Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

57 results about "Security framework" patented technology

An information security framework is a series of documented processes that are used to define policies and procedures around the implementation and ongoing management of information security controls in an enterprise environment. These frameworks are basically a "blueprint" for building an information security program to manage risk and reduce vulnerabilities.

Providing generative artificial intelligence (AI)-enabled notebook interfaces for a security framework

Providing generative artificial intelligence (AI)-enabled notebook interfaces for a security framework, including: receiving a request to generate a notebook interface for a security framework monitoring a cloud deployment; generating, in response to the request, the notebook interface, wherein the notebook interface comprises one or more notebook cells for interacting with the security framework, wherein the one or more notebook cells comprise a natural language input cell for querying a generative artificial intelligence (AI) model; and presenting the notebook interface.
Owner:FORTINET INC

Dynamic cybersecurity policy management based on contextual adaptive learning

A computerized system for dynamic cybersecurity policy using AI-based contextual adaptive learning includes an AI system that evaluates business contexts, risk tolerance, and productivity impact to generate threat intelligence assessments. The system includes a Contextual Adaptive Learning module that dynamically adjusts cybersecurity policies based on threat assessments to create security workflows. A Cybersecurity Mesh Development module that integrates policies across security frameworks. A Dynamic Scenario Catalog module that updates policy adjustments based on threat intelligence. An Automated Workflow Orchestration module that creates and refines security workflows for optimal efficiency. A Policy Recommendation and Automation module that generates prioritized security recommendations and automates policy changes based on organizational risk profiles and current security controls. This system harmonizes security policies while considering business context, risk, and productivity impacts.
Owner:PURATHEPPARAMBIL SANTHOSH KUNJAPPAN +2

System and method for communication validation and multi-attribute trust scoring through cross-network intelligence correlation

A system and method for privacy-preserving communication validation and multi-attribute trust scoring is disclosed. The system analyzes communication metadata to determine pattern legitimacy by comparing current communication patterns against relationship fingerprints without accessing communication content. The system validates relationship context between communicating parties using interaction graph analysis and historical communication data. Cross-network intelligence correlation compares current patterns against aggregated patterns across voice, email, and messaging services, creating a self-strengthening security framework that recognizes emerging threat patterns while validating legitimate communication behaviors. The system generates comprehensive multi-attribute trust assessments comprising individual trust attribute scores including engagement rate, reliability index, channel preference, temporal pattern, and behavioral pattern, combined into overall trust levels. Trust context is displayed through a user interface presenting simplified, intuitive, and actionable information with progressive disclosure capabilities, enabling informed user decisions while preserving privacy. Communication processing actions provide users with appropriate engagement options tailored to specific trust assessment results.
Owner:ICA AI INC

Intelligent construction collaborative management platform and method based on digital twinning

The invention relates to the technical field of intelligent construction, and discloses an intelligent construction collaborative management platform and method based on digital twinning, and the method comprises the steps: firstly obtaining the practical operation data of a target engineering machine, analyzing the data safety level of the practical operation data to generate a distributed storage path, extracting storage node identifiers in the path, and deploying the storage node identifiers to a digital twinning platform; analyzing a node storage state index, querying a data backup demand and constructing a storage backup framework; then identifying an access request of the storage security framework, verifying a user identity, calculating an authority level index, analyzing an access range, and determining a platform multi-layer access regulation; then monitoring a permission change event, collecting a log, identifying a risk access behavior and calculating an access risk index; and finally, adjusting node encryption configuration according to the risk index, identifying an authority control key, and generating a self-adaptive security policy of the target engineering machinery on the platform. According to the invention, the integrity and safety of construction management can be improved.
Owner:XIAMEN ZHONGTA RISHENG INFORMATION TECH CO LTD

QR code verification engine

A QR Code Verification Engine provides a multi-layered security framework for generating, validating, and authenticating QR codes while preventing tampering, fraud, and unauthorized access. The system embeds a hidden security layer within the QR code using steganographic encoding or invisible watermarking techniques, ensuring detection of any modifications. The hidden layer is encrypted using asymmetric cryptography, allowing only an authorized verification system to extract and validate it. An AI-powered tamper detection module analyzes QR codes for anomalies, while cryptographic hash verification ensures integrity. The system employs biometric authentication, push notification approvals, and contextual security measures to enhance user verification. Dynamic QR codes with expiration rules prevent replay attacks. Secure offline verification allows authentication without network connectivity. The system integrates with financial platforms, web security tools, and real-time fraud detection mechanisms, ensuring a highly secure and scalable QR code validation framework for transactions, identity verification, and access control applications.
Owner:BANK OF AMERICA CORP

Gateway management system and method based on multiple internet of things protocols

The invention relates to the technical field of Internet of Things communication, and discloses a gateway management system and method based on multiple Internet of Things protocols, and the system comprises a processor architecture, a protocol conversion module, a collaborative management module, a unified security framework module and an edge computing module. The method is applied to the system. According to the application, efficient interconnection and dynamic collaborative management of multi-protocol equipment are realized through FPGA module hardware acceleration protocol conversion, a genetic algorithm and a Petr network hybrid task scheduling framework and a unified security mechanism irrelevant to a protocol, and various different mainstream Internet of Things protocols are compatible through a modular processor architecture and a dynamic expansion interface, so that the implementation is convenient, and the implementation is easy. According to the method, the hardware cost is reduced, rapid integration of a new protocol is supported, local and cloud resource allocation is further optimized through an intelligent switching mechanism of edge computing and cloud collaboration, the system stability and the data processing efficiency are improved, and the method is widely applied to scenes such as smart home, industrial Internet of Things and smart cities.
Owner:SOUTHERN XINJIANG ELECTRICITY SUPPLY COMPANY OF STATE GRID XINJIANG ELECTRIC POWER +1

Security framework matrix visualizations for notable events

Techniques are described for generating visualizations of security framework information (such as, e.g., MITRE ATT&CK® information) displayed in connection with notable events detected by a data intake and query system. Data intake and query systems, SIEM systems, and other applications often provide user interfaces that display detected occurrences of incidents, sometimes referred to as “notable events,” within users' information technology (IT) environments. A data intake and query system is described herein that is capable of identifying notable events, assigning tactic and technique information to notable events (and optionally to associated risk objects), and causing display of tactic and technique visualizations which are intuitive and customizable, provide ready access to relevant documentation, and follow a format with which security analysts are familiar.
Owner:CISCO TECHNOLOGY INC

System and Method for Dynamic Multi-Level Security in High-Capacity Optical Codes

A system and method for encoding and decoding optical codes with context-aware, multi-level security. Input data is classified into security levels with associated context sensitivity requirements. The system compresses data using public and private codebooks based on security classifications, then generates optical codes incorporating both compressed data and context requirements. When scanned, the system collects environmental contextual data (location, network environment, device security, user behavior), analyzes it against embedded context requirements, and dynamically determines which security levels are accessible in the current environment. Only authorized security levels are decoded using appropriate codebooks based on both user credentials and current contextual factors. This approach enables fine-grained, context-sensitive access control that adapts to changing environments while maintaining the compression benefits and capacity advantages of the multi-level security framework.
Owner:ATOMBEAM TECH INC

Spurious less data authentication by method mesh engineering using digital GenAI with proof of digital manipulation (PODM)

Systems and methods are disclosed to provide a security framework for the authentication of digital content and the prevention of unauthorized modifications, especially targeting the vulnerabilities introduced by deepfake technologies. It innovates by merging reverse engineering with expression manipulation detection to discern genuine from altered digital media. The process involves comparing historical data against synthetic or real-time content, generating a “video mesh” that enables precise manipulation identification. Enhanced by Smart Contracts for each content piece to record and verify changes, this system advances digital identity and transaction security significantly beyond current methodologies. Furthermore, it employs Generative AI within the Identity Intelligent Clip Reviewer to scrutinize blockchain-secured data for manipulation signs, issuing a Proof of Digital Manipulation (PODM) for verified authenticity. This comprehensive method ensures the integrity and trustworthiness of digital interactions across various platforms, marking a significant step forward in the protection against sophisticated cyber threats and unauthorized data alterations.
Owner:BANK OF AMERICA CORP

A Power Transmission Intelligent Inspection Image Defect Recognition and Intelligent Annotation System

This invention provides a power transmission intelligent inspection image defect recognition and intelligent annotation system. The system includes a data layer, an application layer, a system layer, and a hardware layer. The data layer is used to manage and store data. The application layer is used to implement business logic and user interaction functions. The system layer is used to manage the operating environment and security framework. The hardware layer is used to provide underlying computing power, storage, and communication support. This invention integrates multimodal inspection data with multi-round time series analysis to construct an integrated intelligent inspection system with high-precision recognition, trend perception, and visual early warning capabilities.
Owner:GUANGDONG NANFANG POWER COMM CO LTD +1

System and method for identification of compromise events and response

Methods and systems can secure distributed systems. The distributed systems may include data processing systems subject to compromise by malicious entities. If compromised, the data processing systems may impair the services provided by the distributed system. To secure the distributed systems, the data processing systems may implement a security framework. The security framework may utilize a hierarchy that defines authority for validating trusted entities. The hierarchy may vest authority across the distributed system, and may be based on a reputation (e.g., weighted reputation) of each of the data processing systems within the distributed system. If the reputation of a data processing system meets criteria based on active and passive monitoring, the data processing system may be treated as being compromised and a local refresh of security data may be performed. Consequently, the impact of compromise of the data processing system may be limited by the distributed authority.
Owner:DELL PROD LP

Secure Authentication and Distribution of Redundancy Configuration Data for Compute Modules

PendingUS20260189403A1Security frameworkTerm memory
A security framework for redundancy configuration management ensures that multiplexer control data and redundancy maps distributed to compute modules are authenticated, verified, and securely applied. Configuration packets are cryptographically signed, versioned, and transmitted through an isolated sideband channel. A coordination processor verifies signatures, checks integrity hashes, prevents replay, and applies updates only during redundancy-safe intervals. Logs of verified configurations are stored in secure memory and may be audited through a hierarchical management structure. The invention prevents unauthorized or corrupted redundancy configurations in multi-module compute systems.
Owner:SILVEBROOK KIA

System and method for dynamic security frameworks in distributed systems

Methods and systems for securing distributed systems are disclosed. The distributed systems may include data processing systems subject to compromise by malicious entities. If compromised, the data processing systems may impair the services provided by the distributed system. To secure the distributed systems, the data processing systems may implement a security framework. The security framework may utilize a hierarchy that defines authority for validating trusted entities. The hierarchy may vest authority across the distributed system, and may be based on a reputation (e.g., weighted reputation) of each of the data processing systems within the distributed system. The hierarchy may be dynamically updated over time as new information regarding data processing systems is discovered. Consequently, the impact of compromise of a data processing system may be limited by the distributed authority.
Owner:DELL PROD LP

Adding guardrails to generative artificial intelligence (AI)-created workflows

Adding guardrails to generative artificial intelligence (AI)-created workflows, including: receiving, via a natural language interface for a security framework monitoring a cloud deployment, a natural language input; providing the natural language input to a generative artificial intelligence (AI) model; receiving, from the generative AI model, a response to the natural language input, wherein the response comprises data encoding a user interface (UI) widget comprising natural language description of one or more actions determined by the generative AI model based on the natural language input and a selectable element that, when selected by a user, causes the one or more actions to be performed by an entity other than the generative AI model; and presenting the UI widget via the natural language interface.
Owner:FORTINET INC

Offline encryption security framework with pluggable function and management and control method

The invention discloses an offline encryption security framework with a pluggable function and a management and control method, and relates to the technical field of computer security and document processing. According to the framework, an encrypted USB flash disk serves as a hardware carrier, five modules including function management, safety control, document typesetting, a safety box and tamper-proof logs are integrated, the whole process runs in an off-line mode, and data are only stored in the USB flash disk; the function management module supports dynamic addition / removal of offline. Exe programs and creates a hidden data isolation folder for each program; the security management and control module adopts an SHA256 salted Hash storage hierarchical password, and automatically clears local operation traces when the security management and control module is closed; the official document typesetting module realizes standardization of a. Docx file title / text format, and the typeset file is stored in an exclusive isolation folder; the safe case module only allows files to be imported from the folder, and AES-256 encryption storage is adopted; the anti-tampering log module guarantees the integrity of logs through a hash chain, and adapts to secret-related office scenes such as party and government organizations.
Owner:李文操

Systems and methods of a cloud security engine (CSE) with intelligent decision making

The systems and methods comprising a Cloud Security Engine with decision intelligence providing one or more pre-coded, pre-built, pre-configured, pre-tested, secure framework-compliant components; pre-defining one or more secure framework-compliant cloud architectures and comprised of pre-coded secure framework-compliant components; receiving user-configurable customizations; designing one or more cloud architectures using the said one or more provided components, or the components customized using the user-configurable customizations; simulating and testing a cloud environment model with a selected designed cloud architecture; collecting and maintaining context and risk information for the cloud environment autonomously, or from system owners, or users; automatically incorporating the secure configuration from the context and risk mapped pre-coded policies into the components and architectures for cloud environment at design, model, build, test, or deploy phase; allowing for requesting, approving and tracking exceptions based on the automatically incorporated secure configuration; deploying the selected, designed, secured cloud architecture in the cloud environment.
Owner:INVI GRID INC

Proactively determining security risks and deployment impacts across cloud computing environments

This disclosure describes a proactive deployment impact system that detects and addresses the security impact of candidate code-based infrastructure changes before they are deployed in a production environment within a cloud computing system. The proactive deployment impact system implements a lightweight preemptive security framework, based on runtime resource information, to determine whether a requested candidate code-based infrastructure change would introduce new security risks, attack patterns, or breach vulnerabilities. Furthermore, the proactive deployment impact system can actively block the deployment of negatively impacting candidate changes, report potential security breaches, and / or automatically modify the candidate changes to eliminate security vulnerabilities.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Enhancing security frameworks of a production environment by managing data protection scripts

A method for managing data protection scripts includes monitoring, by a backup server, a production environment to obtain script execution information associated with an application executing a data protection script, obtaining, in response to the monitoring, script metadata associated with the application and using the script execution information, converting the script metadata to an analytical format to obtain a security profile of the data protection script, applying the security profile to a script processing engine to obtain a script execution recommendation for the data protection script, and implementing the script execution recommendation on the application.
Owner:DELL PROD LP

A security enhanced can controller based on cryptographic authentication and intrusion detection

This invention discloses a security-enhanced CAN controller based on encryption authentication and intrusion detection, designed to address security threats such as remote unlocking and start-stop of vehicles via the Internet of Vehicles (IoV). This application constructs a security framework based on encryption authentication and intrusion detection, utilizing a pre-shared symmetric key combined with AES and HMAC-SHA256 algorithms to encrypt and authenticate CAN communication data, ensuring the confidentiality, integrity, and authenticity of data transmission. Simultaneously, it introduces intrusion detection technology based on information entropy to effectively defend against data frame injection attacks initiated by legitimate nodes. This application employs a strategy of parallel processing of data frame transmission and encryption computation, solving the problem of existing methods where the CAN controller and security module are implemented independently, introducing additional data handling overhead. This achieves efficient transmission of encrypted CAN data and has excellent development and application prospects.
Owner:SOUTHEAST UNIV

Hybrid security framework for radio frequency and vision based positioning systems

Techniques for communication are disclosed. In an aspect, a network entity receives, from a target network node, radio frequency (RF)-based information obtained by the target network node, obtains, from one or more network nodes, visual channel state information (vCSI) associated with the target network node, and determining whether the RF-based information is compromised based on a comparison of a first set of values of a set of characteristics of an environment of the target network node determined based on the RF-based information and a second set of values of a set of characteristics of an environment of the target network node determined based on the vCSI.
Owner:QUALCOMM INC

Dikwp ai-os and security framework

The invention relates to a DIKWP aware operating system (AI-OS) and a security framework. The invention provides an artificial consciousness operating system and a security framework based on a DIKWP (Data-Information-Knowledge-Intelligence-Intention) model, and aims to solve the problems that the decision-making process of an existing AI (Artificial Intelligence) system is black, the existing AI system does not have self-cognition, the security is uncontrollable and the like. According to the operation system, the cognitive process of AI is divided into five stages of data processing, information extraction, knowledge application, intelligent decision making and intention management, and through core components such as a concept-semantic fusion kernel, a white-box evaluation module, a semantic security protection module and an intention regulation and control interface, an intellectual property of the AI is evaluated. Semantic checking, whole-process monitoring and purpose constraint of an AI internal cognitive process are realized. Wherein the kernel adopts a concept space and semantic space double-layer verification mechanism to improve AI semantic understanding consistency, the white box module records AI full-link reasoning to achieve interpretable auditing, the safety protection module is embedded into ethical rules to intercept violation output in real time, and the intention interface directly acts human high-level intentions on the AI decision process. Through the architecture, the decision-making process of the AI system is transparent and controllable, the output behavior is consistent with the preset target and value criterion, and the interpretability, safety and reliability of the AI system are remarkably improved.
Owner:HAINAN UNIV

Privacy-preserving personalized federated learning methods and apparatus for heterogeneous scenarios

This invention discloses an efficient personalized privacy-preserving federated learning method for heterogeneous scenarios. The specific implementation steps include: 1. System initialization and key distribution; 2. Global model distribution; 3. Client base layer and personalization layer updates; 4. Encrypted upload and local update; 5. Weighted aggregation of the global model; 6. Global model update. This invention overcomes the limitations of heterogeneous data scenarios based on a "base + personalization layers" model, alleviating the problems of low global model accuracy and poor generalization caused by data heterogeneity. This invention designs a privacy-preserving framework based on CKKS fully homomorphic encryption, achieving client privacy protection during the federated learning process. Simultaneously, it significantly reduces computational and communication overhead and improves encryption efficiency under large-scale vectors and model parameters.
Owner:SICHUAN POLICE COLLEGE +1

A mimicry-based secure data exchange method based on MQTT

The present application relates to a kind of mimicry security data exchange methods based on MQTT, the method utilizes the subscription / distribution capacity of MQTT proxy, constructs MQTT proxy redundancy cluster, broadcast one data to multiple MQTT proxy by distribution component, adopts the large number of decision mode of mimicry security, and the same theme data is merged;The method is based on the framework composition of MQTT proxy's mimicry security data exchange, and the composition structure includes publisher, distribution component, MQTT proxy cluster, decision component, subscriber, negative feedback component;The problem that multiple data transmission paths are increased for security but also bring difficult to merge in data transmission of mimicry security framework is solved, the present application is based on the original mimicry security defense architecture, utilizes the data distribution capacity of MQTT subscription, redundantly parallelly deploys multiple MQTT proxy, and effectively protects the intelligent fusion terminal application in the edge side of Internet.
Owner:EAST CHINA INST OF COMPUTING TECH

Proactively determining security risks and deployment impacts across cloud computing environments

This disclosure describes a proactive deployment impact system that detects and addresses the security impact of candidate code-based infrastructure changes before they are deployed in a production environment within a cloud computing system. The proactive deployment impact system implements a lightweight preemptive security framework, based on runtime resource information, to determine whether a requested candidate code-based infrastructure change would introduce new security risks, attack patterns, or breach vulnerabilities. Furthermore, the proactive deployment impact system can actively block the deployment of negatively impacting candidate changes, report potential security breaches, and / or automatically modify the candidate changes to eliminate security vulnerabilities.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Seamless network confidentiality for a containerized application on edge infrastructure

Methods and systems for managing operation of endpoint devices are disclosed. The operation of the endpoint devices may be managed using a security framework. The security framework may be used to transparently encrypt and decrypt application data transmitted via a network without requiring the applications to participate in the encryption and decryption. Additionally, the security framework may facilitate screening of network traffic for malicious traffic. The traffic may be screened using information inserted into reserved fields of control information from network data units. The reserved fields may be used to store data based on network information for originating entities.
Owner:DELL PROD LP

Application migration security framework using service mesh and bi-directional proxy

Systems and methods for secure migration of applications using service mesh and bi-directional proxy are described. According to one embodiment, an Information Handling System (IHS) includes executable logic to receive a request to migrate an application from a first computing device to a second computing device, deploy a first side-car module on the first computing device and a second side-car module on the second computing device, establish a secure communication tunnel with the first and second side-car modules, and using the secure tunnel, migrate the application from the first computing device to the second computing device.
Owner:DELL PROD LP

Privacy protection Transform reasoning method and system based on integral gradient three-dimensional collaborative optimization

The invention relates to the technical field of text processing, in particular to a privacy protection Transform reasoning method and system based on integral gradient three-dimensional collaborative optimization, and the method comprises the steps: inputting a text processing data set into a pre-training Transform model in an offline stage, carrying out the path integral attribution of the output of each attention head of each layer of the model on the text processing data set, and carrying out the path integral attribution of the output of each attention head of each layer of the model; obtaining importance scores of the attention heads based on path integral attribution, and constructing a pruning strategy of cross-layer global sorting and unified threshold control, so as to perform pruning operation on the attention heads in the pre-trained Transform model by using the pruning strategy to obtain a text processing target model; and in the online stage, deploying the text processing target model to a privacy reasoning platform under the secure multi-party computing framework so as to obtain a reasoning result of the to-be-processed text under the secure multi-party computing framework. According to the method, the efficiency and practicability of privacy reasoning can be improved on the premise of not changing the existing text processing security framework.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University

Mutable Code Efficiencies in Measured Secure Boot for Hardware Root of Trust

Mutable firmware commonality for hardware root of trust is described. In at least one aspect, a system includes a volatile memory circuit having a first region that persistently stores a reusable portion of instructions executed during a boot sequence for establishing a hardware root of trust among multiple security layers of a security framework, and a second region that is overwritten during the boot sequence with each layer-specific portion of the instructions executed sequentially to implement a corresponding security layer based on the reusable portion. The system further includes a processing circuit that sequentially establish the hardware root of trust one security layer at a time by loading the second region of the volatile memory with a current layer-specific portion of the instructions that are executed in combination with the reusable portion of the instructions to implement a current security layer.
Owner:ATI TECHNOLOGIES ULC +1