Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

93 results about "Security association" patented technology

A security association (SA) is the establishment of shared security attributes between two network entities to support secure communication. An SA may include attributes such as: cryptographic algorithm and mode; traffic encryption key; and parameters for the network data to be passed over the connection. The framework for establishing security associations is provided by the Internet Security Association and Key Management Protocol (ISAKMP). Protocols such as Internet Key Exchange (IKE) and Kerberized Internet Negotiation of Keys (KINK) provide authenticated keying material.

Security-linked telemetry in a zero-trust computing environment

Systems and methods support collection of telemetry by an Information Handling System (IHS). A policy decision point of a zero-trust computing environment controls access to protected resources and receives an indication of attack related to the IHS. A telemetry definition is identified that specifies telemetry being collected by the IHS and it is updated to specify a security delay for telemetry related to the indication of attack. The updated telemetry definition is transmitted to the IHS. Upon identifying telemetry that is ready for transmission, the IHS determines whether the telemetry is subject to a security delay specified in the updated telemetry definition. When the telemetry is subject to a security delay, the telemetry that is ready for transmission is queued and transmitted to one or more destinations specified in the updated telemetry definition upon expiration of the security delay.
Owner:DELL PROD LP

Flow-based secure packet forwarding

Example methods and systems for flow-based secure packet forwarding are described. In one example, a first computer system may assess validity of a security token associated with a flow of one or more packets. In response to determination that the security token is valid, a security association associated with the flow and the security token may be negotiated with a second computer system. The first computer system may process a packet associated with the flow and the security token to generate an encapsulated encrypted packet by performing encryption and encapsulation based on the security association. The encapsulated encrypted packet may be forwarded towards the second computer system to cause the second computer system to perform decapsulation and decryption, and to forward a decapsulated and decrypted packet towards the destination.
Owner:VMWARE INC

Prioritized Rekeying of Security Associations

Embodiments include methods for a first node to manage rekeying of a security association (SA) between the first node and a second node in a communication network. Such methods include sending to the second node a request indicating a rekey priority of the first node, and receiving from the second node a response indicating a rekey priority of the second node. Such methods also include selectively initiating rekeying of the SA between the first node and the second node based on the request and the response. Other embodiments include complementary methods for the second node, as well as nodes (e.g., hosts, gateways, UEs, base stations, servers, etc.) configured to perform such methods.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Cross-platform user behavior analysis method and system based on transfer learning

The invention provides a cross-platform user behavior analysis method and system based on transfer learning, and relates to the technical field of network security, first, historical network behavior record data of a source domain security platform and real-time network behavior flow data of a target domain security platform are obtained, the historical network behavior record data comprise security behavior sequences of source domain users in different access scenes, and the real-time network behavior flow data are stored in the target domain security platform; the method comprises the following steps of: performing cross-domain security feature extraction on two types of data, constructing a cross-domain security behavior association graph, migrating source domain historical malicious behavior mode knowledge to a target domain through a migration learning model based on the graph, generating cross-platform migration security features, and performing cross-domain security feature extraction on the target domain historical malicious behavior mode knowledge. And calling a security behavior analysis model to carry out joint modeling and time sequence security association analysis, identifying an abnormal security behavior mode of a target domain user, and finally matching a network security disposal rule base according to the abnormal mode, generating and issuing a protection strategy, and realizing real-time risk interception.
Owner:LESHAN NORMAL UNIV

Cryptographic system and method for dynamic and automated secure preshared key rotation and distribution

A method and apparatus are provided for automatically distributing pre-shared keys (PSKs) in a secure communication network. A first security association (SA) or secured message (SM) is created between two endpoints based on a first PSK. Then, one or more subsequent PSKs are distributed between the endpoints with secure communication support by the first SA or SM. Based on one of the subsequent PSKs, a second security association is formed between the endpoints. Messages between the endpoints can then be transmitted with secure communication support by the second SA or SM.
Owner:NOKIA SOLUTIONS & NETWORKS OY

Systems and methods for security association enabling make-before-break-roaming (MBBR)

A system and method are provided for generating a pairwise transient key security association (PTKSA) by: providing a first media access control (MAC) address that is shared by multiple access points (APs), the first MAC address corresponding to an infrastructure comprising the multiple APs, and each AP of the multiple APs having a respective AP MAC address; providing a second MAC address to a station (STA); and establishing a secure link between the STA and the infrastructure using the first MAC address and the second MAC address to derive a pairwise transit key (PTK) for the secure link, wherein the secure link is between the STA and the multiple APs.
Owner:CISCO TECHNOLOGY INC

A Cross-Platform User Behavior Analysis Method and System Based on Transfer Learning

This invention provides a cross-platform user behavior analysis method and system based on transfer learning, relating to the field of network security technology. First, it acquires historical network behavior records from a source domain security platform and real-time network behavior stream data from a target domain security platform. The former includes security behavior sequences of source domain users under different access scenarios, while the latter includes dynamic security operation records of the target domain user's current session. Next, it extracts cross-domain security features from both types of data to construct a cross-domain security behavior association graph. Based on this graph, it uses a transfer learning model to transfer historical malicious behavior patterns from the source domain to the target domain, generating cross-platform transferred security features. Then, it calls a security behavior analysis model for joint modeling and temporal security association analysis to identify abnormal security behavior patterns of target domain users. Finally, it matches the abnormal patterns with a network security handling rule base to generate and distribute protection policies, achieving real-time risk interception.
Owner:LESHAN NORMAL UNIV

Network security situation awareness method and system based on large model and threat assessment

The invention relates to the technical field of network security, in particular to a network security situation awareness method and system based on a large model and threat assessment. The method comprises the following steps: firstly, acquiring and standardizing multi-modal security data in a cloud service environment in real time, distributing a behavior modal cluster for security event metadata through clustering analysis, and generating a security feature vector containing business semantics and behavior dynamic features based on a cluster center relocation technology; then constructing a local situation map reflecting asset topology and an access link by using a cloud security association model; semantic reasoning is performed on the atlas through a large language model, an attack intention is recognized, and an attack path is predicted; and finally, combining the path probability, the asset value and the vulnerability feature to quantitatively calculate a risk index, and automatically generating a response strategy. Semantic compression of massive logs is realized through modal clustering, and the calculation bottleneck of processing original data by a large model is overcome; and in combination with graph correlation and large model reasoning, the crossing from passive warning to active intention prediction is realized.
Owner:BEIJING ZHONGCHUANG HAISHENG TECHNOLOGY CO LTD

System and Method for Early Detection of Duplicate Security Association of IPsec Tunnels

In an embodiment, a method includes transmitting an initiation request from a first electronic device to a second electronic device, the initiation request being associated with a notification that the first electronic device is capable of early detection of duplicate security associations (SAs), receiving an initiation request from the second electronic device at the first electronic device, the initiation request being associated with a capability notification that the second electronic device is capable of early detection of duplicate SAs, determining a possibility of duplicate SAs by the first electronic device, transmitting responses configured to prevent duplicate SAs from the first electronic device to the second electronic device, receiving responses at the first electronic device from the second electronic device, wherein the responses indicate no duplicate SAs created by the second electronic device, and establishing a non-duplicate SA for the first and second electronic devices.
Owner:CISCO TECHNOLOGY INC

System and method for early detection of duplicate security association of IPsec tunnels

In an embodiment, a method includes transmitting an initiation request from a first electronic device to a second electronic device, the initiation request being associated with a notification that the first electronic device is capable of early detection of duplicate security associations (SAs), receiving an initiation request from the second electronic device at the first electronic device, the initiation request being associated with a capability notification that the second electronic device is capable of early detection of duplicate SAs, determining a possibility of duplicate SAs by the first electronic device, transmitting responses configured to prevent duplicate SAs from the first electronic device to the second electronic device, receiving responses at the first electronic device from the second electronic device, wherein the responses indicate no duplicate SAs created by the second electronic device, and establishing a non-duplicate SA for the first and second electronic devices.
Owner:CISCO TECHNOLOGY INC

System and method for implementing security association for break-before-connect roaming (MBBR)

A system and method for generating a pairwise transient key security association (PTKSA) is provided, including providing a first media access control (MAC) address shared by a plurality of access points (APs), the first MAC address corresponding to an infrastructure including the plurality of APs, and each AP of the plurality of APs having a respective AP MAC address; providing the second MAC address to a station (STA); and establishing a secure link between the STA and the infrastructure using the first MAC address and the second MAC address to derive a pair-to-pair transmission key (PTK) for the secure link, where the secure link is between one or more of the plurality of APs and the STA.
Owner:CISCO TECHNOLOGY INC

Enhanced wireless security

This disclosure describes systems, methods, and devices related to using pairwise master key security association (PMKSA) caching for authentication and time synchronization factor security. A method may include sending a first message of an 802.1X authentication frame exchange, including an indication of a first pairwise master key identifier (PMKID) associated with one or more PMKSA identifiers; identifying a second PMKID indicated in a second message of the 802.1X authentication frame exchange, received from a responder device; determining that second PMKID matches the first PMKID; storing a PMKSA identifier corresponding to the second PMKID; and sending an association request frame to the responder device based on determining that the second PMKID matches the first PMKID, wherein the association request frame is sent in succession with receiving the second message of the 802.1X authentication frame exchange.
Owner:INTEL CORP

Post-quantum secure media access control security (macsec) pre-shared key auto-refresh

Techniques for utilizing post-quantum pre-shared key (PPK) identifiers (PPK_ID) to determine control association key(s) (CAK(s)) and / or secure association key(s) (SAK(s)) utilized in MACsec sessions are described herein. A key server (KS) and a non-key server (NKS) may advertise capabilities indicating an ability to utilize PPKs as CAKs and / or SAKs in MACsec sessions. The KS may leverage a quantum key distribution (QKD) service to determine a PPK_ID and a PPK, which may be utilized as a CAK for a MACsec session with the NKS. The PPK_ID may be transmitted to the NKS, where the NKS may retrieve the PPK from the QKD, and a new group connectivity association may be established using the PPK as the CAK. In some examples, the KS may be configured to refresh the PPK as the CAK for instantiating subsequent MACsec sessions. Additionally, the KS may be configured to distribute a SAK in a similar manner.
Owner:CISCO TECHNOLOGY INC

Wireless communication reconnection method and device, equipment and storage medium

The embodiment of the invention provides a wireless communication reconnection method and device, equipment and a storage medium, and is applied to the technical field of wireless communication. The method comprises the following steps: a wireless client sends a detection request frame to an access point, the detection request frame comprising a first state flag bit, and the first state flag bit is used for inquiring whether the access point saves a key session association (PMKSA); the access point receives the detection request frame, generates a detection response frame based on the detection request frame and sends the detection response frame to the wireless client, the detection response frame comprises a second state flag bit, and the second state flag bit is used for indicating whether the access point stores the PMKSA; the wireless client judges whether the access point stores the PMKSA or not according to the detection response frame; when the access point stores the PMKSA, initiating a connection request to the access point according to the PMKSA; and when the PMKSA is not stored in the access point, initiating an authentication request to the access point, and initiating a connection request to the access point after the authentication is passed. The method can improve the success rate and efficiency of wireless communication reconnection.
Owner:SPREADTRUM COMM (TIANJIN) INC

Office equipment rental management method and system based on local area network and data security

The present invention discloses a local area network (LAN) and data security-based office equipment rental management method and system. The method includes responding to office equipment rental requests from rental terminals, obtaining equipment loss rates and network behavior security scores from historical rental behaviors; parsing the target device model and required quantity in the rental request when both meet preset conditions; monitoring the LAN online status and resource occupancy rate of the target device in real time to calculate the available inventory of the target device; when the available inventory is lower than the required quantity, matching security-associated devices of the same type as the target device in the LAN device registry to calculate the device replacement security index; generating a device replacement policy when the index is greater than a security baseline, signing the policy with a digital certificate, and issuing it to the rental terminal. The system generates a target rental plan by requesting the device replacement policy in response to the rental terminal. The present invention improves the data security and response speed of rental services, and increases the utilization rate of equipment resources and the transaction rate of rental business.
Owner:广东本立租科技有限公司

Duplicate security association manager

One example method includes receiving, at a first computing system from a secure association (SA) service, a first event that indicates that a first SA encryption tunnel has been generated that includes the first computing system, the first SA encryption tunnel including encryption and decryption keys assigned to an IP address of the first computing system. In response to receiving the first event, requesting from the SA service a first SA encryption tunnel list that lists all SA encryption tunnels existing in a computing environment. Comparing the first SA encryption tunnel with the SA encryption tunnels included in the first SA encryption tunnel list. Based on the comparison, determining whether the first SA encryption tunnel is a duplicate of one or more of the SA encryption tunnels included in the first SA encryption tunnel list.
Owner:DELL PROD LP

Sensitive data security association analysis method and device based on secure multi-party computing

The present application relates to a method and apparatus for secure association analysis of sensitive data based on secure multi-party computing, comprising the steps of: creating several roles and granting permissions; implementing identity authentication and authorization management between participants; establishing a secure communication tunnel for the participants; encrypting the sensitive data of the participants, and partially decrypting the data only during predefined computing processes; and capturing and recording data access and processing behaviors. The present application establishes a secure communication tunnel for each participant in data association analysis after successful identity authentication, encrypts the sensitive data of each participant, and partially decrypts the necessary data only during predefined required computing processes. At the same time, an audit tracking system is used to capture and record data access and processing behaviors. This protects the privacy of each party when multiple parties conduct data association analysis, prevents the leakage of sensitive data, and improves the security of sensitive data association analysis.
Owner:CHINA MOBILE GRP GUANGDONG CO LTD

Dynamic adaption of ARW management with enhanced security

Methods and apparatus for dynamic adaption of anti-replay window (ARW) management with enhanced security. According to aspects of the method, pre-ARW block employing a pre-ARW sliding window and an ARW block employing an ARW sliding window are maintained for an associated IPsec security association (SA). A determination is made to whether a received packet passes a pre-ARW check using the pre-ARW sliding window. When it does, the pre-ARW sliding window is advanced, encrypted content in the packet is decrypted, and processing is forwarded to the ARW block which performs an ARW check and advances the ARW sliding window when the ARW check is passed. Packets that do not pass the pre-ARW check may be buffered in queues and subsequently rechecked against the ARW sliding window. Under solutions provided herein, ARW checks and updates are decoupled from the decryption processes, enabling decryption to be performed in parallel and / or offloaded to a hardware accelerator.
Owner:INTEL CORP

Ground-based measurement and control network communication method based on security gateway

The invention relates to the field of radio communication, in particular to a ground-based measurement and control network communication method based on a security gateway. The invention provides a security gateway design suitable for measurement and control network communication aiming at the characteristic that the security requirement of data communication between a China external station and a domestic central system of a current commercial measurement and control system is high, and technologies such as business data encryption, signature authentication and integrity verification are realized by adding security gateways to the external station and the center in pairs. And the communication security is ensured. And a symmetric / asymmetric encryption and decryption algorithm of the national secret standard is adopted to encrypt the service data, so that the data is prevented from being exposed in the network. The key negotiation process is based on an asymmetric cryptography algorithm, safety association is established through key negotiation, generation and sharing of symmetric keys are achieved, it is ensured that a third party cannot decrypt or counterfeit a data packet, and therefore communication safety is effectively protected.
Owner:THE 54TH RESEARCH INSTITUTE OF CHINA ELECTRONICS TECHNOLOGY GROUP CORPORATION

Intelligent classification management method and system for hard disk data

The invention provides an intelligent classification management method and system for hard disk data, and relates to the technical field of intelligent storage, and the method comprises the steps: employing an Andru algorithm in convex hull construction, carrying out the sorting and stack maintenance of an extracted feature point set under different scales, constructing a convex hull, achieving the geometric contour fusion of multi-scale features, and obtaining a multi-scale feature set; generating regional confidence evaluation parameters; positioning a bank card information area in the cashier desk video according to the area confidence evaluation parameter, applying a dynamic mask, performing security association operation on desensitized data, an event label and an area label, and outputting a label association data volume; and based on the label associated data volume, calculating the pressure value of the data to be processed of each hard disk in real time through the load sensor in combination with a resource allocation game optimization algorithm, and generating a real-time data stream. According to the method, the intelligence and the high efficiency of hard disk data classification management are improved.
Owner:FUBEN (XIAMEN) TECH CO LTD

IKE-based path identity

The present technology uses the IKE protocol to establish a path identity on both sides of a peer connection. This is achieved by using IKE to exchange local and peer device identifiers along with transport identifiers. IKE then populates the path identity into the IPsec data plane by associating it with the transmit and receive security association databases (IPsec Tx & Rx SA DB). The device's data plane can monitor traffic sent or received through these IPsec SAs by using the path identity information linked with the IPsec SAs. This allows the creation of an application-to-path monitoring record, or matching traffic to the record for purposes such as statistics collection, troubleshooting, and performance evaluation.
Owner:CISCO TECHNOLOGY INC

Enhanced processing for IPSEC flows

Embodiments of the present disclosure relate to methods, apparatuses, and computer readable storage media for processing Internet Protocol Security (IPsec) flows. One method includes determining a security association for an incoming flow, the incoming flow comprising a plurality of packets; performing pre-processing on the plurality of packets based on the security association; and in response to performing the pre-processing on at least one packet of the plurality of packets, performing parallel processing on the at least one packet of the plurality of packets.
Owner:NOKIA NETWORKS OY

Authentication and security for ultra-high reliability (UHR) roaming

This disclosure provides methods, components, devices and systems for authentication and security for ultra-high reliability (UHR) roaming. Some aspects more specifically relate to devices in a seamless mobility domain (SMD), such as access point (AP) multi-link devices (MLDs) and non-AP MLDs, supporting the generation of different temporal keys (TKs) for each AP MLD. For example, the non-AP MLD may establish, via authenticator associated with the SMD, a pairwise master key security association (PMKSA) and a single pairwise transient key security association (PTKSA). Thus, the non-AP MLD may communicate with a first AP MLD (such as of multiple AP MLDs associated with the SMD) in accordance with a first pairwise transient key (PTK) and, after roaming to a second AP MLD (such as of the multiple AP MLDs), may communicate with the second AP MLD in accordance with a second PTK, where the second TK is different than the first PTK.
Owner:QUALCOMM INC

Location Data Harvesting and Pruning for Wireless Accessory Devices

Techniques are disclosed for identifying and processing beacon advertisement packets on an electronic device equipped with a wireless processor and wireless radio. An example method may include scanning for beacon advertisements, detecting a specific beacon advertisement that includes a beacon advertisement packet, and determining whether the detected packet is of a first or second type based on its structure. Upon identification of the packet as the first type, the method may further include executing a key matching operation to ascertain whether the beacon advertisement is associated with a known device. This approach enables efficient device recognition and secure association within wireless environments, enhancing connectivity management and security on electronic devices.
Owner:APPLE INC

Comprehensive congestion control and adaptive transmission optimization method based on WAPI

The invention provides a comprehensive congestion control and adaptive transmission optimization method based on WAPI, and belongs to the field of communication. The key problems that under the wireless communication environment based on the WAPI security standard in the electric power Internet of Things, network congestion is difficult to dynamically regulate and control, data transmission is prone to disorder, and a retransmission mechanism lacks intelligent adaptation are solved, and the method comprises the following steps that WAPI environment initialization and security association establishment are carried out; based on a WAPI and reinforcement learning congestion control framework, a teacher-student distillation mechanism is adopted to extract a symbol strategy, and multi-context branch agents are integrated to adapt to different network conditions, so that long-term congestion planning and dynamic rate adjustment are realized; optimizing a data packet sequence and congestion window growth coupling in multi-path transmission through ECN marking and correlation verification; running a WAPI security aware adaptive retransmission module, and dynamically selecting unicast or multicast retransmission in combination with a WAPI security mechanism; the present application is applied to WAPI.
Owner:ELECTRIC POWER RES INST STATE GRID SHANXI ELECTRIC POWER +1

Systems and methods for security association enabling make-before-break-roaming (MBBR)

PendingUS20260189902A1StationSecurity association
A system and method are provided for generating a pairwise transient key security association (PTKSA) by: providing a first media access control (MAC) address that is shared by multiple access points (APs), the first MAC address corresponding to an infrastructure comprising the multiple APs, and each AP of the multiple APs having a respective AP MAC address; providing a second MAC address to a station (STA); and establishing a secure link between the STA and the infrastructure using the first MAC address and the second MAC address to derive a pairwise transit key (PTK) for the secure link, wherein the secure link is between the STA and the multiple APs.
Owner:CISCO TECHNOLOGY INC

Method, apparatus and electronic device for identifying a cryptographic device

The application provides a method, device and electronic equipment for identifying a cryptographic device, wherein the method comprises: obtaining target encrypted traffic when a target encrypted tunnel is established, the target encrypted traffic comprising initiator encrypted traffic; identifying an initiator protocol of the initiator encrypted traffic, and parsing the initiator protocol to obtain a security association payload supported by the initiator protocol, and determining a payload fingerprint of the initiator encrypted traffic based on the security association payload; and determining, based on the payload fingerprint, a cryptographic device corresponding to a target encrypted tunnel to which the target encrypted traffic belongs. The method, device and electronic equipment for identifying a cryptographic device provided by the application utilize certain attributes of an initiator protocol in initiator encrypted traffic processed by a cryptographic device, can be associated with inherent characteristics of a corresponding cryptographic device, are not affected by a complex network and time delay, can more accurately determine a cryptographic device, and are high in identification efficiency and easy to implement.
Owner:VIEWINTECH

Generating keys for node clusters in single security association

A computing node in the computing cluster includes at least a key generator and an encryption engine. The key generator implements a key derivation function and generates a first data encryption key based on the key derivation key. The key derivation key is a global security association encryption key shared by a plurality of nodes in the computing cluster. The first data encryption key has uniqueness for a node pair of the plurality of nodes including a first node and a second node. The encryption engine encrypts a data packet using the first data encryption key.
Owner:ADVANCED MICRO DEVICES INC

Apparatus and method for supporting l4s in no-3GPP access environments

The present disclosure relates to a 5G or 6G communication system for supporting a higher data transmission rate, and to a method performed by a non-3GPP interworking function (N3IWF) entity of a wireless communication system, the method comprising the steps of: receiving session management information from a session management function (SMF) entity via an access and mobility management function (AMF) entity, the session management information includes an explicit congestion notification (ECN) flag indication for supporting low latency, low loss, and scalable throughput (L4S) in non-3GPP access; determining a connection of an Internet Protocol Security (IPsec) sub-security association (SA) supporting a Quality of Service (QoS) flow of the L4S; and sending a message for requesting the IPsec sub-SA connection to the terminal.
Owner:SAMSUNG ELECTRONICS CO LTD