HAISHENG TECHNOLOGY CO LTD

System and method for early detection of duplicate security association of IPsec tunnels

ActiveUS12598169B2Securing communicationTelecommunicationsSecurity association
In an embodiment, a method includes transmitting an initiation request from a first electronic device to a second electronic device, the initiation request being associated with a notification that the first electronic device is capable of early detection of duplicate security associations (SAs), receiving an initiation request from the second electronic device at the first electronic device, the initiation request being associated with a capability notification that the second electronic device is capable of early detection of duplicate SAs, determining a possibility of duplicate SAs by the first electronic device, transmitting responses configured to prevent duplicate SAs from the first electronic device to the second electronic device, receiving responses at the first electronic device from the second electronic device, wherein the responses indicate no duplicate SAs created by the second electronic device, and establishing a non-duplicate SA for the first and second electronic devices.
Owner:CISCO TECHNOLOGY INC

Post-quantum secure media access control security (macsec) pre-shared key auto-refresh

PendingUS20260081767A1Key distribution for secure communicationUser identity/authority verificationKey serverSecurity association
Techniques for utilizing post-quantum pre-shared key (PPK) identifiers (PPK_ID) to determine control association key(s) (CAK(s)) and / or secure association key(s) (SAK(s)) utilized in MACsec sessions are described herein. A key server (KS) and a non-key server (NKS) may advertise capabilities indicating an ability to utilize PPKs as CAKs and / or SAKs in MACsec sessions. The KS may leverage a quantum key distribution (QKD) service to determine a PPK_ID and a PPK, which may be utilized as a CAK for a MACsec session with the NKS. The PPK_ID may be transmitted to the NKS, where the NKS may retrieve the PPK from the QKD, and a new group connectivity association may be established using the PPK as the CAK. In some examples, the KS may be configured to refresh the PPK as the CAK for instantiating subsequent MACsec sessions. Additionally, the KS may be configured to distribute a SAK in a similar manner.
Owner:CISCO TECHNOLOGY INC

Wireless communication reconnection method and device, equipment and storage medium

The embodiment of the invention provides a wireless communication reconnection method and device, equipment and a storage medium, and is applied to the technical field of wireless communication. The method comprises the following steps: a wireless client sends a detection request frame to an access point, the detection request frame comprising a first state flag bit, and the first state flag bit is used for inquiring whether the access point saves a key session association (PMKSA); the access point receives the detection request frame, generates a detection response frame based on the detection request frame and sends the detection response frame to the wireless client, the detection response frame comprises a second state flag bit, and the second state flag bit is used for indicating whether the access point stores the PMKSA; the wireless client judges whether the access point stores the PMKSA or not according to the detection response frame; when the access point stores the PMKSA, initiating a connection request to the access point according to the PMKSA; and when the PMKSA is not stored in the access point, initiating an authentication request to the access point, and initiating a connection request to the access point after the authentication is passed. The method can improve the success rate and efficiency of wireless communication reconnection.
Owner:SPREADTRUM COMM (TIANJIN) INC

IKE-based path identity

PendingUS20260067277A1Securing communicationPathPingSecurity association
The present technology uses the IKE protocol to establish a path identity on both sides of a peer connection. This is achieved by using IKE to exchange local and peer device identifiers along with transport identifiers. IKE then populates the path identity into the IPsec data plane by associating it with the transmit and receive security association databases (IPsec Tx & Rx SA DB). The device's data plane can monitor traffic sent or received through these IPsec SAs by using the path identity information linked with the IPsec SAs. This allows the creation of an application-to-path monitoring record, or matching traffic to the record for purposes such as statistics collection, troubleshooting, and performance evaluation.
Owner:CISCO TECHNOLOGY INC

Enhanced processing for IPSEC flows

ActiveCN115085962BSecuring communicationSecurity associationIPsec
Embodiments of the present disclosure relate to methods, apparatuses, and computer readable storage media for processing Internet Protocol Security (IPsec) flows. One method includes determining a security association for an incoming flow, the incoming flow comprising a plurality of packets; performing pre-processing on the plurality of packets based on the security association; and in response to performing the pre-processing on at least one packet of the plurality of packets, performing parallel processing on the at least one packet of the plurality of packets.
Owner:NOKIA NETWORKS OY

Authentication and security for ultra-high reliability (UHR) roaming

PendingUS20260149965A1Security arrangementNetwork data managementSecurity associationMaster key
This disclosure provides methods, components, devices and systems for authentication and security for ultra-high reliability (UHR) roaming. Some aspects more specifically relate to devices in a seamless mobility domain (SMD), such as access point (AP) multi-link devices (MLDs) and non-AP MLDs, supporting the generation of different temporal keys (TKs) for each AP MLD. For example, the non-AP MLD may establish, via authenticator associated with the SMD, a pairwise master key security association (PMKSA) and a single pairwise transient key security association (PTKSA). Thus, the non-AP MLD may communicate with a first AP MLD (such as of multiple AP MLDs associated with the SMD) in accordance with a first pairwise transient key (PTK) and, after roaming to a second AP MLD (such as of the multiple AP MLDs), may communicate with the second AP MLD in accordance with a second PTK, where the second TK is different than the first PTK.
Owner:QUALCOMM INC

Location Data Harvesting and Pruning for Wireless Accessory Devices

PendingUS20260189875A1Security associationConnection management
Techniques are disclosed for identifying and processing beacon advertisement packets on an electronic device equipped with a wireless processor and wireless radio. An example method may include scanning for beacon advertisements, detecting a specific beacon advertisement that includes a beacon advertisement packet, and determining whether the detected packet is of a first or second type based on its structure. Upon identification of the packet as the first type, the method may further include executing a key matching operation to ascertain whether the beacon advertisement is associated with a known device. This approach enables efficient device recognition and secure association within wireless environments, enhancing connectivity management and security on electronic devices.
Owner:APPLE INC

Comprehensive congestion control and adaptive transmission optimization method based on WAPI

The invention provides a comprehensive congestion control and adaptive transmission optimization method based on WAPI, and belongs to the field of communication. The key problems that under the wireless communication environment based on the WAPI security standard in the electric power Internet of Things, network congestion is difficult to dynamically regulate and control, data transmission is prone to disorder, and a retransmission mechanism lacks intelligent adaptation are solved, and the method comprises the following steps that WAPI environment initialization and security association establishment are carried out; based on a WAPI and reinforcement learning congestion control framework, a teacher-student distillation mechanism is adopted to extract a symbol strategy, and multi-context branch agents are integrated to adapt to different network conditions, so that long-term congestion planning and dynamic rate adjustment are realized; optimizing a data packet sequence and congestion window growth coupling in multi-path transmission through ECN marking and correlation verification; running a WAPI security aware adaptive retransmission module, and dynamically selecting unicast or multicast retransmission in combination with a WAPI security mechanism; the present application is applied to WAPI.
Owner:ELECTRIC POWER RES INST STATE GRID SHANXI ELECTRIC POWER +1

Systems and methods for security association enabling make-before-break-roaming (MBBR)

PendingUS20260189902A1StationSecurity association
A system and method are provided for generating a pairwise transient key security association (PTKSA) by: providing a first media access control (MAC) address that is shared by multiple access points (APs), the first MAC address corresponding to an infrastructure comprising the multiple APs, and each AP of the multiple APs having a respective AP MAC address; providing a second MAC address to a station (STA); and establishing a secure link between the STA and the infrastructure using the first MAC address and the second MAC address to derive a pairwise transit key (PTK) for the secure link, wherein the secure link is between the STA and the multiple APs.
Owner:CISCO TECHNOLOGY INC

Method, apparatus and electronic device for identifying a cryptographic device

The application provides a method, device and electronic equipment for identifying a cryptographic device, wherein the method comprises: obtaining target encrypted traffic when a target encrypted tunnel is established, the target encrypted traffic comprising initiator encrypted traffic; identifying an initiator protocol of the initiator encrypted traffic, and parsing the initiator protocol to obtain a security association payload supported by the initiator protocol, and determining a payload fingerprint of the initiator encrypted traffic based on the security association payload; and determining, based on the payload fingerprint, a cryptographic device corresponding to a target encrypted tunnel to which the target encrypted traffic belongs. The method, device and electronic equipment for identifying a cryptographic device provided by the application utilize certain attributes of an initiator protocol in initiator encrypted traffic processed by a cryptographic device, can be associated with inherent characteristics of a corresponding cryptographic device, are not affected by a complex network and time delay, can more accurately determine a cryptographic device, and are high in identification efficiency and easy to implement.
Owner:VIEWINTECH

Apparatus and method for supporting l4s in no-3GPP access environments

The present disclosure relates to a 5G or 6G communication system for supporting a higher data transmission rate, and to a method performed by a non-3GPP interworking function (N3IWF) entity of a wireless communication system, the method comprising the steps of: receiving session management information from a session management function (SMF) entity via an access and mobility management function (AMF) entity, the session management information includes an explicit congestion notification (ECN) flag indication for supporting low latency, low loss, and scalable throughput (L4S) in non-3GPP access; determining a connection of an Internet Protocol Security (IPsec) sub-security association (SA) supporting a Quality of Service (QoS) flow of the L4S; and sending a message for requesting the IPsec sub-SA connection to the terminal.
Owner:SAMSUNG ELECTRONICS CO LTD

Dynamic bringup of secure tunneling of access-controlled network domain interconnect traffic

PCT designated stageWO2026073033A1Securing communicationRouting tableSecurity association
Methods and devices provide improved secure tunneling of interconnect traffic across access-controlled network domains, by configuring network devices according to a dynamic tunnel bringup method to discover peer network devices, establish a tunnel gateway in a security association, monitor a security association session status, and update routing and forwarding tables in accordance. A processing unit of a network device configures the network device to discover a peer network device; update a next hop in a local routing table; establish a tunnel endpoint; encapsulate an encrypted packet with a SA tag; monitor a SA session status; and advertise routing information based on a monitored SA session status.
Owner:CISCO TECHNOLOGY INC

Secure packet transmission method and related apparatus

This disclosure provides a secure packet transmission method, a method for negotiating an internet protocol security security association (IPsec SA), and a related apparatus, and is applied to a wide area network. In a scenario of crossing a plurality of segments of tunnels, an IPsec SA used for end-to-end security protection is negotiated between a first site edge and a second site edge based on a virtual routing and forwarding (VRF) granularity by extending a border gateway protocol (BGP) route. After performing security protection on a virtual private network (VPN) service packet based on the IPsec SA, the first site edge sends the packet through an overlay end-to-end tunnel between the first site edge and the second site edge, and the second site edge processes the packet based on the IPsec SA, to obtain the VPN service packet.
Owner:HUAWEI TECH CO LTD

Data transmission method and device

ActiveCN121261880AKey distribution for secure communicationInternet Key ExchangeSecurity association
The embodiment of the invention provides a data transmission method and device, and relates to the technical field of quantum communication, and the method applied to a first device in communication connection with a quantum server comprises the following steps: establishing an Internet Key Exchange Security Association (IKESA) with a second device, the second device being in communication connection with the quantum server; a key application request is sent to the quantum server, a first quantum key fed back by the quantum server is received, and the first quantum key is generated by the quantum server based on a quantum key distribution (QKD) protocol; establishing an internet protocol security association (IPSecSA) with the second equipment; and encrypting the first to-be-sent data based on the first quantum key, and sending the encrypted data to the second device through an IPSec tunnel formed after the IPSec SA is established. By applying the scheme provided by the embodiment of the invention, the security of data transmission between equipment can be improved.
Owner:NEW H3C TECH CO LTD

A Multi-Source Fusion-Based System and Method for Calculating Peak Fatigue Levels of Runners (up to 10,000 Users)

This invention provides a multi-source fusion-based system and method for calculating peak fatigue levels in runners of up to 10,000 users. The system includes a data acquisition module, a data preprocessing and fusion module, a peak fatigue calculation module, a safety early warning and coordinated intervention module, a data security and privacy protection module, and a backup data acquisition unit. The core functionality involves collecting five-dimensional, multi-source, safety-related data on runners' physiological, exercise, environmental, individual, and subjective factors through the data acquisition module. A simplified version of non-invasive electromyography (EMG) signals is introduced to identify latent muscle fatigue. A dual-layer fusion architecture of "edge + cloud" is adopted, combined with a federated learning model, to achieve deep fusion of multi-source data while protecting runner privacy, constructing a personalized dynamic fatigue threshold model. The system calculates peak fatigue levels based on a real-time safety-oriented fatigue index, implements closed-loop intervention through a four-level graded early warning mechanism linking multiple terminals, and ensures data security through three-link redundant transmission, data anonymization and encryption. The backup acquisition unit ensures full coverage of data from up to 10,000 users.
Owner:WUXI HUIPAO SPORTS CO LTD

Method and apparatus for secure key distribution

The invention relates to a method and apparatus for secure key distribution. A new approach is proposed for supporting secure key distribution between a host and a resource-constrained Ethernet bridge using MACSec, wherein the resource-constrained Ethernet bridge is hardware with multiple hardware blocks but without a processor or non-volatile storage. In the proposed method, existing hardware modules using a resource-constrained Ethernet bridge completely implement a secure key distribution protocol. First, a session encryption key is independently generated by a host and an Ethernet bridge. If the SEKs match, the host is configured to generate and distribute a security association key (SAK) to the Ethernet bridge for installation thereon. After the SAK is installed on the Ethernet bridge, a secure communication channel is established between the host and the Ethernet bridge. A secure communication channel may be used for secure communication of sensitive data collected by an Ethernet bridge from a plurality of electronic devices.
Owner:MARVELL ASIA PTE LTD

Enterprise asset equipment security situation assessment method and device based on large model agent, equipment and medium

The invention discloses an enterprise asset equipment security situation assessment method and device based on a large model agent, equipment and a medium, and relates to the technical field of computers, and the method comprises the steps: determining a target security situation awareness agent based on a security large model agent frame through employing a preset scene demand and a sandbox technology; obtaining enterprise security situation index data including equipment network flow characteristic information, equipment operation state information and equipment alarm information, performing security relevance verification on the enterprise security situation index data by using a target security situation awareness agent, and determining a training sample based on the obtained candidate index data and by using a support vector machine, and training the support vector regression model, performing security situation assessment on each to-be-tested enterprise device in the networked asset device based on the obtained target security situation assessment model, and determining the security state of the networked asset device by using the obtained overall security situation value. And limitation and hysteresis of traditional enterprise safety protection are avoided.
Owner:SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD

Key generation for a cluster of nodes within a single security association

Each computing node in a computing cluster includes at least a key generator and a cryptographic engine. The key generator implements a key derivation function and generates a first data encryption key based on the key derivation key. The key derivation key is a global security association encryption key shared by multiple nodes in the computing cluster. The first data encryption key is unique to a node pair, including a first node and a second node among multiple nodes. The cryptographic engine uses the first data encryption key to encrypt data packets.
Owner:ADVANCED MICRO DEVICES INC

Communication device initiated quality of service with service level agreement for supporting quality of service modification

A method performed by a first network node in a first network is provided for support in a second network of a quality of service, QoS, of the first network for a communication device initiated QoS modification. The method includes checking a QoS profile for a QoS flow of the first network based on a service level agreement, SLA, between the first network and the second network to determine whether the QoS flow is supported by the second network. The method further includes creating a dedicated internet protocol security, IPsec, security association, SA, for handling the QoS flow; and setting a differentiated services code point, DSCP, value of the dedicated IPsec SA according to the SLA. Methods performed by a second network node and by a communication device are also provided.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

An internet of things vulnerability security analysis method and system based on a knowledge graph

The application provides a knowledge graph-based Internet of Things vulnerability security analysis method and system. The method analyzes large-scale Internet of Things firmware files in advance, stores feature information and existing vulnerabilities obtained by analysis into a graph database, and displays on an interface. When uploading new firmware, the information obtained by unpacking and analysis is stored into the graph database, and compared with the firmware information stored in the previous graph database. The firmware with the same information is associated and displayed on the interface. When querying the firmware, the input key is compared with the existing information in the graph database, the firmware with the same information is associated and displayed on the interface. The application solves the problems of large data volume, complex logical relationship and unsuitable capture of security association in the current Internet of Things firmware analysis, can improve the efficiency of Internet of Things firmware analysis personnel in studying Internet of Things firmware information and vulnerabilities, and further improves the level of Internet of Things firmware security analysis.
Owner:INST OF SOFTWARE - CHINESE ACAD OF SCI

Session recovery mechanism

A system is described. The system includes a processing resource and a non-transitory computer-readable medium, coupled to the processing resource, having stored therein instructions that when executed by the processing resource cause the processing resource to detect an unrecognized Internet Protocol Security (IPsec) packet associated with an IP address at a first node within a cluster, retrieve one or more selector fields from the IPsec packet, query of a security policy database to determine whether a destination IP address included in the one or more retrieved selector fields matches one or more matching outbound IPsec policies associated with a destination IP address, determine whether a matching outbound IPsec policy includes an IPsec policy associated with the destination address entry and establish the first IPsec SA communication session between the first node and the client based on the outbound IPsec policy.
Owner:NETAPP INC

Secure association sharing in multi-source and multi-destination environments

PendingUS20260129030A1Securing communicationComputer networkSecurity association
This disclosure describes techniques and mechanisms for providing initialization vector (IV) uniqueness and extending rekeying windows for network devices that perform secure association sharing in multi-source and multi-destination environments. The techniques may apply to existing hardware of the network devices. The techniques may enable the network devices to execute in a non-XPN mode and establish secure tunnels corresponding to secure association sessions. The techniques may utilize software to partition extra bits included in packet headers. The network devices may perform a process to update a loop count value utilizing a portion of the extra bits, thereby exponentially extending the rekeying windows. Further, by utilizing a portion of the extra bits, the system may ensure IV uniqueness for the secure association session between network devices in the multi-source and multi-destination environment.
Owner:CISCO TECHNOLOGY INC

Dynamic data security protection method and device based on adversarial training under multi-modal large model

PendingCN121690761ABiological modelsSecuring communicationSecurity associationSecurity analytics
The invention provides a dynamic data security protection method and device based on adversarial training under a multi-modal large model, and is applied to the field of data processing. According to the method, multi-modal basic data, intelligent algorithm model information and dynamic security protection requirements are acquired, cross-source mapping of data and model vulnerability detection points is established through security association processing, risks are marked, and target association data are generated; splitting target associated data, aligning network unified multi-modal features by means of hierarchical features, and establishing a high-risk data priority cache to obtain structured security analysis data; then, a targeted protection scheme is generated according to data-model-threat association mapping, and a dynamic defense optimization model is constructed in combination with a protection effect and real-time threat feedback; and finally, processing basic data and model information by using the model, and outputting multi-modal basic data dynamic security protection information in combination with protection requirements.
Owner:FUJIAN ZHONGXIN NET SAFETY INFORMATION TECHNOLOGY CO LTD +1

Apparatus and method for signaling that a fifth generation core network does not allow establishment of a secure connection over a non-third generation partnership project access network

ActiveCN116647394BAssess restrictionNetwork topologiesSecurity associationNetworked system
Processing failure for non-3GPP access to a 5G CN is provided. An interworking function in a core network system, such as a 5G core network, attempts to establish a security association with a user equipment (UE) in an untrusted access network. When the 5G core network does not accept the security association, the UE receives a response from the core network that includes a message type indicating that non-3GPP access to the 5G core network is not allowed. Upon receiving the response message, the UE ends the session by sending a 5G stop message formatted in an extensible authentication protocol (EAP) response. The EAP response / 5G stop message includes a message ID field with a 5G stop value.
Owner:NOKIA NETWORKS OY

PMU encrypted communication exception self-healing method and system based on protocol stack state machine learning

PendingCN122372404AKey exchangeMessage length
This application relates to a PMU encrypted communication anomaly self-healing method, system, computer device, and storage medium based on protocol stack state machine learning. The method includes: when PMU encrypted communication transmits data at a preset fixed frame rate, extracting message length and arrival time to generate a protocol stack state feature sequence; constructing a baseline model based on the statistical distribution of normal states; calculating the deviation of the real-time feature sequence relative to the baseline model using a sliding window; when the deviation exceeds a threshold, comparing the dual-end encryption policy parameters to obtain a consistency judgment result; jointly analyzing the deviation and consistency results to distinguish the anomaly type; if the anomaly type is tunnel dead, sending a key exchange protocol deletion message and reconstructing the security association; if it is policy mismatch, issuing a policy correction command through the northbound interface and triggering key renegotiation. This application can distinguish the root cause of encrypted communication anomalies and repair them specifically, improving the repair efficiency of encrypted communication anomalies and the continuity of data transmission.
Owner:GUANGZHOU ZHIXUNDA INFORMATION TECH CO LTD

Authentication and security for ultra-high reliability (UHR) roaming

PCT designated stageWO2026112630A1Key distribution for secure communicationSecurity arrangementSecurity associationMaster key
This disclosure provides methods, components, devices and systems for authentication and security for ultra-high reliability (UHR) roaming. Some aspects more specifically relate to devices in a seamless mobility domain (SMD), such as access point (AP) multi-link devices (MLDs) and non-AP MLDs, supporting the generation of different temporal keys (TKs) for each AP MLD. For example, the non-AP MLD may establish, via authenticator associated with the SMD, a pairwise master key security association (PMKSA) and a single pairwise transient key security association (PTKSA). Thus, the non-AP MLD may communicate with a first AP MLD (such as of multiple AP MLDs associated with the SMD) in accordance with a first pairwise transient key (PTK) and, after roaming to a second AP MLD (such as of the multiple AP MLDs), may communicate with the second AP MLD in accordance with a second PTK, where the second TK is different than the first PTK.
Owner:QUALCOMM INC

Multi-link wireless communication connection

The present disclosure relates to multi-link wireless communication connections. A method is disclosed that can include establishing a multi-link security association between a transmitter-on-medium access control (MAC) logic entity of a transmitter and a receiver-on-MAC logic entity of a receiver. The transmitter can include one or more transmitter links. The receiver can include one or more receiver links.
Owner:MAXLINEAR INC

A processing method for network data security protection

PendingCN122640238ADigital dataSecurity association
The application relates to the field of electric digital data processing and discloses a processing method for network data security protection, which comprises the following steps: acquiring characteristic parameters of each channel in a multi-channel electric digital data stream and calculating an abnormality index according to a preset characteristic calculation rule; constructing an association array of network flow data and data access authentication logs to output a security association index; when the security association index is greater than a security response threshold, adjusting a load distribution strategy, changing an asynchronous polling task of a low abnormality degree channel into an intermittent suspension mode to release computing power resources and centrally scheduling a high abnormality degree channel; and the application can solve the problem of a large number of unresolved stacks caused by a sudden surge of multi-channel flow, avoid the generation of a memory barrier in a business system, ensure that the system maintains a low time delay combined decoupling of data flow, and guarantees the timeliness of threat interception under a heterogeneous data stream working condition.
Owner:浙江微特电子信息有限公司