Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

135 results about "Security context" patented technology

Security contexts are a message security feature and are configured by way of message security bindings. On the client side, the security context is tied to a particular channel. It is configured using the WS_SECURITY_CONTEXT_MESSAGE_SECURITY_BINDING. Behavior and lifetime of the context are determined by the channel.

Mandatory access control method and device based on process function context

The invention discloses a mandatory access control method and device based on a process function context, and the method comprises the steps: collecting a security context associated with a system call initiated by a target process, so as to generate a standardized object description; mapping the object description into a target function classification identifier, so as to obtain a process function context view of the target process according to the target function classification identifier; constructing a target decision key for access decision based on the current policy era, the qualifier, the function classification identifier, the view identifier of the process function context view and the isolation domain abstract; and querying the multi-level cache according to the target decision key to determine a matched target access decision. Therefore, context-sensitive judgment and cross-component consistency taking the functional context as the center are realized.
Owner:BEIJING METRO INFORMATION DEV CO LTD

Method and device for allowing application to access system resource, and terminal

ActiveCN108062483ADigital data protectionSecurity contextUser environment
The embodiment of the invention provides a method and device for allowing an application to access a system resource, and a terminal. The method includes: acquiring an operation control request of anapplication; determining a user environment where the application is about to operate according to the operation control request of the application; acquiring a safe context corresponding to the userenvironment from a plurality of preconfigured safe contexts in a system, wherein the plurality of preconfigured safe contexts in the system are corresponding to different user environments respectively, and system resource access rights corresponding to the plurality of preconfigured safe contexts are different from each other; and performing access processing on the system resource according to the system resource access right corresponding to the safe context corresponding to the user environment. The scheme can perform application behavior control on the same application under different users.
Owner:CHINA MOBILE COMM LTD RES INST +1

Security authentication multi-start method for Linux system of development board

The invention discloses a development board Linux system security authentication multi-start method, which comprises the steps of 1, hardware trust root initialization and storage area division, 2, hardware trust root self-inspection and measurement, 3, starting item dynamic loading and multi-stage authentication, 4, security context establishment and system switching, and 5, multi-system isolation and collaboration. Step 6, performing security audit and exception handling; full-link authentication is realized by taking a hardware trust root as an anchor point, malicious mirror startup and inter-system data leakage are effectively resisted in combination with a storage and resource isolation mechanism, scenes such as on-demand dynamic switching, flexible adaptation debugging, upgrading and fault recovery of multiple systems can be realized, and the system reliability is improved by optimizing the lightweight design of an authentication algorithm and resource management. Limited computing power of the development board is adapted, the starting process and abnormal events can be completely recorded, and illegal operation can be traced conveniently.
Owner:BEIJING XUNWEI ELECTRONICS CO LTD

Dynamic expansion service node management method based on Camuda process engine

The invention discloses a method for managing service nodes capable of being dynamically expanded based on a Camuda process engine, which belongs to the technical field of electric digital data processing and comprises the following steps of: uniformly configuring service process nodes into a pointing proxy delegation class; querying an external mapping table based on the execution context to obtain a business logic unit identifier; obtaining metadata from a logic registration center according to the identifier, and dynamically loading and instantiating a business logic implementation class through a sandbox class loader; driving service logic execution through a security context object of a white list only exposure method; and recording a full-link audit log. According to the method, structural decoupling of process definition and service logic is realized, so that the process definition does not need to be modified during service change, and dynamic replacement and gray release are supported; through sandbox isolation and security agent, isolated operation of dynamic codes and security and stability of an engine are ensured; and in combination with an audit tracking and fusing mechanism, the observability, the reliability and the operation and maintenance efficiency of the system are improved.
Owner:SUZHOU REKTEC INFORMATION TECH CO LTD

Security policy management

PendingUS20260095487A1Securing communicationEngineeringSecurity policy management
In various examples, input queries (e.g. open user queries) are used combination with predefined queries to perform security policy-related actions using a generative machine learning (GML) model or GML models. In one example, an input query relating to a security policy is matched with a predefined query stored in an instruction database. In some examples, the instruction database contains examples of structured configuration data, which in turn can be used by a GML model to configure a predetermined extractor code module to perform a specific policy-related action. In other examples, a security context relating to a security policy is used together with an input query and template query to generate a GML model query. In some examples, the two approaches are combined.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Zero-trust video data access privacy protection method and system

The invention relates to the technical field of video security and protection, and discloses a zero-trust video data access privacy protection method and system, and the method comprises the steps: carrying out the semantic perception analysis of a video data access request of an access subject, and obtaining a subject identifier, a request access action and target video data; performing identity verification on the access subject, and performing digital signature packaging on a verification result and a security context attribute of the access subject to obtain an identity token; performing access credibility evaluation on the access subject to obtain a real-time credibility; performing privacy sensitivity analysis on the target video data to obtain a content sensitivity label; performing differential desensitization planning on the target video data to obtain a fine-grained desensitization strategy; performing an access control decision on the target video data, and generating a complete access audit log; performing incremental updating on the behavior baseline and the historical access behavior log; according to the invention, the efficiency of zero-trust video data access privacy protection can be improved.
Owner:NAVAL UNIV OF ENG PLA

User plane security anchor for wireless network service security architecture

Apparatus, methods, and computer-readable media for performing wireless communication are disclosed. For example, a method for securely accessing a service may include receiving, by a secure service from a service, a request for a service key for accessing the service, the request for the service key including an indication of using a user plane security anchor (UPSA); sending a service key response including the service key from the secure service in response to the request for the service key; receiving an indication of a UPSA key, the indication including an identifier of the UPSA for the service; generating the UPSA key based on the identifier of the UPSA; and sending the generated UPSA key to the UPSA for establishing a user plane security context between the UPSA and a wireless device.
Owner:QUALCOMM INC

Unlimited reprovisionable hardware root of trust

Technologies for protecting a secure context in a hardware root of trust (ROT) are described. One hardware ROT includes key generation logic and a cryptographic circuit. The key generation logic generates a first key from a value, corresponding to a physical variation of the hardware ROT, and first helper data associated with the physical variation of the hardware ROT. The key generation logic generates a second key from the value and second helper data associated with the physical variation of the hardware ROT. The cryptographic circuit receives a first encrypted secure context from off-chip storage and decrypts the first encrypted secure context using the first key to obtain a secure context. The cryptographic circuit encrypts the secure context using the second key to obtain a second encrypted secure context and stores the second encrypted secure context in the off-chip storage.
Owner:CRYPTOGRAPHY RESEARCH INC

A Linux kernel-based password device master-slave cluster load balancing method

PendingCN122394795APasswordinit
The application discloses a kind of based on Linux kernel's cryptographic device master-standby cluster load balancing method, it is related to information security and high-availability cluster technical field, including the following steps: step one, at least one main cryptographic device node is configured with at least one backup cryptographic device node, and cryptographic service program is deployed on all nodes to initialize cluster configuration, Keepalived service module is deployed in main cryptographic device node and backup cryptographic device node, periodically send heartbeat message by groupcast mode, and real-time perception node state;Step two, set up health detection module, and adopt dual detection mechanism of node survival detection and cryptographic service availability detection;It can realize that cryptographic device master-standby automatically switches quickly, load intelligent distribution, security context real-time synchronization, comprehensively improve the availability of cryptographic service, reliability, efficiency and security, meet the high-level security needs of critical information system.
Owner:BEIJING CATHAY INTERNET INFORMATION TECH CO LTD +1

Feature refining method and device based on dynamic security context

The invention discloses a feature refining method and device based on a dynamic security context, and belongs to the technical field of network security. The method comprises the following steps: acquiring a previous round of iteration feature and a current round of security context; the last round of iteration features are features used by the malicious software detection model in the last round of training process; generating a reserved mask for the last round of iteration features by using the current round of security context; screening out reserved features from the last round of iteration features by using the reserved mask; and carrying out the current round of training on the malicious software detection model by utilizing the reserved features, and carrying out malicious software detection by utilizing the malicious software detection model obtained by the current round of training. According to the method, dynamic feature activation can be performed on the last round of iteration features by using the current round of security context, so that the malicious software detection model can focus on the reserved features most related to the current security environment during updating training, and the detection capability on novel threats is improved.
Owner:HARBIN ANTIY TECH

Apparatuses and communication methods

A wireless communication method performed by a user equipment (UE) includes establishing, via an access and mobility management function (AMF), a security context for direct non-access stratum (NAS) communication between the UE and a network function (NF) and performing secure NAS signaling between the UE and the NF using the security context.
Owner:INNOPEAK TECHNOLOGY INC

Non-access stratum (NAS) security mode command and NAS count mismatch avoidance

A method includes transmitting, by a core network entity of a core network of a wireless communication system, a non-access stratum (NAS) security mode command (SMC) message to a user equipment (UE), the NAS SMC message including information about security capabilities of the UE, information for establishing a security context between the UE and the core network, and a first NAS security mode message transaction identifier (ID); receiving, by the core network entity from the UE, a NAS security mode completion message including a second NAS security mode message transaction ID; and generating, by the core network entity, a security key based on a comparison of the first NAS security mode message transaction ID and the second NAS security mode message transaction ID satisfying a condition, where the security key is usable to secure communications between the UE and a device of an access network of the wireless communication system.
Owner:NOKIA TECHNOLOGIES OY

Multilevel cache security

In the described example, the coherent memory system includes a central processing unit (CPU) and level 1 and level 2 caches. The CPU is configured to execute program instructions (1000) to manipulate data in at least a first or second security context. Each of the first and second caches stores (e.g., 1050) a security code indicating the at least first or second security context through which data of a corresponding cache line is received. The level 1 and level 2 caches maintain coherence by comparing (1020) the security code of the corresponding cache line and performing a cache coherence operation (1030) in response.
Owner:TEXAS INSTRUMENTS INC

Registration access method and apparatus

Disclosed in the embodiments of the present application are a registration access method and apparatus. The method comprises: executing PLMN selection to search for an available PLMN; on the basis of the available PLMN and PLMN information stored in each of a plurality of SIM cards, selecting a target SIM card from among the plurality of SIM cards; and initiating registration access on the basis of security context stored in the target SIM card. By using the embodiments of the present application, one SIM card is selected by means of the found available PLMN and the PLMN information stored in each SIM card, and then registration is initiated by means of the security context in the selected SIM card, so as to prevent registration process failures caused by the available PLMN differing from a registered PLMN stored in the SIM card, improve the success rate of registration, and prevent re-authorization and re-authentication or prevent the security context from being acquired from a mobility management network element of a previous PLMN, thereby improving registration efficiency and reducing signaling overhead.
Owner:HUAWEI TECH CO LTD

Pattern selection for integration architecture

A system and method are disclosed for managing integration patterns among a plurality of nodes in a networked environment. Each node is assigned a unique identifier, and integration patterns defining relationships between two or more nodes are represented as vectors comprising node identifiers and additional attributes such as protocol, security context, or dependencies. The vectors are validated using predefined logic and are indexed and stored within a multi-dimensional matrix according to their defining attributes. The system maintains metadata for each vector, including integration dependencies, approval status, and versioning. A graphical user interface presents the matrix as an interactive grid, enabling users to filter, select, and analyze integration patterns based on node attributes or pattern characteristics. The techniques disclosed support dynamic updates, automated governance, and compliance workflows, thereby streamlining the design, validation, and management of integration scenarios across complex computing environments.
Owner:THE HUNTINGTON NAT BANK

Communication method, data processing system, and related device

PCT designated stageWO2026137866A1Data processing systemHandling system
A communication method, a data processing system, and a related device, which relate to the technical field of communications. The method comprises: a first node sending to a second node a first message, which is used for requesting the establishment of a secure connection; when the security connection is not established for the first time, the second node generating authentication information on the basis of a historical security context, and sending to the first node a second message, which comprises the authentication information, wherein the historical security context is generated during the establishment of a security connection between the first node and the second node in a past time period; and the first node verifying the authentication information on the basis of the historical security context, wherein when the authentication information passes the verification, the first node and the second node communicate with each other on the basis of the security connection requested in the first message. In this way, during the establishment of a secure connection, it is not necessary for a first node and a second node to execute the generation of a security context, such that the process of establishing a secure connection between the two nodes can be accelerated, and a data communication delay between the two nodes is reduced.
Owner:HUAWEI TECH CO LTD

Hybrid networking method for 5G and quantum communication

The invention relates to the technical field of mobile communication and quantum security, and discloses a 5G and quantum communication hybrid networking method, which comprises the following steps: S1, pre-establishing hierarchical quantum links between a user equipment unit and a plurality of potential switching target base stations; s2, generating an initial session key and a corresponding first quantum security context abstract; s3, migrating the first context abstract to a target base station, and pre-generating a standby session key associated with the first context abstract; and S4, activating the standby session key, and generating a new second quantum security context abstract. According to the invention, a key negotiation process and a switching execution process are decoupled, non-inductive switching of the quantum security session is realized through a mechanism of pre-building resources, pre-generating a key and instantly activating, a continuous trust chain of security context is constructed, and the continuity and security of mobile communication are remarkably improved.
Owner:SHAANXI JINJUE ENTERPRISE GROUP CO LTD

Adaptive data collection in vehicles for enhanced privacy and data security

ActiveUS12675601B2In vehicleData acquisition
Techniques for adapting data collection in vehicles for enhanced security and privacy are provided. A computer-implemented method, performed by a data processing device of a vehicle, comprises A computer-implemented method performed by a data processing device of a vehicle, comprises determining whether a context of the vehicle corresponds to a security restricted context associated with one or more restrictions related to data capable of being collected via one or more data collection devices integrated on or within the vehicle and communicatively coupled to the data processing device. The method further comprises, in response to a determination that the context corresponds to the security restricted context, rendering, via an electronic output device located on or within the vehicle and communicatively coupled to the data processing device, notification data informing one or more occupants of the vehicle that the context of the vehicle corresponds to the restricted security context.
Owner:VOLVO CAR CORP

A metadata-driven report compliance generation method and system

The application discloses a kind of report compliance generation method and system based on metadata driving, belong to data processing technical field.The method includes: the original metadata of heterogeneous database is collected, is converted into unified metadata model;In response to report configuration operation generation semi-structured SQL template;In response to report query request, build security context, execute SQL after injecting permission condition and obtain query result set;In response to data entry operation, load compliance rule, and check business data object by rule engine;When check does not satisfy and is configured as automatic silent execution mode, execute correction in memory, and write the correction data into business table in the same database transaction, simultaneously change context is written into audit log table;In response to export request, stream generation data file.The application realizes automatic compliance correction, and guarantees rule consistency in heterogeneous database environment based on unified metadata model by atomicity audit, efficiency and compliance are considered.
Owner:SHANDONG CITY COMMERCIAL BANK COOP ALLIANCE CO LTD

5G and TSN communication device and system

The invention provides a 5G and TSN communication device and system, relates to the technical field of 5G and TSN communication, and is used for enhancing the security of data transmission between 5G network equipment and TSN network equipment through transfer equipment. The device comprises a forwarding module used for receiving 5G original data sent by a 5G network device; the security context extraction module is used for obtaining a 5G security context based on the 5G original data and obtaining a security policy based on the 5G security context; the encryption and decryption module is used for performing first decryption processing on the 5G original data and then performing first encryption processing on the decrypted 5G original data based on a security policy to obtain first to-be-transmitted data; and the forwarding module is also used for converting the first to-be-transmitted data into first target data conforming to the TSN transmission specification, and sending the first target data to the TSN network equipment.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD

Communication method and device and computer readable storage medium

The invention provides a communication method and device and a computer readable storage medium, and the method comprises the steps: obtaining first information related to a first satellite, and enabling the first information related to different satellites to be different; generating a first key based on first information associated with the first satellite; and performing NAS security protection between a second network element and the terminal device based on the first key, wherein the second network element is deployed in the first satellite. According to the embodiment of the invention, the NAS security context can be established between the terminal equipment and the first satellite, the NAS security key between the terminal equipment and the first satellite can be generated based on the first information associated with the first satellite, and the first information associated with different satellites is different, so that the security protection of the NAS message under the MME-split architecture can be realized.
Owner:HUAWEI TECH CO LTD

Communication method and communication device

The communication method comprises the steps that a first communication device receives a first request message from a second communication device, the first request message comprises a first ciphertext and first indication information, the first ciphertext is first data subjected to security protection through a first security context, and the first indication information is used for indicating homomorphic encryption of the first ciphertext; the first communication device receives the first security context, performs homomorphic encryption on the first ciphertext to generate a second ciphertext, and sends the second ciphertext to the second network element, the first security context is determined by negotiation of the second communication device and the second network element, and the homomorphic encrypted ciphertext supports to be processed in a ciphertext state. In the communication method, the second network element can process the second ciphertext, the second communication device only needs to perform security protection on the data based on the first security context, and the second communication device does not need to execute homomorphic encryption. On the premise of reducing the encryption overhead of the second communication device, the core network processes the terminal ciphertext data.
Owner:HUAWEI TECH CO LTD

Communication method and device, and storage medium

PCT designated stageWO2026065171A1Security arrangementSecure communicationEngineering
The present disclosure relates to communication method and device, and a storage medium. The method comprises: sending a first message to a second network element, wherein the first message is used for updating a first security context, and the first security context is used for performing security protection on communication between a terminal and a first network element and communication between the terminal and the second network element, or performing security protection on communication between the terminal and the second network element; and updating the first security context. That is to say, when security protection is performed on communication between the terminal and the second network element by means of the first security context, the first security context can be updated by means of the first network element, thereby implementing secure communication in a multi-NAS architecture.
Owner:BEIJING XIAOMI MOBILE SOFTWARE CO LTD

Enhanced paging service with identity management for wireless networks

Apparatus, methods, and computer-readable media for performing wireless communication are disclosed. For example, a process for wireless communication may include sending a service registration request to an identity and routing service, where the service registration request includes a service identifier for a network service, where the network service is independent of the identity and routing service; receiving a first temporary service identifier (TSID) for the network service from the identity and routing service; assigning a first temporary device identifier (TUID) to the device; and sending the first TSID and the first TUID to the device for the first security context.
Owner:QUALCOMM INC

Method and apparatus for enforcing access control based on process functional context

The application discloses a method and device for enforcing access control based on process function context, wherein the method comprises: collecting a security context associated with a system call initiated by a target process to generate a standardized object description; mapping the object description to a target function classification identifier to obtain a process function context view of the target process according to the target function classification identifier; constructing a target decision key for an access decision based on a current policy epoch, a qualifier, a function classification identifier, a view identifier of the process function context view and an isolation domain digest; and querying a multi-level cache according to the target decision key to determine a matching target access decision. Thus, context-sensitive decision based on a function context is realized, and cross-component consistency is achieved.
Owner:BEIJING METRO INFORMATION DEV CO LTD

A content security protection method, an electronic device and a computer readable storage medium

PendingCN122346851AMultiple injectionAlgorithm
The application discloses a content security protection method, an electronic device and a computer readable storage medium, relates to the technical field of artificial intelligence security, and comprises the following steps: dividing to-be-protected content into at least one slice of binding metadata, solving the problem of extensive pollution positioning, and realizing accurate positioning at the slice level; determining the comprehensive judgment result of the slice through multi-factor quantitative scoring and a multiple injection detection mechanism, solving the problem of high detection missing rate, and realizing quantifiable and accurate detection; performing reservation, marking or isolation processing on the slice according to the comprehensive judgment result, extracting factual elements from the isolated slice to construct a safe context, solving the problems of detection interruption and information loss, and realizing the isolation of pollution without interrupting the task; while continuing to execute the task under the safe context, implementing gating on tool calling, output content and memory writing, solving the problems of pollution cross-round diffusion and tool chain risk amplification, and realizing adaptive protection of risk perception.
Owner:DINGHAN TECH CO LTD

Communication method and communication apparatus

A communication method, comprising: a first communication apparatus receiving a first request message from a second communication apparatus, the first request message comprising first ciphertext and first indicating information, the first ciphertext being first data securely protected by means of a first security context, and the first indicating information being used for indicating that homomorphic encryption is to be performed on the first ciphertext. Performing homomorphic encryption on the first ciphertext to generate second ciphertext, and sending the second ciphertext to a second network element, wherein the first security context is determined by means of negotiation between the second communication apparatus and the second network element, and homomorphically encrypted ciphertext supports being processed when in a ciphertext state. In the communication method, second ciphertext can be processed by a second network element, allowing a second communication apparatus to perform data security protection on the basis of a first security context without having to perform homomorphic encryption. This allows for the processing of terminal ciphertext data by a core network while reducing encryption overhead of the second communication apparatus.
Owner:HUAWEI TECH CO LTD

Internet of Things equipment self-adaptive secure communication method and system based on dynamic negotiation, Internet of Things equipment and storage medium

The invention discloses a dynamic negotiation-based self-adaptive secure communication method and system for an internet of things device, the internet of things device and a storage medium, and the method comprises the steps that the internet of things device exchanges a security context through a first packet, and receives and updates a security configuration issued by a cloud in real time; the Internet of Things equipment reads and starts a corresponding encryption algorithm from the local or directly selects a plaintext transmission mode according to the negotiated algorithm configuration; the Internet of Things equipment dynamically manages the secret key, and decides to execute secret key derivation or read the cache secret key for encryption and decryption according to the updating period; the Internet of Things equipment analyzes the security context, obtains corresponding secret keys and algorithm parameters according to configuration requirements, and executes encryption or plaintext transmission; when the security context is changed, the Internet of Things equipment immediately updates an encryption and decryption algorithm adapter of uplink and downlink messages; and after the message is encrypted and decrypted, packaging the message body according to a preset message packaging format and then sending the message body. According to the invention, the communication efficiency and interoperability are improved by optimizing the communication process.
Owner:深圳开鸿数字产业发展有限公司

Communication device and communication method

A communication device according to the present invention comprises: a communication unit that establishes a security context and transmits / receives a non-access stratum (NAS) message to / from a network via an ambient Internet of Things (IoT) reader; and a control unit that, after the point in time when transmission or reception of the NAS message has been executed, transitions to an off state in which charging is performed by energy harvesting and transmission / reception of signals is impossible. The communication unit notifies the network of the capability of the ambient IoT device related to the energy harvesting via the ambient IoT reader.
Owner:NTT DOCOMO INC