Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

248 results about "Security context" patented technology

Security contexts are a message security feature and are configured by way of message security bindings. On the client side, the security context is tied to a particular channel. It is configured using the WS_SECURITY_CONTEXT_MESSAGE_SECURITY_BINDING. Behavior and lifetime of the context are determined by the channel.

Dynamic access blocking method based on zero trust

The invention relates to the technical field of network security, in particular to a dynamic access blocking method based on zero trust. Comprising the following steps: step 1, collecting whole network flow data in real time in a bypass monitoring mode through a flow mirroring function of a network switch, performing deep packet inspection analysis on the collected original flow data, and extracting network flow characteristic parameters; 2, maintaining a dynamic identity information base; 3, performing real-time behavior analysis on each network session; 4, according to the risk assessment result and the real-time security context, generating a dynamic access control strategy based on a minimum permission principle; 5, implementing access control at the network execution point; and 6, continuously monitoring the network flow and the strategy execution effect, collecting feedback data, optimizing the risk assessment model and the strategy generation algorithm based on the feedback data, and forming closed-loop control. By dynamically updating the identity and asset information, the system can identify new assets or changes in real time, so that the adaptability and response capability of a network environment are improved.
Owner:SHANDONG NETWORK SECURITY TECHNOLOGY CO LTD

AI interactive data protection method and system based on security context protocol

The invention discloses an AI interactive data protection method and system based on a security context protocol. According to the method, a client application sends a user request carrying a session identifier to an application gateway; the gateway queries a required context range and a security processing strategy according to the request type, and transmits a strategy instruction; after the SCS verifies the gateway permission, the context data is retrieved and processed according to the strategy instruction, and a security context data block is generated; the gateway assembles the user input and the security context data block into a final request according to an SCP protocol, and sends the final request to an AI model; the AI model processes the request and returns a response; after receiving the response, the gateway updates the session context and updates the stored context data; and finally, the gateway returns the response of the AI model to the client application to complete interaction. According to the method, the exposure of the sensitive context data in the system can be reduced to the greatest extent while the AI interaction effect is ensured, so that the data security and compliance of the AI application are improved.
Owner:CENTURY LONGMAI TECH

NR mobility - security considerations for l1 / l2 mobility switching of an spcell

A wireless transmit / receive unit (WTRU) may be configured to process first downlink data from a source cell using a first security context. The WTRU may receive, from the source cell, configuration information indicating one or more candidate cells for Layer 1 or Layer 2 (L1 / L2) triggered mobility (LTM). The WTRU may receive, from the source cell, a LTM indication to perform a handover (HO) to a candidate cell among the one or more candidate cells. The WTRU may determine a second security context associated with the candidate cell. The WTRU may process second downlink data based on the first security context. The WTRU may process third downlink data from the candidate cell using the second security context upon a determination that one or more of the conditions are met.
Owner:INTERDIGITAL PATENT HOLDINGS INC

Mandatory access control method and device based on process function context

The invention discloses a mandatory access control method and device based on a process function context, and the method comprises the steps: collecting a security context associated with a system call initiated by a target process, so as to generate a standardized object description; mapping the object description into a target function classification identifier, so as to obtain a process function context view of the target process according to the target function classification identifier; constructing a target decision key for access decision based on the current policy era, the qualifier, the function classification identifier, the view identifier of the process function context view and the isolation domain abstract; and querying the multi-level cache according to the target decision key to determine a matched target access decision. Therefore, context-sensitive judgment and cross-component consistency taking the functional context as the center are realized.
Owner:BEIJING METRO INFORMATION DEV CO LTD

API interface security protection method based on anomaly detection

The invention relates to the technical field of security protection, in particular to an API (Application Program Interface) security protection method based on anomaly detection, which comprises the following steps of: based on a received API request, analyzing the API request, extracting a request source network address and a target API calling instruction, and carrying out source authenticity verification and instruction validity judgment. According to the method, the initial security context is established by analyzing the source network address and the interface calling instruction of the API request in combination with the timestamp and the request type, so that the pre-modeling of the environment state of each request is realized, and the basic credibility of the request can be judged immediately before the request is subjected to deep business processing. On the basis, a sequence mode of the request load is combined with a parameter boundary for comparison, the behavior deviation degree is used as a reference item, interface sensitivity information in the context is introduced to complete quantitative judgment on the risk level, and a judgment result has dynamic adaptability and structural relevance.
Owner:SHANGHAI FULEIDE INFORMATION TECH CO LTD

System and method for immutability assurance of backup data based on comprehensive threat detection

Systems and methods for immutability assurance of backup data based on comprehensive threat detection. A method includes performing static and dynamic analysis of a process executing on a computing device, registering an operation of the process with a file on a storage communicatively coupled to the computing device, determining that the file in operation is a backup archive, collecting a context of the process, which includes at least a security context based on the static and dynamic analysis, and a backup archive context based on attributes of the backup archive, analyzing the process operation with the backup file using an access control machine-learning model that calculates an immutability rate based on the collected context, and granting or blocking the process access to the backup archived.
Owner:ACRONIS INT

Reuse of Security Context for Access and Registration

Embodiments include methods for a user equipment (UE) configured to communicate with a communications network via a first access network. Such methods include, without registering with the communications network. receiving from the communications network an authentication-related message that includes an identifier associated with the first access network and at least one of a temporary UE identifier and a security key identifier. Such methods include, based on the identifier, generating a first security key usable for establishing a secure connection with the first access network and establishing a secure connection with the first access network based on the first security key. Such methods include registering with the communications network based on the at least one of the temporary UE identifier and the security key identifier. Other embodiments include complementary methods for network nodes or functions (NNFs) of the communications network. as well as UEs and NNFs configured to perform such methods.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Cryptographic techniques in wireless communication networks

Systems and methods are disclosed for enhancing cryptographic security in 5G networks by addressing key management, algorithm selection, and security context consistency. One method ensures uniform cryptographic key lengths during Access and Mobility Function (AMF) changes, maintaining consistent Non-Access Stratum (NAS) security contexts across transitions. Another method focuses on dual connectivity scenarios, ensuring uniform cryptographic key lengths across Master Node and Secondary Node communications by defining a unified cryptographic profile and enhancing capability signaling. Additionally, an entropy-based approach to cryptographic algorithm selection is introduced, incorporating entropy assessment into the capability signaling process. This ensures that selected cryptographic algorithms for Access Stratum (AS) and NAS layers align with the actual entropy of long-term keys, providing true security levels.
Owner:KOLEKAR ABHIJEET ASHOK

Secure communication connection establishment method, data transmission method, device and equipment

The invention provides a secure communication connection establishment method, a data transmission method, a device and equipment, which can be used in the field of communication. According to the scheme, the system comprises a management node with a built-in encryption card and a terminal node. Wherein key negotiation algorithms different from those of the two nodes are configured in the encryption card. Firstly, a terminal node selects a key negotiation algorithm shared with a notification message broadcast by a management node as a target key negotiation algorithm by means of an encryption card based on a communication message broadcast by the management node, and sends an association request message to the management node. The management node and the terminal node then make a request and response of a security context message between the management node and the terminal node. And finally, after the integrity verification and the parameter verification are passed, establishing secure communication connection between the management node and the terminal node, and performing subsequent secure data transmission. According to the technical scheme, the whole process of key negotiation is completed by means of the built-in encryption cards in the management node and the terminal node, so that special requirements of users are met.
Owner:CHENGDU TD TECH LTD

Method and device for allowing application to access system resource, and terminal

The embodiment of the invention provides a method and device for allowing an application to access a system resource, and a terminal. The method includes: acquiring an operation control request of anapplication; determining a user environment where the application is about to operate according to the operation control request of the application; acquiring a safe context corresponding to the userenvironment from a plurality of preconfigured safe contexts in a system, wherein the plurality of preconfigured safe contexts in the system are corresponding to different user environments respectively, and system resource access rights corresponding to the plurality of preconfigured safe contexts are different from each other; and performing access processing on the system resource according to the system resource access right corresponding to the safe context corresponding to the user environment. The scheme can perform application behavior control on the same application under different users.
Owner:CHINA MOBILE COMM LTD RES INST +1

USB access safety control system

The invention discloses a USB access safety control system, and particularly relates to the field of USB access electric digital data processing, which comprises an identification module, an isolation module, an encryption continuous transmission module, an auditing module and a kernel interrupt signal triggered by USB physical insertion, and the identification module is used for receiving the kernel interrupt signal and writing the kernel interrupt signal into the interrupt event buffer area, generating a to-be-analyzed interrupt data group, analyzing and generating identification notification information and pushing the identification notification information as a USB access snapshot data frame. Strong binding of USB device access identities, interval control of permission states and traceable closed management of behavior tracks are achieved by constructing a security context vector with device fingerprints, authorization group IDs and insertion timestamps as cores and forming a dynamic association verification path among isolation state judgment, behavior integrity measurement and chain audit account books. The key problems of equipment loopback cheating, permission mismatching, audit failure and the like are solved.
Owner:GUANGZHOU HONGYING INFORMATION TECH CO LTD

Security authentication multi-start method for Linux system of development board

The invention discloses a development board Linux system security authentication multi-start method, which comprises the steps of 1, hardware trust root initialization and storage area division, 2, hardware trust root self-inspection and measurement, 3, starting item dynamic loading and multi-stage authentication, 4, security context establishment and system switching, and 5, multi-system isolation and collaboration. Step 6, performing security audit and exception handling; full-link authentication is realized by taking a hardware trust root as an anchor point, malicious mirror startup and inter-system data leakage are effectively resisted in combination with a storage and resource isolation mechanism, scenes such as on-demand dynamic switching, flexible adaptation debugging, upgrading and fault recovery of multiple systems can be realized, and the system reliability is improved by optimizing the lightweight design of an authentication algorithm and resource management. Limited computing power of the development board is adapted, the starting process and abnormal events can be completely recorded, and illegal operation can be traced conveniently.
Owner:BEIJING XUNWEI ELECTRONICS CO LTD

Web workflow system and method based on JSON data analysis

The invention provides a Web workflow system and method based on JSON data analysis, and relates to the technical field of workflow design. A standardized JSON process definition file is generated by adopting a visual process designer, process semantic verification and BPMN conversion are realized through a three-level analysis architecture, and efficient management of the whole process of process modeling, execution and auditing is realized in combination with a plug-in task executor, a thread security context manager and a process monitoring module, so that the process modeling, execution and auditing efficiency is improved. The method has the advantages of fast analysis, strong expansion, easy collaboration, traceability and the like.
Owner:CHINA UNICOM XIONGAN IND INTERNET CO LTD

Hybrid encryption method and device and storage medium

The invention provides a hybrid encryption method and device and a storage medium, and the method comprises the steps: a client generates a short-term SM2 key pair and exchanges with a server after obtaining a long-term SM2 key pair and a server public key, dynamically generates a session SM4 symmetric key through an SM2 key exchange protocol, and finally achieves the data transmission and response processing through the session SM4 symmetric key. Through the implementation of the scheme of the invention, the client not only establishes the basic trust relationship based on the long-term SM2 key pair, but also generates the short-term SM2 key pair during each service request, and dynamically derives a unique session SM4 symmetric key and an initial vector by cooperatively executing the SM2 key exchange protocol with the short-term key of the server. And each request has an independent security context, so that the decryption risk after the session key is reused or stolen is fundamentally prevented, and the end-to-end dynamic security communication under the national secret system is really realized.
Owner:SHANGHAI FEIWEI INFORMATION TECH CO LTD +2

Dynamic expansion service node management method based on Camuda process engine

The invention discloses a method for managing service nodes capable of being dynamically expanded based on a Camuda process engine, which belongs to the technical field of electric digital data processing and comprises the following steps of: uniformly configuring service process nodes into a pointing proxy delegation class; querying an external mapping table based on the execution context to obtain a business logic unit identifier; obtaining metadata from a logic registration center according to the identifier, and dynamically loading and instantiating a business logic implementation class through a sandbox class loader; driving service logic execution through a security context object of a white list only exposure method; and recording a full-link audit log. According to the method, structural decoupling of process definition and service logic is realized, so that the process definition does not need to be modified during service change, and dynamic replacement and gray release are supported; through sandbox isolation and security agent, isolated operation of dynamic codes and security and stability of an engine are ensured; and in combination with an audit tracking and fusing mechanism, the observability, the reliability and the operation and maintenance efficiency of the system are improved.
Owner:SUZHOU REKTEC INFORMATION TECH CO LTD

Protecting machine learning models in a wireless communication network

There is provided a method in a Network Data Analytics Function containing a Model Training logical function. The method comprises receiving a machine learning (ML) model provision request, the ML model provision request comprising: an identifier for at least one Analytic, and, ML model file specific information, and generating a protected trained ML model using a stored security context. The method further comprises sending, in response to the ML model provision request, an ML model provision response message, the ML model provision response message comprising: the identifier for the at least one Analytic; at least one protected trained ML model file; and location information of the stored security context.
Owner:LENOVO (SINGAPORE) PTE LTD

Security protection method and device, communication equipment, medium and product

The invention relates to a security protection method and device, communication equipment, a medium and a product. The method comprises the following steps: receiving a service data packet sent by a service participant; analyzing the service data packet to obtain a security context identifier in the service data packet; the security context identifier corresponds to a service scene of the service participant; determining a target security protection strategy matched with the security context identifier; and performing security protection processing on the service data packet according to the target security protection strategy. Different business scenes correspond to different security context identifiers, so that different target security protection strategies can be matched, different security protection processing is realized, and security requirements of different business scenes are met. Security protection of business scene differentiation can be realized even for business data packets of the same IP address and port, and business scene pertinence of security protection processing is improved.
Owner:CHINA TELECOM CORP LTD +1

User equipment communicating with at least two of a plurality of network functions or services of a telecommunications network

The invention relates to a method for operating a user equipment with a telecommunications network and for communicating with at least two of a plurality of network functions or services of the telecommunications network or of a further telecommunications network, the plurality of network functions or services being able to provide different kinds of network function functionalities, wherein the user equipment is operated using at least a first non-access stratum communication link and a second non-access stratum communication link, the first non-access stratum communication link being established between the user equipment and a first network function or service of the plurality of network functions or services, and the second non-access stratum communication link being established between the user equipment and a second network function or service, wherein the first non-access stratum communication link involves establishing a first non-access stratum security context between the user equipment and the first network function or service and the second non-access stratum communication link involves establishing a second non-access stratum security context between the user equipment and the second network function or service, wherein the operation of the user equipment, using at least the first and second non-access stratum communication links, comprises the following steps: —in a first step, the first non-access stratum communication link as well as the first non-access stratum security context is established using a first non-access stratum endpoint information, and the second non-access stratum communication link as well as the second non-access stratum security context is established using a second non-access stratum endpoint information, —in a second step, the first and second non-access stratum communication links are used between their respective endpoints, wherein a first information element of or transmitted using the first non-access stratum security context is able to be referenced by a second information element of or transmitted using the second considered non-access stratum security context and / or wherein a first information element of or transmitted using the first non-access stratum security context is able to reference a second information element of or transmitted using the second considered non-access stratum security context.
Owner:DEUTSCHE TELEKOM AG

First class database object server application

A data platform for managing an application as a first-class database object. The data platform includes at least one processor and a memory storing instructions that cause the at least one processor to perform operations including detecting a data request from a browser for a data object located on the data platform, executing a stored procedure, the stored procedure containing instructions that cause the at least one processor to perform additional operations including instantiating a User Defined Function (UDF) server, an application engine, and the application within a security context of the data platform based on a security policy determined by an owner of the data object. The data platform then communicates with the browser using the application engine as a proxy server.
Owner:SNOWFLAKE INC

Reuse of Security Context for Access and Registration

Embodiments include methods for a user equipment (UE) configured to communicate with a communications network via at least a first access network. Such methods include, without registering with the communications network, receiving from the communications network an identifier associated with the first access network and an indication of security algorithms to use when communicating with the communications network. Such methods include, based on the identifier associated with the first access network, generating a first security key usable for establishing a secure connection with the first access network and establishing a secure connection with the first access network based on the first security key. Such methods include registering with the communications network using the indicated security algorithms. Other embodiments include complementary methods for network nodes or functions (NNFs) of the communications network, as well as UEs and NNFs configured to perform such methods.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Security policy management

PendingUS20260095487A1Securing communicationEngineeringSecurity policy management
In various examples, input queries (e.g. open user queries) are used combination with predefined queries to perform security policy-related actions using a generative machine learning (GML) model or GML models. In one example, an input query relating to a security policy is matched with a predefined query stored in an instruction database. In some examples, the instruction database contains examples of structured configuration data, which in turn can be used by a GML model to configure a predetermined extractor code module to perform a specific policy-related action. In other examples, a security context relating to a security policy is used together with an input query and template query to generate a GML model query. In some examples, the two approaches are combined.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

AI interactive data protection method and system based on security context protocol

The present application discloses a method and system for protecting AI interactive data based on a secure context protocol. The method comprises the following steps: a client application sends a user request carrying a session identifier to an application gateway; the gateway queries the required context scope and security processing policy according to the request type, and transmits policy instructions; after the SCS verifies the gateway's authority, it retrieves the context data and processes it according to the policy instructions to generate a secure context data block; the gateway assembles the user input and the secure context data block into a final request according to the SCP protocol and sends it to the AI ​​model; the AI ​​model processes the request and returns a response; after receiving the response, the gateway updates the session context and the stored context data; finally, the gateway returns the response of the AI ​​model to the client application to complete the interaction. This method can minimize the exposure of sensitive context data within the system while ensuring the effect of AI interaction, thereby improving the data security and compliance of AI applications.
Owner:CENTURY LONGMAI TECH

Zero-trust video data access privacy protection method and system

The invention relates to the technical field of video security and protection, and discloses a zero-trust video data access privacy protection method and system, and the method comprises the steps: carrying out the semantic perception analysis of a video data access request of an access subject, and obtaining a subject identifier, a request access action and target video data; performing identity verification on the access subject, and performing digital signature packaging on a verification result and a security context attribute of the access subject to obtain an identity token; performing access credibility evaluation on the access subject to obtain a real-time credibility; performing privacy sensitivity analysis on the target video data to obtain a content sensitivity label; performing differential desensitization planning on the target video data to obtain a fine-grained desensitization strategy; performing an access control decision on the target video data, and generating a complete access audit log; performing incremental updating on the behavior baseline and the historical access behavior log; according to the invention, the efficiency of zero-trust video data access privacy protection can be improved.
Owner:NAVAL UNIV OF ENG PLA

A security context generation method, device and computer-readable storage medium

Embodiments of the present invention disclose a security context generation method, apparatus, and computer-readable storage medium, including: a terminal device obtaining a first security context, the first security context being used to protect a first communication service of the terminal device; the terminal device sending a session request message to a session management function network element, the session request message being used to request establishment of a session for a second communication service, the second communication service being different from the first communication service; the terminal device receiving a session accept message from the session management function network element, the session accept message being used to complete establishment of the session for the second communication service; the terminal device obtaining an additional generation indication; and the terminal device obtaining a second security context based on the additional generation indication, the second security context being used to protect the second communication service. In this embodiment of the present invention, by protecting different communication services through different security contexts, the security of the communication services can be improved.
Owner:HUAWEI TECH CO LTD

User plane security anchor for wireless network service security architecture

Apparatus, methods, and computer-readable media for performing wireless communication are disclosed. For example, a method for securely accessing a service may include receiving, by a secure service from a service, a request for a service key for accessing the service, the request for the service key including an indication of using a user plane security anchor (UPSA); sending a service key response including the service key from the secure service in response to the request for the service key; receiving an indication of a UPSA key, the indication including an identifier of the UPSA for the service; generating the UPSA key based on the identifier of the UPSA; and sending the generated UPSA key to the UPSA for establishing a user plane security context between the UPSA and a wireless device.
Owner:QUALCOMM INC

Communication method, communication device, communication system, and program product

Embodiments of the present disclosure relate to a communication method, a communication device, a communication system and a program product. The communication method comprises: receiving a first message sent by a terminal, the first message comprising: an identifier of the terminal and first information sent to a second network function; and sending a second message to the terminal, the second message comprising: response information of the first information sent by the second network function to the terminal; wherein the response information of the first information is protected by using a first security context, and the first security context is a security context related to a non-access stratum related to the second network function.
Owner:BEIJING XIAOMI MOBILE SOFTWARE CO LTD

Authentication and key management for roaming using applications

Devices, methods, and systems are disclosed for enabling roaming using authentication and key management for applications. A device (800) includes a processor (805) that determines a serving network of a user equipment ("UE") device, the serving network comprising a visited public land mobile network ("VPLMN") that is different from a home PLMN ("HPLMN") associated with the UE. The processor (805) selects a network function within the serving network for providing an authentication and key management ("AKMA") security context for an application function ("AF") based on a name of the serving network. The device (800) includes a transceiver (825) that sends the security context to the network function.
Owner:LENOVO (SINGAPORE) PTE LTD

Unlimited reprovisionable hardware root of trust

Technologies for protecting a secure context in a hardware root of trust (ROT) are described. One hardware ROT includes key generation logic and a cryptographic circuit. The key generation logic generates a first key from a value, corresponding to a physical variation of the hardware ROT, and first helper data associated with the physical variation of the hardware ROT. The key generation logic generates a second key from the value and second helper data associated with the physical variation of the hardware ROT. The cryptographic circuit receives a first encrypted secure context from off-chip storage and decrypts the first encrypted secure context using the first key to obtain a secure context. The cryptographic circuit encrypts the secure context using the second key to obtain a second encrypted secure context and stores the second encrypted secure context in the off-chip storage.
Owner:CRYPTOGRAPHY RESEARCH INC

Reuse of Security Context for Access and Registration

Embodiments include methods for a user equipment (UE) configured to communicate with a communications network via a first access network. Such methods include, without registering with the communications network, receiving from the communications network an authentication-related message. Such methods include generating the following based on the authentication-related message: a first security key usable for establishing a secure connection with the first access network, and second security key(s) usable for communicating with the communications network. Such methods include establishing a secure connection with the first access network based on the first security key and registering with the communication network based on at least one of the second security keys. Other embodiments include complementary methods for first, second, and third network nodes or functions (NNFs) of the communications network, as well as UEs and NNFs configured to perform such methods.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)