Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

67 results about "Security association" patented technology

A security association (SA) is the establishment of shared security attributes between two network entities to support secure communication. An SA may include attributes such as: cryptographic algorithm and mode; traffic encryption key; and parameters for the network data to be passed over the connection. The framework for establishing security associations is provided by the Internet Security Association and Key Management Protocol (ISAKMP). Protocols such as Internet Key Exchange (IKE) and Kerberized Internet Negotiation of Keys (KINK) provide authenticated keying material.

Flow-based secure packet forwarding

Example methods and systems for flow-based secure packet forwarding are described. In one example, a first computer system may assess validity of a security token associated with a flow of one or more packets. In response to determination that the security token is valid, a security association associated with the flow and the security token may be negotiated with a second computer system. The first computer system may process a packet associated with the flow and the security token to generate an encapsulated encrypted packet by performing encryption and encapsulation based on the security association. The encapsulated encrypted packet may be forwarded towards the second computer system to cause the second computer system to perform decapsulation and decryption, and to forward a decapsulated and decrypted packet towards the destination.
Owner:VMWARE INC

Cross-platform user behavior analysis method and system based on transfer learning

The invention provides a cross-platform user behavior analysis method and system based on transfer learning, and relates to the technical field of network security, first, historical network behavior record data of a source domain security platform and real-time network behavior flow data of a target domain security platform are obtained, the historical network behavior record data comprise security behavior sequences of source domain users in different access scenes, and the real-time network behavior flow data are stored in the target domain security platform; the method comprises the following steps of: performing cross-domain security feature extraction on two types of data, constructing a cross-domain security behavior association graph, migrating source domain historical malicious behavior mode knowledge to a target domain through a migration learning model based on the graph, generating cross-platform migration security features, and performing cross-domain security feature extraction on the target domain historical malicious behavior mode knowledge. And calling a security behavior analysis model to carry out joint modeling and time sequence security association analysis, identifying an abnormal security behavior mode of a target domain user, and finally matching a network security disposal rule base according to the abnormal mode, generating and issuing a protection strategy, and realizing real-time risk interception.
Owner:LESHAN NORMAL UNIV

Systems and methods for security association enabling make-before-break-roaming (MBBR)

A system and method are provided for generating a pairwise transient key security association (PTKSA) by: providing a first media access control (MAC) address that is shared by multiple access points (APs), the first MAC address corresponding to an infrastructure comprising the multiple APs, and each AP of the multiple APs having a respective AP MAC address; providing a second MAC address to a station (STA); and establishing a secure link between the STA and the infrastructure using the first MAC address and the second MAC address to derive a pairwise transit key (PTK) for the secure link, wherein the secure link is between the STA and the multiple APs.
Owner:CISCO TECHNOLOGY INC

A Cross-Platform User Behavior Analysis Method and System Based on Transfer Learning

This invention provides a cross-platform user behavior analysis method and system based on transfer learning, relating to the field of network security technology. First, it acquires historical network behavior records from a source domain security platform and real-time network behavior stream data from a target domain security platform. The former includes security behavior sequences of source domain users under different access scenarios, while the latter includes dynamic security operation records of the target domain user's current session. Next, it extracts cross-domain security features from both types of data to construct a cross-domain security behavior association graph. Based on this graph, it uses a transfer learning model to transfer historical malicious behavior patterns from the source domain to the target domain, generating cross-platform transferred security features. Then, it calls a security behavior analysis model for joint modeling and temporal security association analysis to identify abnormal security behavior patterns of target domain users. Finally, it matches the abnormal patterns with a network security handling rule base to generate and distribute protection policies, achieving real-time risk interception.
Owner:LESHAN NORMAL UNIV

Network security situation awareness method and system based on large model and threat assessment

The invention relates to the technical field of network security, in particular to a network security situation awareness method and system based on a large model and threat assessment. The method comprises the following steps: firstly, acquiring and standardizing multi-modal security data in a cloud service environment in real time, distributing a behavior modal cluster for security event metadata through clustering analysis, and generating a security feature vector containing business semantics and behavior dynamic features based on a cluster center relocation technology; then constructing a local situation map reflecting asset topology and an access link by using a cloud security association model; semantic reasoning is performed on the atlas through a large language model, an attack intention is recognized, and an attack path is predicted; and finally, combining the path probability, the asset value and the vulnerability feature to quantitatively calculate a risk index, and automatically generating a response strategy. Semantic compression of massive logs is realized through modal clustering, and the calculation bottleneck of processing original data by a large model is overcome; and in combination with graph correlation and large model reasoning, the crossing from passive warning to active intention prediction is realized.
Owner:BEIJING ZHONGCHUANG HAISHENG TECHNOLOGY CO LTD

System and method for early detection of duplicate security association of IPsec tunnels

In an embodiment, a method includes transmitting an initiation request from a first electronic device to a second electronic device, the initiation request being associated with a notification that the first electronic device is capable of early detection of duplicate security associations (SAs), receiving an initiation request from the second electronic device at the first electronic device, the initiation request being associated with a capability notification that the second electronic device is capable of early detection of duplicate SAs, determining a possibility of duplicate SAs by the first electronic device, transmitting responses configured to prevent duplicate SAs from the first electronic device to the second electronic device, receiving responses at the first electronic device from the second electronic device, wherein the responses indicate no duplicate SAs created by the second electronic device, and establishing a non-duplicate SA for the first and second electronic devices.
Owner:CISCO TECHNOLOGY INC

System and method for implementing security association for break-before-connect roaming (MBBR)

A system and method for generating a pairwise transient key security association (PTKSA) is provided, including providing a first media access control (MAC) address shared by a plurality of access points (APs), the first MAC address corresponding to an infrastructure including the plurality of APs, and each AP of the plurality of APs having a respective AP MAC address; providing the second MAC address to a station (STA); and establishing a secure link between the STA and the infrastructure using the first MAC address and the second MAC address to derive a pair-to-pair transmission key (PTK) for the secure link, where the secure link is between one or more of the plurality of APs and the STA.
Owner:CISCO TECHNOLOGY INC

Post-quantum secure media access control security (macsec) pre-shared key auto-refresh

Techniques for utilizing post-quantum pre-shared key (PPK) identifiers (PPK_ID) to determine control association key(s) (CAK(s)) and / or secure association key(s) (SAK(s)) utilized in MACsec sessions are described herein. A key server (KS) and a non-key server (NKS) may advertise capabilities indicating an ability to utilize PPKs as CAKs and / or SAKs in MACsec sessions. The KS may leverage a quantum key distribution (QKD) service to determine a PPK_ID and a PPK, which may be utilized as a CAK for a MACsec session with the NKS. The PPK_ID may be transmitted to the NKS, where the NKS may retrieve the PPK from the QKD, and a new group connectivity association may be established using the PPK as the CAK. In some examples, the KS may be configured to refresh the PPK as the CAK for instantiating subsequent MACsec sessions. Additionally, the KS may be configured to distribute a SAK in a similar manner.
Owner:CISCO TECHNOLOGY INC

Wireless communication reconnection method and device, equipment and storage medium

The embodiment of the invention provides a wireless communication reconnection method and device, equipment and a storage medium, and is applied to the technical field of wireless communication. The method comprises the following steps: a wireless client sends a detection request frame to an access point, the detection request frame comprising a first state flag bit, and the first state flag bit is used for inquiring whether the access point saves a key session association (PMKSA); the access point receives the detection request frame, generates a detection response frame based on the detection request frame and sends the detection response frame to the wireless client, the detection response frame comprises a second state flag bit, and the second state flag bit is used for indicating whether the access point stores the PMKSA; the wireless client judges whether the access point stores the PMKSA or not according to the detection response frame; when the access point stores the PMKSA, initiating a connection request to the access point according to the PMKSA; and when the PMKSA is not stored in the access point, initiating an authentication request to the access point, and initiating a connection request to the access point after the authentication is passed. The method can improve the success rate and efficiency of wireless communication reconnection.
Owner:SPREADTRUM COMM (TIANJIN) INC

Office equipment rental management method and system based on local area network and data security

The present invention discloses a local area network (LAN) and data security-based office equipment rental management method and system. The method includes responding to office equipment rental requests from rental terminals, obtaining equipment loss rates and network behavior security scores from historical rental behaviors; parsing the target device model and required quantity in the rental request when both meet preset conditions; monitoring the LAN online status and resource occupancy rate of the target device in real time to calculate the available inventory of the target device; when the available inventory is lower than the required quantity, matching security-associated devices of the same type as the target device in the LAN device registry to calculate the device replacement security index; generating a device replacement policy when the index is greater than a security baseline, signing the policy with a digital certificate, and issuing it to the rental terminal. The system generates a target rental plan by requesting the device replacement policy in response to the rental terminal. The present invention improves the data security and response speed of rental services, and increases the utilization rate of equipment resources and the transaction rate of rental business.
Owner:广东本立租科技有限公司

Duplicate security association manager

One example method includes receiving, at a first computing system from a secure association (SA) service, a first event that indicates that a first SA encryption tunnel has been generated that includes the first computing system, the first SA encryption tunnel including encryption and decryption keys assigned to an IP address of the first computing system. In response to receiving the first event, requesting from the SA service a first SA encryption tunnel list that lists all SA encryption tunnels existing in a computing environment. Comparing the first SA encryption tunnel with the SA encryption tunnels included in the first SA encryption tunnel list. Based on the comparison, determining whether the first SA encryption tunnel is a duplicate of one or more of the SA encryption tunnels included in the first SA encryption tunnel list.
Owner:DELL PROD LP

Sensitive data security association analysis method and device based on secure multi-party computing

The present application relates to a method and apparatus for secure association analysis of sensitive data based on secure multi-party computing, comprising the steps of: creating several roles and granting permissions; implementing identity authentication and authorization management between participants; establishing a secure communication tunnel for the participants; encrypting the sensitive data of the participants, and partially decrypting the data only during predefined computing processes; and capturing and recording data access and processing behaviors. The present application establishes a secure communication tunnel for each participant in data association analysis after successful identity authentication, encrypts the sensitive data of each participant, and partially decrypts the necessary data only during predefined required computing processes. At the same time, an audit tracking system is used to capture and record data access and processing behaviors. This protects the privacy of each party when multiple parties conduct data association analysis, prevents the leakage of sensitive data, and improves the security of sensitive data association analysis.
Owner:CHINA MOBILE GRP GUANGDONG CO LTD

Ground-based measurement and control network communication method based on security gateway

The invention relates to the field of radio communication, in particular to a ground-based measurement and control network communication method based on a security gateway. The invention provides a security gateway design suitable for measurement and control network communication aiming at the characteristic that the security requirement of data communication between a China external station and a domestic central system of a current commercial measurement and control system is high, and technologies such as business data encryption, signature authentication and integrity verification are realized by adding security gateways to the external station and the center in pairs. And the communication security is ensured. And a symmetric / asymmetric encryption and decryption algorithm of the national secret standard is adopted to encrypt the service data, so that the data is prevented from being exposed in the network. The key negotiation process is based on an asymmetric cryptography algorithm, safety association is established through key negotiation, generation and sharing of symmetric keys are achieved, it is ensured that a third party cannot decrypt or counterfeit a data packet, and therefore communication safety is effectively protected.
Owner:THE 54TH RESEARCH INSTITUTE OF CHINA ELECTRONICS TECHNOLOGY GROUP CORPORATION

Intelligent classification management method and system for hard disk data

The invention provides an intelligent classification management method and system for hard disk data, and relates to the technical field of intelligent storage, and the method comprises the steps: employing an Andru algorithm in convex hull construction, carrying out the sorting and stack maintenance of an extracted feature point set under different scales, constructing a convex hull, achieving the geometric contour fusion of multi-scale features, and obtaining a multi-scale feature set; generating regional confidence evaluation parameters; positioning a bank card information area in the cashier desk video according to the area confidence evaluation parameter, applying a dynamic mask, performing security association operation on desensitized data, an event label and an area label, and outputting a label association data volume; and based on the label associated data volume, calculating the pressure value of the data to be processed of each hard disk in real time through the load sensor in combination with a resource allocation game optimization algorithm, and generating a real-time data stream. According to the method, the intelligence and the high efficiency of hard disk data classification management are improved.
Owner:FUBEN (XIAMEN) TECH CO LTD

IKE-based path identity

The present technology uses the IKE protocol to establish a path identity on both sides of a peer connection. This is achieved by using IKE to exchange local and peer device identifiers along with transport identifiers. IKE then populates the path identity into the IPsec data plane by associating it with the transmit and receive security association databases (IPsec Tx & Rx SA DB). The device's data plane can monitor traffic sent or received through these IPsec SAs by using the path identity information linked with the IPsec SAs. This allows the creation of an application-to-path monitoring record, or matching traffic to the record for purposes such as statistics collection, troubleshooting, and performance evaluation.
Owner:CISCO TECHNOLOGY INC

Enhanced processing for IPSEC flows

Embodiments of the present disclosure relate to methods, apparatuses, and computer readable storage media for processing Internet Protocol Security (IPsec) flows. One method includes determining a security association for an incoming flow, the incoming flow comprising a plurality of packets; performing pre-processing on the plurality of packets based on the security association; and in response to performing the pre-processing on at least one packet of the plurality of packets, performing parallel processing on the at least one packet of the plurality of packets.
Owner:NOKIA NETWORKS OY

Authentication and security for ultra-high reliability (UHR) roaming

This disclosure provides methods, components, devices and systems for authentication and security for ultra-high reliability (UHR) roaming. Some aspects more specifically relate to devices in a seamless mobility domain (SMD), such as access point (AP) multi-link devices (MLDs) and non-AP MLDs, supporting the generation of different temporal keys (TKs) for each AP MLD. For example, the non-AP MLD may establish, via authenticator associated with the SMD, a pairwise master key security association (PMKSA) and a single pairwise transient key security association (PTKSA). Thus, the non-AP MLD may communicate with a first AP MLD (such as of multiple AP MLDs associated with the SMD) in accordance with a first pairwise transient key (PTK) and, after roaming to a second AP MLD (such as of the multiple AP MLDs), may communicate with the second AP MLD in accordance with a second PTK, where the second TK is different than the first PTK.
Owner:QUALCOMM INC

Location Data Harvesting and Pruning for Wireless Accessory Devices

Techniques are disclosed for identifying and processing beacon advertisement packets on an electronic device equipped with a wireless processor and wireless radio. An example method may include scanning for beacon advertisements, detecting a specific beacon advertisement that includes a beacon advertisement packet, and determining whether the detected packet is of a first or second type based on its structure. Upon identification of the packet as the first type, the method may further include executing a key matching operation to ascertain whether the beacon advertisement is associated with a known device. This approach enables efficient device recognition and secure association within wireless environments, enhancing connectivity management and security on electronic devices.
Owner:APPLE INC

Comprehensive congestion control and adaptive transmission optimization method based on WAPI

The invention provides a comprehensive congestion control and adaptive transmission optimization method based on WAPI, and belongs to the field of communication. The key problems that under the wireless communication environment based on the WAPI security standard in the electric power Internet of Things, network congestion is difficult to dynamically regulate and control, data transmission is prone to disorder, and a retransmission mechanism lacks intelligent adaptation are solved, and the method comprises the following steps that WAPI environment initialization and security association establishment are carried out; based on a WAPI and reinforcement learning congestion control framework, a teacher-student distillation mechanism is adopted to extract a symbol strategy, and multi-context branch agents are integrated to adapt to different network conditions, so that long-term congestion planning and dynamic rate adjustment are realized; optimizing a data packet sequence and congestion window growth coupling in multi-path transmission through ECN marking and correlation verification; running a WAPI security aware adaptive retransmission module, and dynamically selecting unicast or multicast retransmission in combination with a WAPI security mechanism; the present application is applied to WAPI.
Owner:ELECTRIC POWER RES INST STATE GRID SHANXI ELECTRIC POWER +1

Systems and methods for security association enabling make-before-break-roaming (MBBR)

PendingUS20260189902A1StationSecurity association
A system and method are provided for generating a pairwise transient key security association (PTKSA) by: providing a first media access control (MAC) address that is shared by multiple access points (APs), the first MAC address corresponding to an infrastructure comprising the multiple APs, and each AP of the multiple APs having a respective AP MAC address; providing a second MAC address to a station (STA); and establishing a secure link between the STA and the infrastructure using the first MAC address and the second MAC address to derive a pairwise transit key (PTK) for the secure link, wherein the secure link is between the STA and the multiple APs.
Owner:CISCO TECHNOLOGY INC

Method, apparatus and electronic device for identifying a cryptographic device

The application provides a method, device and electronic equipment for identifying a cryptographic device, wherein the method comprises: obtaining target encrypted traffic when a target encrypted tunnel is established, the target encrypted traffic comprising initiator encrypted traffic; identifying an initiator protocol of the initiator encrypted traffic, and parsing the initiator protocol to obtain a security association payload supported by the initiator protocol, and determining a payload fingerprint of the initiator encrypted traffic based on the security association payload; and determining, based on the payload fingerprint, a cryptographic device corresponding to a target encrypted tunnel to which the target encrypted traffic belongs. The method, device and electronic equipment for identifying a cryptographic device provided by the application utilize certain attributes of an initiator protocol in initiator encrypted traffic processed by a cryptographic device, can be associated with inherent characteristics of a corresponding cryptographic device, are not affected by a complex network and time delay, can more accurately determine a cryptographic device, and are high in identification efficiency and easy to implement.
Owner:VIEWINTECH

Generating keys for node clusters in single security association

A computing node in the computing cluster includes at least a key generator and an encryption engine. The key generator implements a key derivation function and generates a first data encryption key based on the key derivation key. The key derivation key is a global security association encryption key shared by a plurality of nodes in the computing cluster. The first data encryption key has uniqueness for a node pair of the plurality of nodes including a first node and a second node. The encryption engine encrypts a data packet using the first data encryption key.
Owner:ADVANCED MICRO DEVICES INC

Apparatus and method for supporting l4s in no-3GPP access environments

The present disclosure relates to a 5G or 6G communication system for supporting a higher data transmission rate, and to a method performed by a non-3GPP interworking function (N3IWF) entity of a wireless communication system, the method comprising the steps of: receiving session management information from a session management function (SMF) entity via an access and mobility management function (AMF) entity, the session management information includes an explicit congestion notification (ECN) flag indication for supporting low latency, low loss, and scalable throughput (L4S) in non-3GPP access; determining a connection of an Internet Protocol Security (IPsec) sub-security association (SA) supporting a Quality of Service (QoS) flow of the L4S; and sending a message for requesting the IPsec sub-SA connection to the terminal.
Owner:SAMSUNG ELECTRONICS CO LTD

Dynamic bringup of secure tunneling of access-controlled network domain interconnect traffic

Methods and devices provide improved secure tunneling of interconnect traffic across access-controlled network domains, by configuring network devices according to a dynamic tunnel bringup method to discover peer network devices, establish a tunnel gateway in a security association, monitor a security association session status, and update routing and forwarding tables in accordance. A processing unit of a network device configures the network device to discover a peer network device; update a next hop in a local routing table; establish a tunnel endpoint; encapsulate an encrypted packet with a SA tag; monitor a SA session status; and advertise routing information based on a monitored SA session status.
Owner:CISCO TECHNOLOGY INC

Seamless Switching of IPsec Tunnels

This document describes aspects of seamless switching of Internet Protocol security (IPsec) tunnels between subsystems within a user device. In aspects, the described systems and methods can initiate a child Security Association (SA) rekeying process to establish a new IPsec tunnel without interrupting a data exchange on an active IPsec tunnel. The described aspects may enable continuous communication while the data exchanged is migrated between the IPsec tunnels. In some cases, both the old and new child SAs coexist temporarily during the rekeying process, allowing for uninterrupted data flow and ensuring that security measures, such as anti-replay checks, remain effective. As such, the transitions of the data can be completed without data loss, as the subsystems handle the transfer of data packets over both IPsec tunnels. The described aspects are particularly beneficial for devices that switch between high-performance and low-power hardware subsystems, enabling the optimization of performance and energy efficiency.
Owner:GOOGLE LLC

Secure packet transmission method and related apparatus

This disclosure provides a secure packet transmission method, a method for negotiating an internet protocol security security association (IPsec SA), and a related apparatus, and is applied to a wide area network. In a scenario of crossing a plurality of segments of tunnels, an IPsec SA used for end-to-end security protection is negotiated between a first site edge and a second site edge based on a virtual routing and forwarding (VRF) granularity by extending a border gateway protocol (BGP) route. After performing security protection on a virtual private network (VPN) service packet based on the IPsec SA, the first site edge sends the packet through an overlay end-to-end tunnel between the first site edge and the second site edge, and the second site edge processes the packet based on the IPsec SA, to obtain the VPN service packet.
Owner:HUAWEI TECH CO LTD

Data transmission method and device

The embodiment of the invention provides a data transmission method and device, and relates to the technical field of quantum communication, and the method applied to a first device in communication connection with a quantum server comprises the following steps: establishing an Internet Key Exchange Security Association (IKESA) with a second device, the second device being in communication connection with the quantum server; a key application request is sent to the quantum server, a first quantum key fed back by the quantum server is received, and the first quantum key is generated by the quantum server based on a quantum key distribution (QKD) protocol; establishing an internet protocol security association (IPSecSA) with the second equipment; and encrypting the first to-be-sent data based on the first quantum key, and sending the encrypted data to the second device through an IPSec tunnel formed after the IPSec SA is established. By applying the scheme provided by the embodiment of the invention, the security of data transmission between equipment can be improved.
Owner:NEW H3C TECH CO LTD

Rekeying a security association using a security parameter index transform

Disclosed embodiments implement rekeying keys of a Security Association (SA) using an SPI Transform to provide secure data transfer in a computing environment. A disclosed method comprises detecting, by a local key manager (LKM) executing on a computing node, an expired rekey timer of an SA between an initiator channel on the computing node and a responder channel on a responder node. The LKM requests, based on the expired rekey timer, an SA Index from the initiator channel on a computing node. The LKM creates an SPI based on an SPI Transform using the new SA Index and SPI Transform values. The LKM builds an SKE SA Initialization Request message based on an authentication key of the SA and the SPI to obtain a new session key.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

A Multi-Source Fusion-Based System and Method for Calculating Peak Fatigue Levels of Runners (up to 10,000 Users)

This invention provides a multi-source fusion-based system and method for calculating peak fatigue levels in runners of up to 10,000 users. The system includes a data acquisition module, a data preprocessing and fusion module, a peak fatigue calculation module, a safety early warning and coordinated intervention module, a data security and privacy protection module, and a backup data acquisition unit. The core functionality involves collecting five-dimensional, multi-source, safety-related data on runners' physiological, exercise, environmental, individual, and subjective factors through the data acquisition module. A simplified version of non-invasive electromyography (EMG) signals is introduced to identify latent muscle fatigue. A dual-layer fusion architecture of "edge + cloud" is adopted, combined with a federated learning model, to achieve deep fusion of multi-source data while protecting runner privacy, constructing a personalized dynamic fatigue threshold model. The system calculates peak fatigue levels based on a real-time safety-oriented fatigue index, implements closed-loop intervention through a four-level graded early warning mechanism linking multiple terminals, and ensures data security through three-link redundant transmission, data anonymization and encryption. The backup acquisition unit ensures full coverage of data from up to 10,000 users.
Owner:WUXI HUIPAO SPORTS CO LTD

Method and apparatus for secure key distribution

The invention relates to a method and apparatus for secure key distribution. A new approach is proposed for supporting secure key distribution between a host and a resource-constrained Ethernet bridge using MACSec, wherein the resource-constrained Ethernet bridge is hardware with multiple hardware blocks but without a processor or non-volatile storage. In the proposed method, existing hardware modules using a resource-constrained Ethernet bridge completely implement a secure key distribution protocol. First, a session encryption key is independently generated by a host and an Ethernet bridge. If the SEKs match, the host is configured to generate and distribute a security association key (SAK) to the Ethernet bridge for installation thereon. After the SAK is installed on the Ethernet bridge, a secure communication channel is established between the host and the Ethernet bridge. A secure communication channel may be used for secure communication of sensitive data collected by an Ethernet bridge from a plurality of electronic devices.
Owner:MARVELL ASIA PTE LTD