Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

196 results about "Security context" patented technology

Security contexts are a message security feature and are configured by way of message security bindings. On the client side, the security context is tied to a particular channel. It is configured using the WS_SECURITY_CONTEXT_MESSAGE_SECURITY_BINDING. Behavior and lifetime of the context are determined by the channel.

Dynamic access blocking method based on zero trust

The invention relates to the technical field of network security, in particular to a dynamic access blocking method based on zero trust. Comprising the following steps: step 1, collecting whole network flow data in real time in a bypass monitoring mode through a flow mirroring function of a network switch, performing deep packet inspection analysis on the collected original flow data, and extracting network flow characteristic parameters; 2, maintaining a dynamic identity information base; 3, performing real-time behavior analysis on each network session; 4, according to the risk assessment result and the real-time security context, generating a dynamic access control strategy based on a minimum permission principle; 5, implementing access control at the network execution point; and 6, continuously monitoring the network flow and the strategy execution effect, collecting feedback data, optimizing the risk assessment model and the strategy generation algorithm based on the feedback data, and forming closed-loop control. By dynamically updating the identity and asset information, the system can identify new assets or changes in real time, so that the adaptability and response capability of a network environment are improved.
Owner:SHANDONG NETWORK SECURITY TECHNOLOGY CO LTD

NR mobility - security considerations for l1 / l2 mobility switching of an spcell

A wireless transmit / receive unit (WTRU) may be configured to process first downlink data from a source cell using a first security context. The WTRU may receive, from the source cell, configuration information indicating one or more candidate cells for Layer 1 or Layer 2 (L1 / L2) triggered mobility (LTM). The WTRU may receive, from the source cell, a LTM indication to perform a handover (HO) to a candidate cell among the one or more candidate cells. The WTRU may determine a second security context associated with the candidate cell. The WTRU may process second downlink data based on the first security context. The WTRU may process third downlink data from the candidate cell using the second security context upon a determination that one or more of the conditions are met.
Owner:INTERDIGITAL PATENT HOLDINGS INC

Mandatory access control method and device based on process function context

The invention discloses a mandatory access control method and device based on a process function context, and the method comprises the steps: collecting a security context associated with a system call initiated by a target process, so as to generate a standardized object description; mapping the object description into a target function classification identifier, so as to obtain a process function context view of the target process according to the target function classification identifier; constructing a target decision key for access decision based on the current policy era, the qualifier, the function classification identifier, the view identifier of the process function context view and the isolation domain abstract; and querying the multi-level cache according to the target decision key to determine a matched target access decision. Therefore, context-sensitive judgment and cross-component consistency taking the functional context as the center are realized.
Owner:BEIJING METRO INFORMATION DEV CO LTD

System and method for immutability assurance of backup data based on comprehensive threat detection

Systems and methods for immutability assurance of backup data based on comprehensive threat detection. A method includes performing static and dynamic analysis of a process executing on a computing device, registering an operation of the process with a file on a storage communicatively coupled to the computing device, determining that the file in operation is a backup archive, collecting a context of the process, which includes at least a security context based on the static and dynamic analysis, and a backup archive context based on attributes of the backup archive, analyzing the process operation with the backup file using an access control machine-learning model that calculates an immutability rate based on the collected context, and granting or blocking the process access to the backup archived.
Owner:ACRONIS INT

Reuse of Security Context for Access and Registration

Embodiments include methods for a user equipment (UE) configured to communicate with a communications network via a first access network. Such methods include, without registering with the communications network. receiving from the communications network an authentication-related message that includes an identifier associated with the first access network and at least one of a temporary UE identifier and a security key identifier. Such methods include, based on the identifier, generating a first security key usable for establishing a secure connection with the first access network and establishing a secure connection with the first access network based on the first security key. Such methods include registering with the communications network based on the at least one of the temporary UE identifier and the security key identifier. Other embodiments include complementary methods for network nodes or functions (NNFs) of the communications network. as well as UEs and NNFs configured to perform such methods.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Method and device for allowing application to access system resource, and terminal

The embodiment of the invention provides a method and device for allowing an application to access a system resource, and a terminal. The method includes: acquiring an operation control request of anapplication; determining a user environment where the application is about to operate according to the operation control request of the application; acquiring a safe context corresponding to the userenvironment from a plurality of preconfigured safe contexts in a system, wherein the plurality of preconfigured safe contexts in the system are corresponding to different user environments respectively, and system resource access rights corresponding to the plurality of preconfigured safe contexts are different from each other; and performing access processing on the system resource according to the system resource access right corresponding to the safe context corresponding to the user environment. The scheme can perform application behavior control on the same application under different users.
Owner:CHINA MOBILE COMM LTD RES INST +1

Security authentication multi-start method for Linux system of development board

The invention discloses a development board Linux system security authentication multi-start method, which comprises the steps of 1, hardware trust root initialization and storage area division, 2, hardware trust root self-inspection and measurement, 3, starting item dynamic loading and multi-stage authentication, 4, security context establishment and system switching, and 5, multi-system isolation and collaboration. Step 6, performing security audit and exception handling; full-link authentication is realized by taking a hardware trust root as an anchor point, malicious mirror startup and inter-system data leakage are effectively resisted in combination with a storage and resource isolation mechanism, scenes such as on-demand dynamic switching, flexible adaptation debugging, upgrading and fault recovery of multiple systems can be realized, and the system reliability is improved by optimizing the lightweight design of an authentication algorithm and resource management. Limited computing power of the development board is adapted, the starting process and abnormal events can be completely recorded, and illegal operation can be traced conveniently.
Owner:BEIJING XUNWEI ELECTRONICS CO LTD

Web workflow system and method based on JSON data analysis

The invention provides a Web workflow system and method based on JSON data analysis, and relates to the technical field of workflow design. A standardized JSON process definition file is generated by adopting a visual process designer, process semantic verification and BPMN conversion are realized through a three-level analysis architecture, and efficient management of the whole process of process modeling, execution and auditing is realized in combination with a plug-in task executor, a thread security context manager and a process monitoring module, so that the process modeling, execution and auditing efficiency is improved. The method has the advantages of fast analysis, strong expansion, easy collaboration, traceability and the like.
Owner:CHINA UNICOM XIONGAN IND INTERNET CO LTD

Hybrid encryption method and device and storage medium

The invention provides a hybrid encryption method and device and a storage medium, and the method comprises the steps: a client generates a short-term SM2 key pair and exchanges with a server after obtaining a long-term SM2 key pair and a server public key, dynamically generates a session SM4 symmetric key through an SM2 key exchange protocol, and finally achieves the data transmission and response processing through the session SM4 symmetric key. Through the implementation of the scheme of the invention, the client not only establishes the basic trust relationship based on the long-term SM2 key pair, but also generates the short-term SM2 key pair during each service request, and dynamically derives a unique session SM4 symmetric key and an initial vector by cooperatively executing the SM2 key exchange protocol with the short-term key of the server. And each request has an independent security context, so that the decryption risk after the session key is reused or stolen is fundamentally prevented, and the end-to-end dynamic security communication under the national secret system is really realized.
Owner:SHANGHAI FEIWEI INFORMATION TECH CO LTD +2

Dynamic expansion service node management method based on Camuda process engine

The invention discloses a method for managing service nodes capable of being dynamically expanded based on a Camuda process engine, which belongs to the technical field of electric digital data processing and comprises the following steps of: uniformly configuring service process nodes into a pointing proxy delegation class; querying an external mapping table based on the execution context to obtain a business logic unit identifier; obtaining metadata from a logic registration center according to the identifier, and dynamically loading and instantiating a business logic implementation class through a sandbox class loader; driving service logic execution through a security context object of a white list only exposure method; and recording a full-link audit log. According to the method, structural decoupling of process definition and service logic is realized, so that the process definition does not need to be modified during service change, and dynamic replacement and gray release are supported; through sandbox isolation and security agent, isolated operation of dynamic codes and security and stability of an engine are ensured; and in combination with an audit tracking and fusing mechanism, the observability, the reliability and the operation and maintenance efficiency of the system are improved.
Owner:SUZHOU REKTEC INFORMATION TECH CO LTD

Protecting machine learning models in a wireless communication network

There is provided a method in a Network Data Analytics Function containing a Model Training logical function. The method comprises receiving a machine learning (ML) model provision request, the ML model provision request comprising: an identifier for at least one Analytic, and, ML model file specific information, and generating a protected trained ML model using a stored security context. The method further comprises sending, in response to the ML model provision request, an ML model provision response message, the ML model provision response message comprising: the identifier for the at least one Analytic; at least one protected trained ML model file; and location information of the stored security context.
Owner:LENOVO (SINGAPORE) PTE LTD

User equipment communicating with at least two of a plurality of network functions or services of a telecommunications network

The invention relates to a method for operating a user equipment with a telecommunications network and for communicating with at least two of a plurality of network functions or services of the telecommunications network or of a further telecommunications network, the plurality of network functions or services being able to provide different kinds of network function functionalities, wherein the user equipment is operated using at least a first non-access stratum communication link and a second non-access stratum communication link, the first non-access stratum communication link being established between the user equipment and a first network function or service of the plurality of network functions or services, and the second non-access stratum communication link being established between the user equipment and a second network function or service, wherein the first non-access stratum communication link involves establishing a first non-access stratum security context between the user equipment and the first network function or service and the second non-access stratum communication link involves establishing a second non-access stratum security context between the user equipment and the second network function or service, wherein the operation of the user equipment, using at least the first and second non-access stratum communication links, comprises the following steps: —in a first step, the first non-access stratum communication link as well as the first non-access stratum security context is established using a first non-access stratum endpoint information, and the second non-access stratum communication link as well as the second non-access stratum security context is established using a second non-access stratum endpoint information, —in a second step, the first and second non-access stratum communication links are used between their respective endpoints, wherein a first information element of or transmitted using the first non-access stratum security context is able to be referenced by a second information element of or transmitted using the second considered non-access stratum security context and / or wherein a first information element of or transmitted using the first non-access stratum security context is able to reference a second information element of or transmitted using the second considered non-access stratum security context.
Owner:DEUTSCHE TELEKOM AG

Reuse of Security Context for Access and Registration

Embodiments include methods for a user equipment (UE) configured to communicate with a communications network via at least a first access network. Such methods include, without registering with the communications network, receiving from the communications network an identifier associated with the first access network and an indication of security algorithms to use when communicating with the communications network. Such methods include, based on the identifier associated with the first access network, generating a first security key usable for establishing a secure connection with the first access network and establishing a secure connection with the first access network based on the first security key. Such methods include registering with the communications network using the indicated security algorithms. Other embodiments include complementary methods for network nodes or functions (NNFs) of the communications network, as well as UEs and NNFs configured to perform such methods.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Security policy management

PendingUS20260095487A1Securing communicationEngineeringSecurity policy management
In various examples, input queries (e.g. open user queries) are used combination with predefined queries to perform security policy-related actions using a generative machine learning (GML) model or GML models. In one example, an input query relating to a security policy is matched with a predefined query stored in an instruction database. In some examples, the instruction database contains examples of structured configuration data, which in turn can be used by a GML model to configure a predetermined extractor code module to perform a specific policy-related action. In other examples, a security context relating to a security policy is used together with an input query and template query to generate a GML model query. In some examples, the two approaches are combined.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Zero-trust video data access privacy protection method and system

The invention relates to the technical field of video security and protection, and discloses a zero-trust video data access privacy protection method and system, and the method comprises the steps: carrying out the semantic perception analysis of a video data access request of an access subject, and obtaining a subject identifier, a request access action and target video data; performing identity verification on the access subject, and performing digital signature packaging on a verification result and a security context attribute of the access subject to obtain an identity token; performing access credibility evaluation on the access subject to obtain a real-time credibility; performing privacy sensitivity analysis on the target video data to obtain a content sensitivity label; performing differential desensitization planning on the target video data to obtain a fine-grained desensitization strategy; performing an access control decision on the target video data, and generating a complete access audit log; performing incremental updating on the behavior baseline and the historical access behavior log; according to the invention, the efficiency of zero-trust video data access privacy protection can be improved.
Owner:NAVAL UNIV OF ENG PLA

User plane security anchor for wireless network service security architecture

Apparatus, methods, and computer-readable media for performing wireless communication are disclosed. For example, a method for securely accessing a service may include receiving, by a secure service from a service, a request for a service key for accessing the service, the request for the service key including an indication of using a user plane security anchor (UPSA); sending a service key response including the service key from the secure service in response to the request for the service key; receiving an indication of a UPSA key, the indication including an identifier of the UPSA for the service; generating the UPSA key based on the identifier of the UPSA; and sending the generated UPSA key to the UPSA for establishing a user plane security context between the UPSA and a wireless device.
Owner:QUALCOMM INC

Communication method, communication device, communication system, and program product

Embodiments of the present disclosure relate to a communication method, a communication device, a communication system and a program product. The communication method comprises: receiving a first message sent by a terminal, the first message comprising: an identifier of the terminal and first information sent to a second network function; and sending a second message to the terminal, the second message comprising: response information of the first information sent by the second network function to the terminal; wherein the response information of the first information is protected by using a first security context, and the first security context is a security context related to a non-access stratum related to the second network function.
Owner:BEIJING XIAOMI MOBILE SOFTWARE CO LTD

Authentication and key management for roaming using applications

Devices, methods, and systems are disclosed for enabling roaming using authentication and key management for applications. A device (800) includes a processor (805) that determines a serving network of a user equipment ("UE") device, the serving network comprising a visited public land mobile network ("VPLMN") that is different from a home PLMN ("HPLMN") associated with the UE. The processor (805) selects a network function within the serving network for providing an authentication and key management ("AKMA") security context for an application function ("AF") based on a name of the serving network. The device (800) includes a transceiver (825) that sends the security context to the network function.
Owner:LENOVO (SINGAPORE) PTE LTD

Unlimited reprovisionable hardware root of trust

Technologies for protecting a secure context in a hardware root of trust (ROT) are described. One hardware ROT includes key generation logic and a cryptographic circuit. The key generation logic generates a first key from a value, corresponding to a physical variation of the hardware ROT, and first helper data associated with the physical variation of the hardware ROT. The key generation logic generates a second key from the value and second helper data associated with the physical variation of the hardware ROT. The cryptographic circuit receives a first encrypted secure context from off-chip storage and decrypts the first encrypted secure context using the first key to obtain a secure context. The cryptographic circuit encrypts the secure context using the second key to obtain a second encrypted secure context and stores the second encrypted secure context in the off-chip storage.
Owner:CRYPTOGRAPHY RESEARCH INC

Reuse of Security Context for Access and Registration

Embodiments include methods for a user equipment (UE) configured to communicate with a communications network via a first access network. Such methods include, without registering with the communications network, receiving from the communications network an authentication-related message. Such methods include generating the following based on the authentication-related message: a first security key usable for establishing a secure connection with the first access network, and second security key(s) usable for communicating with the communications network. Such methods include establishing a secure connection with the first access network based on the first security key and registering with the communication network based on at least one of the second security keys. Other embodiments include complementary methods for first, second, and third network nodes or functions (NNFs) of the communications network, as well as UEs and NNFs configured to perform such methods.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

A Linux kernel-based password device master-slave cluster load balancing method

PendingCN122394795APasswordinit
The application discloses a kind of based on Linux kernel's cryptographic device master-standby cluster load balancing method, it is related to information security and high-availability cluster technical field, including the following steps: step one, at least one main cryptographic device node is configured with at least one backup cryptographic device node, and cryptographic service program is deployed on all nodes to initialize cluster configuration, Keepalived service module is deployed in main cryptographic device node and backup cryptographic device node, periodically send heartbeat message by groupcast mode, and real-time perception node state;Step two, set up health detection module, and adopt dual detection mechanism of node survival detection and cryptographic service availability detection;It can realize that cryptographic device master-standby automatically switches quickly, load intelligent distribution, security context real-time synchronization, comprehensively improve the availability of cryptographic service, reliability, efficiency and security, meet the high-level security needs of critical information system.
Owner:BEIJING CATHAY INTERNET INFORMATION TECH CO LTD +1

Feature refining method and device based on dynamic security context

The invention discloses a feature refining method and device based on a dynamic security context, and belongs to the technical field of network security. The method comprises the following steps: acquiring a previous round of iteration feature and a current round of security context; the last round of iteration features are features used by the malicious software detection model in the last round of training process; generating a reserved mask for the last round of iteration features by using the current round of security context; screening out reserved features from the last round of iteration features by using the reserved mask; and carrying out the current round of training on the malicious software detection model by utilizing the reserved features, and carrying out malicious software detection by utilizing the malicious software detection model obtained by the current round of training. According to the method, dynamic feature activation can be performed on the last round of iteration features by using the current round of security context, so that the malicious software detection model can focus on the reserved features most related to the current security environment during updating training, and the detection capability on novel threats is improved.
Owner:HARBIN ANTIY TECH

Unified container-based heterogeneous system communication interaction processing method and system

This invention discloses a method and system for heterogeneous system communication and interaction processing based on a unified container, relating to the fields of computer network communication and software architecture technology. The method uses a unified data processing container as the sole data carrier throughout the entire link. The container contains message header fields, business data bodies, security context, and routing metadata. The container is created when the inbound process starts and continuously loads and updates data in each processing stage until the outbound process ends or the business layer consumes the data and destroys it. During inbound processing, external requests are routed to the business layer after protocol parsing, decryption, and format conversion to an internal standard format. During outbound processing, internal standard messages are sent to the target external system after format conversion and encryption, and responses are sent back to the business layer after reverse parsing. This invention eliminates the intrusion of heterogeneous system differences into business logic through a unified data container throughout the entire link, reducing the coupling and maintenance costs of inter-system communication integration.
Owner:SHANDONG CITY COMMERCIAL BANK COOP ALLIANCE CO LTD

Apparatuses and communication methods

A wireless communication method performed by a user equipment (UE) includes establishing, via an access and mobility management function (AMF), a security context for direct non-access stratum (NAS) communication between the UE and a network function (NF) and performing secure NAS signaling between the UE and the NF using the security context.
Owner:INNOPEAK TECHNOLOGY INC

Techniques for configuring an access stratum security for a non-terrestrial network

Various aspects of the present disclosure relate to transmitting a registration request message and receiving a registration accept message in plaintext, where the registration accept message comprises an authentication token and an access stratum (AS) security command from a satellite. Aspects of the present disclosure relate to transmitting, to the satellite, an AS security mode complete message in response to the AS security command and determining an authentication result based at least in part on the authentication token. Aspects of the present disclosure relate to transmitting, to a network function, a protected non-access stratum (NAS) request message using an AS security context based at least in part on the AS security command, where the protected NAS request message comprises the authentication result and a data packet.
Owner:LENOVO (SINGAPORE) PTE LTD

Non-access stratum (NAS) security mode command and NAS count mismatch avoidance

A method includes transmitting, by a core network entity of a core network of a wireless communication system, a non-access stratum (NAS) security mode command (SMC) message to a user equipment (UE), the NAS SMC message including information about security capabilities of the UE, information for establishing a security context between the UE and the core network, and a first NAS security mode message transaction identifier (ID); receiving, by the core network entity from the UE, a NAS security mode completion message including a second NAS security mode message transaction ID; and generating, by the core network entity, a security key based on a comparison of the first NAS security mode message transaction ID and the second NAS security mode message transaction ID satisfying a condition, where the security key is usable to secure communications between the UE and a device of an access network of the wireless communication system.
Owner:NOKIA TECHNOLOGIES OY

Multilevel cache security

In the described example, the coherent memory system includes a central processing unit (CPU) and level 1 and level 2 caches. The CPU is configured to execute program instructions (1000) to manipulate data in at least a first or second security context. Each of the first and second caches stores (e.g., 1050) a security code indicating the at least first or second security context through which data of a corresponding cache line is received. The level 1 and level 2 caches maintain coherence by comparing (1020) the security code of the corresponding cache line and performing a cache coherence operation (1030) in response.
Owner:TEXAS INSTRUMENTS INC

Registration access method and apparatus

Disclosed in the embodiments of the present application are a registration access method and apparatus. The method comprises: executing PLMN selection to search for an available PLMN; on the basis of the available PLMN and PLMN information stored in each of a plurality of SIM cards, selecting a target SIM card from among the plurality of SIM cards; and initiating registration access on the basis of security context stored in the target SIM card. By using the embodiments of the present application, one SIM card is selected by means of the found available PLMN and the PLMN information stored in each SIM card, and then registration is initiated by means of the security context in the selected SIM card, so as to prevent registration process failures caused by the available PLMN differing from a registered PLMN stored in the SIM card, improve the success rate of registration, and prevent re-authorization and re-authentication or prevent the security context from being acquired from a mobility management network element of a previous PLMN, thereby improving registration efficiency and reducing signaling overhead.
Owner:HUAWEI TECH CO LTD

Pattern selection for integration architecture

A system and method are disclosed for managing integration patterns among a plurality of nodes in a networked environment. Each node is assigned a unique identifier, and integration patterns defining relationships between two or more nodes are represented as vectors comprising node identifiers and additional attributes such as protocol, security context, or dependencies. The vectors are validated using predefined logic and are indexed and stored within a multi-dimensional matrix according to their defining attributes. The system maintains metadata for each vector, including integration dependencies, approval status, and versioning. A graphical user interface presents the matrix as an interactive grid, enabling users to filter, select, and analyze integration patterns based on node attributes or pattern characteristics. The techniques disclosed support dynamic updates, automated governance, and compliance workflows, thereby streamlining the design, validation, and management of integration scenarios across complex computing environments.
Owner:THE HUNTINGTON NAT BANK

Communication method and device

The invention provides a communication method and device. The method comprises the following steps: receiving first downlink data of terminal equipment; when the first condition is met, a first message is sent to the first satellite or a second network device on the first satellite, the first message comprises first downlink data of the terminal device and context information of the terminal device, and the context information comprises access layer security context information and / or non-access layer context information of the terminal device; the first condition comprises one or more of the following items: the terminal equipment accesses a network through a satellite and supports a store-and-forward mode; or the communication link between the first network equipment and the first satellite is available, and the communication link cannot be established between the terminal equipment and the first satellite at present, so that the security and reliability of data transmission between the satellite and the terminal equipment can be ensured in a store-and-forward scene.
Owner:HUAWEI TECH CO LTD