Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

37 results about "Security framework" patented technology

An information security framework is a series of documented processes that are used to define policies and procedures around the implementation and ongoing management of information security controls in an enterprise environment. These frameworks are basically a "blueprint" for building an information security program to manage risk and reduce vulnerabilities.

Providing generative artificial intelligence (AI)-enabled notebook interfaces for a security framework

Providing generative artificial intelligence (AI)-enabled notebook interfaces for a security framework, including: receiving a request to generate a notebook interface for a security framework monitoring a cloud deployment; generating, in response to the request, the notebook interface, wherein the notebook interface comprises one or more notebook cells for interacting with the security framework, wherein the one or more notebook cells comprise a natural language input cell for querying a generative artificial intelligence (AI) model; and presenting the notebook interface.
Owner:FORTINET INC

Dynamic cybersecurity policy management based on contextual adaptive learning

A computerized system for dynamic cybersecurity policy using AI-based contextual adaptive learning includes an AI system that evaluates business contexts, risk tolerance, and productivity impact to generate threat intelligence assessments. The system includes a Contextual Adaptive Learning module that dynamically adjusts cybersecurity policies based on threat assessments to create security workflows. A Cybersecurity Mesh Development module that integrates policies across security frameworks. A Dynamic Scenario Catalog module that updates policy adjustments based on threat intelligence. An Automated Workflow Orchestration module that creates and refines security workflows for optimal efficiency. A Policy Recommendation and Automation module that generates prioritized security recommendations and automates policy changes based on organizational risk profiles and current security controls. This system harmonizes security policies while considering business context, risk, and productivity impacts.
Owner:PURATHEPPARAMBIL SANTHOSH KUNJAPPAN +2

System and method for communication validation and multi-attribute trust scoring through cross-network intelligence correlation

A system and method for privacy-preserving communication validation and multi-attribute trust scoring is disclosed. The system analyzes communication metadata to determine pattern legitimacy by comparing current communication patterns against relationship fingerprints without accessing communication content. The system validates relationship context between communicating parties using interaction graph analysis and historical communication data. Cross-network intelligence correlation compares current patterns against aggregated patterns across voice, email, and messaging services, creating a self-strengthening security framework that recognizes emerging threat patterns while validating legitimate communication behaviors. The system generates comprehensive multi-attribute trust assessments comprising individual trust attribute scores including engagement rate, reliability index, channel preference, temporal pattern, and behavioral pattern, combined into overall trust levels. Trust context is displayed through a user interface presenting simplified, intuitive, and actionable information with progressive disclosure capabilities, enabling informed user decisions while preserving privacy. Communication processing actions provide users with appropriate engagement options tailored to specific trust assessment results.
Owner:ICA AI INC

QR code verification engine

A QR Code Verification Engine provides a multi-layered security framework for generating, validating, and authenticating QR codes while preventing tampering, fraud, and unauthorized access. The system embeds a hidden security layer within the QR code using steganographic encoding or invisible watermarking techniques, ensuring detection of any modifications. The hidden layer is encrypted using asymmetric cryptography, allowing only an authorized verification system to extract and validate it. An AI-powered tamper detection module analyzes QR codes for anomalies, while cryptographic hash verification ensures integrity. The system employs biometric authentication, push notification approvals, and contextual security measures to enhance user verification. Dynamic QR codes with expiration rules prevent replay attacks. Secure offline verification allows authentication without network connectivity. The system integrates with financial platforms, web security tools, and real-time fraud detection mechanisms, ensuring a highly secure and scalable QR code validation framework for transactions, identity verification, and access control applications.
Owner:BANK OF AMERICA CORP

Security framework matrix visualizations for notable events

Techniques are described for generating visualizations of security framework information (such as, e.g., MITRE ATT&CK® information) displayed in connection with notable events detected by a data intake and query system. Data intake and query systems, SIEM systems, and other applications often provide user interfaces that display detected occurrences of incidents, sometimes referred to as “notable events,” within users' information technology (IT) environments. A data intake and query system is described herein that is capable of identifying notable events, assigning tactic and technique information to notable events (and optionally to associated risk objects), and causing display of tactic and technique visualizations which are intuitive and customizable, provide ready access to relevant documentation, and follow a format with which security analysts are familiar.
Owner:CISCO TECHNOLOGY INC

System and method for identification of compromise events and response

ActiveUS12556530B2Securing communicationData processing systemSecurity framework
Methods and systems can secure distributed systems. The distributed systems may include data processing systems subject to compromise by malicious entities. If compromised, the data processing systems may impair the services provided by the distributed system. To secure the distributed systems, the data processing systems may implement a security framework. The security framework may utilize a hierarchy that defines authority for validating trusted entities. The hierarchy may vest authority across the distributed system, and may be based on a reputation (e.g., weighted reputation) of each of the data processing systems within the distributed system. If the reputation of a data processing system meets criteria based on active and passive monitoring, the data processing system may be treated as being compromised and a local refresh of security data may be performed. Consequently, the impact of compromise of the data processing system may be limited by the distributed authority.
Owner:DELL PROD LP

Secure Authentication and Distribution of Redundancy Configuration Data for Compute Modules

PendingUS20260189403A1Security frameworkTerm memory
A security framework for redundancy configuration management ensures that multiplexer control data and redundancy maps distributed to compute modules are authenticated, verified, and securely applied. Configuration packets are cryptographically signed, versioned, and transmitted through an isolated sideband channel. A coordination processor verifies signatures, checks integrity hashes, prevents replay, and applies updates only during redundancy-safe intervals. Logs of verified configurations are stored in secure memory and may be audited through a hierarchical management structure. The invention prevents unauthorized or corrupted redundancy configurations in multi-module compute systems.
Owner:SILVEBROOK KIA

Offline encryption security framework with pluggable function and management and control method

The invention discloses an offline encryption security framework with a pluggable function and a management and control method, and relates to the technical field of computer security and document processing. According to the framework, an encrypted USB flash disk serves as a hardware carrier, five modules including function management, safety control, document typesetting, a safety box and tamper-proof logs are integrated, the whole process runs in an off-line mode, and data are only stored in the USB flash disk; the function management module supports dynamic addition / removal of offline. Exe programs and creates a hidden data isolation folder for each program; the security management and control module adopts an SHA256 salted Hash storage hierarchical password, and automatically clears local operation traces when the security management and control module is closed; the official document typesetting module realizes standardization of a. Docx file title / text format, and the typeset file is stored in an exclusive isolation folder; the safe case module only allows files to be imported from the folder, and AES-256 encryption storage is adopted; the anti-tampering log module guarantees the integrity of logs through a hash chain, and adapts to secret-related office scenes such as party and government organizations.
Owner:李文操

Proactively determining security risks and deployment impacts across cloud computing environments

This disclosure describes a proactive deployment impact system that detects and addresses the security impact of candidate code-based infrastructure changes before they are deployed in a production environment within a cloud computing system. The proactive deployment impact system implements a lightweight preemptive security framework, based on runtime resource information, to determine whether a requested candidate code-based infrastructure change would introduce new security risks, attack patterns, or breach vulnerabilities. Furthermore, the proactive deployment impact system can actively block the deployment of negatively impacting candidate changes, report potential security breaches, and / or automatically modify the candidate changes to eliminate security vulnerabilities.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Hybrid security framework for radio frequency and vision based positioning systems

Techniques for communication are disclosed. In an aspect, a network entity receives, from a target network node, radio frequency (RF)-based information obtained by the target network node, obtains, from one or more network nodes, visual channel state information (vCSI) associated with the target network node, and determining whether the RF-based information is compromised based on a comparison of a first set of values of a set of characteristics of an environment of the target network node determined based on the RF-based information and a second set of values of a set of characteristics of an environment of the target network node determined based on the vCSI.
Owner:QUALCOMM INC

Dikwp ai-os and security framework

The invention relates to a DIKWP aware operating system (AI-OS) and a security framework. The invention provides an artificial consciousness operating system and a security framework based on a DIKWP (Data-Information-Knowledge-Intelligence-Intention) model, and aims to solve the problems that the decision-making process of an existing AI (Artificial Intelligence) system is black, the existing AI system does not have self-cognition, the security is uncontrollable and the like. According to the operation system, the cognitive process of AI is divided into five stages of data processing, information extraction, knowledge application, intelligent decision making and intention management, and through core components such as a concept-semantic fusion kernel, a white-box evaluation module, a semantic security protection module and an intention regulation and control interface, an intellectual property of the AI is evaluated. Semantic checking, whole-process monitoring and purpose constraint of an AI internal cognitive process are realized. Wherein the kernel adopts a concept space and semantic space double-layer verification mechanism to improve AI semantic understanding consistency, the white box module records AI full-link reasoning to achieve interpretable auditing, the safety protection module is embedded into ethical rules to intercept violation output in real time, and the intention interface directly acts human high-level intentions on the AI decision process. Through the architecture, the decision-making process of the AI system is transparent and controllable, the output behavior is consistent with the preset target and value criterion, and the interpretability, safety and reliability of the AI system are remarkably improved.
Owner:HAINAN UNIV

Privacy-preserving personalized federated learning methods and apparatus for heterogeneous scenarios

This invention discloses an efficient personalized privacy-preserving federated learning method for heterogeneous scenarios. The specific implementation steps include: 1. System initialization and key distribution; 2. Global model distribution; 3. Client base layer and personalization layer updates; 4. Encrypted upload and local update; 5. Weighted aggregation of the global model; 6. Global model update. This invention overcomes the limitations of heterogeneous data scenarios based on a "base + personalization layers" model, alleviating the problems of low global model accuracy and poor generalization caused by data heterogeneity. This invention designs a privacy-preserving framework based on CKKS fully homomorphic encryption, achieving client privacy protection during the federated learning process. Simultaneously, it significantly reduces computational and communication overhead and improves encryption efficiency under large-scale vectors and model parameters.
Owner:SICHUAN POLICE COLLEGE +1

Proactively determining security risks and deployment impacts across cloud computing environments

PCT designated stageWO2026096019A1Platform integrity maintainanceKnowledge representationResource informationSecurity framework
This disclosure describes a proactive deployment impact system that detects and addresses the security impact of candidate code-based infrastructure changes before they are deployed in a production environment within a cloud computing system. The proactive deployment impact system implements a lightweight preemptive security framework, based on runtime resource information, to determine whether a requested candidate code-based infrastructure change would introduce new security risks, attack patterns, or breach vulnerabilities. Furthermore, the proactive deployment impact system can actively block the deployment of negatively impacting candidate changes, report potential security breaches, and / or automatically modify the candidate changes to eliminate security vulnerabilities.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Application migration security framework using service mesh and bi-directional proxy

PendingUS20260100936A1Securing communicationSecure communicationSecurity framework
Systems and methods for secure migration of applications using service mesh and bi-directional proxy are described. According to one embodiment, an Information Handling System (IHS) includes executable logic to receive a request to migrate an application from a first computing device to a second computing device, deploy a first side-car module on the first computing device and a second side-car module on the second computing device, establish a secure communication tunnel with the first and second side-car modules, and using the secure tunnel, migrate the application from the first computing device to the second computing device.
Owner:DELL PROD LP

Privacy protection Transform reasoning method and system based on integral gradient three-dimensional collaborative optimization

The invention relates to the technical field of text processing, in particular to a privacy protection Transform reasoning method and system based on integral gradient three-dimensional collaborative optimization, and the method comprises the steps: inputting a text processing data set into a pre-training Transform model in an offline stage, carrying out the path integral attribution of the output of each attention head of each layer of the model on the text processing data set, and carrying out the path integral attribution of the output of each attention head of each layer of the model; obtaining importance scores of the attention heads based on path integral attribution, and constructing a pruning strategy of cross-layer global sorting and unified threshold control, so as to perform pruning operation on the attention heads in the pre-trained Transform model by using the pruning strategy to obtain a text processing target model; and in the online stage, deploying the text processing target model to a privacy reasoning platform under the secure multi-party computing framework so as to obtain a reasoning result of the to-be-processed text under the secure multi-party computing framework. According to the method, the efficiency and practicability of privacy reasoning can be improved on the premise of not changing the existing text processing security framework.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University

Mutable Code Efficiencies in Measured Secure Boot for Hardware Root of Trust

PendingUS20260093816A1Platform integrity maintainanceSecurity frameworkVolatile memory
Mutable firmware commonality for hardware root of trust is described. In at least one aspect, a system includes a volatile memory circuit having a first region that persistently stores a reusable portion of instructions executed during a boot sequence for establishing a hardware root of trust among multiple security layers of a security framework, and a second region that is overwritten during the boot sequence with each layer-specific portion of the instructions executed sequentially to implement a corresponding security layer based on the reusable portion. The system further includes a processing circuit that sequentially establish the hardware root of trust one security layer at a time by loading the second region of the volatile memory with a current layer-specific portion of the instructions that are executed in combination with the reusable portion of the instructions to implement a current security layer.
Owner:ATI TECHNOLOGIES ULC +1

Methods, architectures, apparatuses, and systems for secure non-3GPP access

A process for establishing a secure non-3GPP connection between a wireless transmit and / or receive unit (WTRU) and a wireless network using existing 3GPP access credentials. The WTRU transmits a request to establish a protocol data unit (PDU) session along with secure non-3GPP information to the wireless network. Upon receiving an acceptance indication, the WTRU generates new security credentials based on the existing 3GPP credentials and establishes the secure non-3GPP connection. Provisions are made for indicating 3GPP security capability of the secure non-3GPP connection, standalone non-3GPP connections, and secure connection termination at the user plane function (UPF). Additionally, new shared keys are generated for secure non-3GPP connectivity and handling handovers with updated 3GPP access credentials. The process ensures secure communication between the WTRU and the wireless network by leveraging security frameworks.
Owner:INTERDIGITAL PATENT HOLDINGS INC

A centralized system for synchronizing financial data for S / 4HANA environments

ActiveDE202026101299U1FinanceResourcesData synchronizationRole-based access control
A centralized financial data synchronization system for S / 4HANA environments, consisting of: A data ingestion module configured to capture financial transactions, master data records, journal entries, tax data, and intercompany postings from multiple enterprise modules and external third-party systems. a centralized synchronization engine that is operationally connected to the data ingestion module and configured to process and synchronize the collected financial data in real time or near real time; a validation and harmonization layer configured to standardize heterogeneous financial data structures into a unified data model, detect inconsistencies, duplicates and structural discrepancies, and apply predefined financial governance rules; a reconciliation processor configured to compare synchronized financial records with the records of the source system to identify discrepancies and automatically generate exception alerts or corrective workflows; a security framework that includes encryption mechanisms for data in transit and at rest, role-based access control, and activity logging to protect sensitive financial information; and a reporting interface configured to generate consolidated financial reports, audit trails, variance reports, and centralized dashboards for authorized users; the system ensures centralized, secure and scalable synchronization of financial data across cloud, on-premise or hybrid S / 4 HANA infrastructures.
Owner:JAYARAMAN KAJENDRAN WEST CHESTER

Cross-domain intelligent wireless sensing method based on federated learning and blockchain

The application discloses a cross-domain intelligent wireless sensing method based on federated learning and block chain, relates to the technical field of wireless sensing, solves the problems of efficient cooperation and privacy protection of cross-domain heterogeneous data, insufficient generalization ability of multi-target sensing model under a dynamic environment, and contradiction between real-time sensing and calculation efficiency under resource constraints, and the application constructs a FL-BLC cooperative security framework based on lightweight federated learning and block chain to perform distributed training on a local client model; on the basis of the framework, a DB-SE-Yolov8 sensing algorithm model is constructed to extract and reserve global and local fine-grained information by adopting a parallel double-branch network structure, to dynamically weight and fuse multi-scale feature information through a gating mechanism, to perform regression statistics on the extracted feature information by using a full-connection linear classifier, to perform probability mapping by using a Softmax activation function, and to output a sensing result; while improving the precision of cross-domain wireless sensing, the privacy protection capability of cross-domain heterogeneous data is effectively improved.
Owner:QINGDAO UNIV OF SCI & TECH

Systems and methods for handling security threats

A system to handle cybersecurity threats is disclosed. The system may include a transceiver and a processor. The transceiver may be configured to receive a request from a user via a user interface rendered on a user device. The request may include a query associated with cyber security. The processor may be configured to render the user interface on the user device, and obtain the query from the transceiver. The processor may parse the query into structured data, and identify a sequence of templated actions based on the structured data and a security framework. The processor may map each templated action into one or more action blocks to perform the templated action, based on a user environment. The processor may prepare a workflow to resolve the query based on the sequence of templated actions and the action blocks for each templated action, and perform a predetermined action.
Owner:SIMBIAN INC

Systems and methods to map attack paths to applications assets in a visualization interface

A system and a method to map attack paths in a visualization interface may include storing in a memory asset inventory indicating application assets, attack vector parameters configured to indicate vulnerabilities of one or more of the application assets, and asset mapping information. A processor may determine multiple vulnerable assets in the application assets based at least in part upon the attack vector parameters. Further, the processor may obtain security parameters from a security framework indicating one or more attack techniques, associate each of the vulnerable assets to one or more of the security parameters, and generate a visual interface showing the vulnerable assets and the security parameters. The processor may determine an attack path connecting the vulnerable assets based at least in part upon the asset mapping information, and map the attack path to the application layers and the security parameters in the visual interface.
Owner:CISCO TECHNOLOGY INC

Security framework for virtual machines

A secure framework for a virtual machine is described. In one or more implementations, a hardware platform includes physical computer hardware that includes one or more processing units and one or more memories. The system also includes a virtual machine monitor configured to virtualize physical computer hardware of the hardware platform to instantiate the plurality of framework-secure virtual machines. Further, the system includes a root framework secure virtual machine instantiated by a virtual machine monitor. In accordance with the described techniques, a root framework-secure virtual machine is configured to control access to a hardware platform by a framework-secure virtual machine instantiated by a virtual machine monitor.
Owner:ADVANCED MICRO DEVICES INC

Data Processing Equipment for Lightweight Cryptography

ActiveGB6499922SLightweight cryptographyEngineering
Data Processing Equipment for Lightweight Cryptography
Owner:DR JAYAKUMAR SATTANATHAN +5

Preventing resource breaches in a cloud computing system caused by new code-based infrastructures using preventative pattern-based analysis

ActiveUS12675582B2Security frameworkThreat level
This disclosure describes a preventative breach detection system that detects and addresses potential resource breaches in candidate code-based infrastructure templates before deployment in a production environment within a cloud computing system. For example, the preventative breach detection system provides a preemptive security framework that utilizes hybrid pattern-based data structures, security pattern analysis, and resource vulnerability patterns to determine the security posture of a candidate code-based infrastructure based on its potential impact on the surrounding infrastructure in the production environment. By doing so, the preventative breach detection system quickly detects potential new resource breaches or changes in the security threat levels that may occur before the candidate code-based infrastructure is introduced into the production environment of the cloud computing system.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

An autonomously controllable digital twin governance method and system

The application discloses a kind of self-controllable digital twin governance method and system, comprising: based on self-controllable edge computing equipment collection physical entity data and pre-processing;Through the importance score extrapolation framework, efficient pruning is carried out on data;Branch schrodinger bridge neural network is constructed, and the evolution characteristics of system multi-path are expressed;Enhance the generalization ability of model using multi-experiment equation learning;Based on domestic cryptographic algorithm and security chip, build self-controllable security framework;Integrate real-time data and digital twin model output for analysis, realize closed-loop control.The application solves the technical problems of the existing digital twin system centralized architecture, such as low efficiency, serious external technology dependence, and difficulty in expressing system dynamic divergence evolution characteristics, realizes efficient data processing, accurate mapping of system dynamic divergence characteristics, enhanced model generalization ability and data sovereignty security guarantee, and has wide application prospect.
Owner:贵州中汇科技发展有限公司

Systems and methods for sensor response management

PCT designated stageWO2026112660A1AlarmsSecurity frameworkSecurity parameter
Disclosed are systems and methods that provide a novel security framework for a dynamic, intelligent approach to location protection through flexible zone management. Each location or entry point can be treated as a configurable "zone" with multiple layers of customizable security parameters. The framework goes beyond traditional armed / disarmed states via alarm profiles that can computationally, dynamically and / or automatically control, manage, modify and / or trigger sensor response to particular types of events detected or not detected at a location. The framework's ability to learn, adapt and respond contextually transforms security from a passive, alarm-driven model to an active, intelligent protection ecosystem.
Owner:RESIDEO LLC

Preventing resource breaches in a cloud computing system caused by new code-based infrastructures using preventative pattern-based analysis

ActiveUS20260087141A1Platform integrity maintainanceSecurity frameworkThreat level
This disclosure describes a preventative breach detection system that detects and addresses potential resource breaches in candidate code-based infrastructure templates before deployment in a production environment within a cloud computing system. For example, the preventative breach detection system provides a preemptive security framework that utilizes hybrid pattern-based data structures, security pattern analysis, and resource vulnerability patterns to determine the security posture of a candidate code-based infrastructure based on its potential impact on the surrounding infrastructure in the production environment. By doing so, the preventative breach detection system quickly detects potential new resource breaches or changes in the security threat levels that may occur before the candidate code-based infrastructure is introduced into the production environment of the cloud computing system.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Multi-party private set merging method and system based on trusted execution environment

The invention discloses a multi-party private set merging method and system based on a trusted execution environment, and belongs to the technical field of privacy computing and secure multi-party computing. Comprising the steps of TEE initialization, security key exchange, hash bucking and data preprocessing, multi-party privacy set merging and union set distribution. According to the invention, the TEE hardware isolation capability is creatively combined with cryptographic proof, and the secure union set calculation of multi-party data is realized through a star topology network architecture. The TEE is used as a neutral trusted node, plaintext data is directly processed in a secure enclave, and complex encryption calculation is avoided; by adopting a Hash bucket dividing strategy and an external storage mechanism, the limitation of a TEE memory is overcome, and large-scale data set processing is supported; based on a universal combinable (UC) security framework design protocol, malicious security is achieved through a non-interactive witness-indistinguishable (NIWI) attestation system without a non-collusion hypothesis.
Owner:SHANGHAI MARITIME UNIVERSITY