Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

29 results about "Security function" patented technology

Security functions are the hardware, software, and/or firmware of the information system responsible for enforcing the system security policy and supporting the isolation of code and data on which the protection is based.

System for orchestrated management of identity security functions in container-based multi-cloud environments

ActiveDE202026100671U1Resource allocationDigital data authenticationOrchestration (computing)Security rule
System for the orchestrated management of identity security functions in container-based multi-cloud environments, comprehensive an identity data capture unit, trained to capture identity-related security parameters from multiple distributed, container-based computing environments, an orchestration control unit, trained to coordinate the control of identity and access security functions across multiple cloud environments, a policy linking unit, trained to assign safety rules to container-related execution states, and a security enforcement unit trained to execute identity-related security measures within the respective computing environment, the system coordinates identity security functions across environments without imposing a fixed prioritization of individual cloud environments.
Owner:GAHLOT RAKESH EDISON +3

Method for verifying the setting of predefined safety functions of a field device in process and automation technology

A method for verifying the setting of predefined safety functions (SF1, ..., SFn) of a field device for process and automation technology, wherein the predefined safety functions (SF1, ..., SFn) relate in particular to access to at least one function of the field device by an unauthorized person, wherein the method provides the following steps: - Determining a security level required at the measuring point and / or at the field device, wherein the determined security level defines the target setting of the predefined safety functions (SF1, ..., SFn) of the field device (1), - Identifying a user by means of an authentication protocol (2), - Starting a query about the actual setting of the safety functions (SF1, ..., SFn) of the field device specified at the measuring point by the user (3), - Comparing the actual setting of the predefined safety functions (SF1, ..., SFn) of the field device with the target setting of the specified safety functions (SF1, ..., SFn) defined by the specified safety level (4),- Issuance of an electronic report to the user regarding a conformity or deviation between the actual setting and the target setting of the specified safety functions (SF1, ..., SFn) of the field device (5),- in the case of conformity between the actual setting and the target setting of the specified safety functions (SF1, ..., SFn) of the field device, the following step is provided:◯ Storage of the electronic report (6), or- in the case of deviation between the actual setting and the target setting of the specified safety functions (SF1, ..., SFn) of the field device, the following steps are provided:◯ Proposal of at least one measure to adjust the actual setting of at least one specified safety function (SF1, ..., SFn) of the field device to the target setting (7), whereby at least one measure is shown to the user,◯ Implementation of the at least one proposed measure to adapt the actual setting to the target setting of the specified safety functions (SF1, ..., SFn) of the field device by the user (8),◯ Repetition of the query about the actual setting of the specified safety functions (SF1, ..., SFn) of the field device by the user (3).
Owner:ENDRESS & HAUSER GMBH & CO KG

Electronic device, method, and non-transitory storage medium for changing screen displayed on display

The present document relates to an electronic device, a method, and a non-transitory storage medium for changing a screen displayed on a display. According to one embodiment, the electronic device may comprise: a display; at least one processor including a processing circuit; and a memory for storing instructions. The instructions, when executed individually or collectively by the at least one processor, may instruct the electronic device to: display, on the display, a screen including a first image indicating first information; on the basis of performing a security function for the screen, identify information related to at least one pixel of an inner part or an outer part with respect to a boundary between an object indicating the first information included in the first image and a background excluding the object; on the basis of the information related to the pixel, obtain a second image in which at least one of the inner part or the outer part is adjusted; obtain a third image in which the background included in the first image is blurred; obtain a fourth image in which the first information is processed so as not to be visually identified at a specified distance or more, by using the second image and the third image; and replace the first image displayed on the screen with the fourth image. Various other embodiments are also possible.
Owner:SAMSUNG ELECTRONICS CO LTD

Latent fault detection system, method and on-board chip for register protection security mechanism

ActiveCN119621450BIn vehicleMode control
The present application relates to a latent fault detection system, method and vehicle chip of register protection security mechanism, by adding fault mode control register, fault injection register and self-checking control module between each register related to security function and register protection security mechanism module, to realize fault self-checking of register protection security mechanism module in the way of increasing self-checking circuit module, the self-checking process does not produce destruction to the existing function circuit and does not need to reset after self-checking, and does not need to rely on DFT logic, and there is no test level requirement to module and system, the increased self-checking circuit module can be integrated in IP development stage of vehicle chip, so that latent fault detection in different modes is automatically executed according to the configured fault detection mode through self-checking control module, and a simplified and efficient latent fault detection means is provided and higher self-checking coverage is realized.
Owner:上海芯钛信息科技有限公司

Data storage device and method of operation thereof

ActiveCN114254402BEngineeringMessage authentication code
The present invention relates to a data storage device and an operating method thereof. According to the present invention, a data storage device providing an improved security function includes a memory device including a protected storage block protected by a security protocol; and a memory controller configured to receive a command protocol component associated with the security protocol, the security protocol including a host-side protection message requesting to write data from a host to the protected storage block, perform an authentication operation on the protected storage block using a host message authentication code included in the host-side protection message, and store the data from the host according to a result of the authentication operation.
Owner:SK HYNIX INC

Secure chip and multi-application management method, device and storage medium thereof

The application discloses a kind of security chip and its multi-application management method, device and storage medium, it is related to chip technical field.The method comprises the following steps: in response to external command, target application and target management requirement are determined according to external command by management task;If target management requirement is to create target application, the application management handle of target application is created, and the application management handle is added to application management linked list, and the processing task of target application is created;When the processing task of target application is scheduled to execute, the application management handle of target application is obtained from application management linked list, and the command set in application management handle is searched using application processing framework function to find security function function table, obtain target security function function, and execute target security function function based on command data in application management handle.The method not only can realize the dynamic management of application, including dynamic creation, but also can reduce code compilation, application loading complexity, and reduce storage space occupation.
Owner:BEIJING SMARTCHIP MICROELECTRONICS TECHNOLOGY CO LTD

Security systems, security devices, security methods and programs

The aim is to allow video confirmation at the control center as needed, even when security is deactivated, while respecting user privacy. [Solution] The security system 100 includes an imaging device 10 that captures images of a predetermined security area S, a security device 30 that acquires images from the imaging device 10, a security terminal 50 that requests the security device 30 to display the images and displays the images when the request is approved, and a user terminal 60 that receives an image display signal indicating that the security terminal 50 has displayed the images. When the security device 30 approves the security terminal's request to display the images, it transmits the images to the security terminal 50 and also transmits an image display signal to the user terminal 60.
Owner:KING TSUSHIN INDS

Information processing device

To provide an information processing device that can reduce development man-hours and lower vulnerabilities. [Solution] The memory 10 of the information processing device 1 stores a secure function module 111a that contains instructions to be executed by the processor 20 in the performance of a function and is restricted from external interference. The memory 10 also stores a processing function module 131 that contains instructions common to the secure function module 111a, has less restrictive external interference than the secure function module 111a, and is processed into a disabled state in which the processor 20 cannot execute instructions. The memory 10 also stores a release module 112 that has more restricted external interference than the processing function module 131 and can release the disabled state in the processing function module 131. The memory 10 also stores a security request determination flag 115 that defines the security level required in the performance of a function.
Owner:DENSO CORP

METHOD AND SYSTEM FOR MONITORING AN ONBOARD COMMUNICATION NETWORK OF AN AIRCRAFT

A method for monitoring an aircraft's onboard communication network, comprising, for a data stream transmitted or received by a network switch, a flow limiting function (to enforce a bandwidth limit) and a security function (202) comprising: obtaining measurements of at least one stream parameter; based on the measurements obtained, calculating a value of at least one bandwidth consumption parameter, contributing to the definition of a measured bandwidth consumption profile; comparing the measured profile with a predetermined profile by comparing the calculated value with a reference value; and, if at least one difference criterion is met, performing at least one network security action. This allows the detection of an unusual (although remaining below the bandwidth limit) bandwidth consumption profile that could constitute a malicious act. Figure to be published with the abbreviation: Fig. 2
Owner:AIRBUS OPERATIONS (SAS)

Security enhancement methods and systems for the IEC 104 protocol on the master station side of power monitoring systems

PendingCN122339686AIEC 62351Embedded system
This invention discloses a security enhancement method and system for the IEC 104 protocol on the master station side of a power monitoring system, comprising: generating input data, dynamically selecting a security mode and issuing configuration commands, generating original ASDU messages, calling application-layer security plugins to generate enhanced ASDU messages, encapsulating them into complete APDUs, generating security messages via transport-layer security plugins, and sending them to the station. This invention adopts a plug-in embedded architecture, integrating IEC 62351-5 application-layer and IEC 62351-3 transport-layer security plugins into the protocol processing module and communication processing module respectively, achieving decoupling of security functions and business functions; establishing a policy-driven mechanism, adding a security policy management module and an operation monitoring module, and providing port differentiation to adapt to different terminals to meet the needs of gradual transformation; controlling terminal concurrent connection latency at the millisecond level to meet the needs of large-scale high-concurrency access at the master station, and establishing a layered security protection system that coordinates the transport layer and application layer, ensuring message security even if transport layer security fails.
Owner:NARI NANJING CONTROL SYSTEM CO LTD +1

Communication method and apparatus

Provided in the present application are a communication method and apparatus, which are used for preventing a key of a terminal from being stolen by an attacker, thereby ensuring the communication security of the terminal. The method comprises: a network function production entity serving a terminal sending a first message to a first security function entity, receiving a second message from the first security function entity, and sending ciphertext information to a network function consumption entity, wherein the network function production entity and the first security function entity are deployed in the same hardware environment, the network function production entity operates in a first operating environment, the first security function entity operates in a second operating environment, and the security level of the second operating environment is higher than the security level of the first operating environment; the first message is used for requesting the generation, for the network function consumption entity serving the terminal, of a key shared by the network function consumption entity and the terminal; and the second message comprises the ciphertext information, and the ciphertext information is ciphertext obtained by means of the first security function entity encrypting the key shared by the network function consumption entity and the terminal.
Owner:HUAWEI TECH CO LTD

Method and system for monitoring an onboard communication network of an aircraft

The application discloses a method and a system for monitoring an onboard communication network of an aircraft. The method comprises, for a data flow sent or received by a switch of the network, performing a traffic policing function (to bring the data flow into compliance with a bandwidth limit) and performing a security function (202) comprising obtaining a measurement of at least one parameter of the traffic, calculating, from the obtained measurement, a value of at least one bandwidth consumption parameter, the calculated value participating in the definition of a measured bandwidth consumption curve, comparing the measured curve with a predefined curve by comparing the calculated value with a reference value, and performing at least one action for protecting the network in the event of a verification of at least one discrepancy criterion. This makes it possible to detect abnormal bandwidth consumption curves that can constitute malicious actions (despite the fact that they remain below the bandwidth limit).
Owner:AIRBUS OPERATIONS (SAS)

A vehicle-mounted signal system of a SIL2 safety level and a control method thereof

ActiveCN121425302BChannel dataIn vehicle
The application discloses a SIL2 safety level vehicle-mounted signal system and a control method thereof, and the system comprises a safety computing core, a CLU3 module and an input and output VDU module; the safety computing core comprises CLU1 and CLU2 modules, realizes system safety functions, and carries out double-channel data comparison and internal self-checking; the VDU executes input collection and output control, and when internal faults are detected, the safety output channel thereof enters and maintains a no-output state, and fault information is reported; the CLU3 independently takes charge of non-safety functions; wherein, the safety computing core carries out fault diagnosis and safety level division according to comprehensive self-checking, double-channel comparison and VDU reported information, and generates alarm information; the CLU3 outputs alarm signals corresponding to fault levels to external systems or drivers according to the alarm information, and the final safety control is completed by the external systems or drivers. Compared with the prior art, the application reduces system complexity and cost effectively under the premise of ensuring the SIL2 safety level through fault grading, alarm and man-machine cooperative control mechanisms.
Owner:CASCO SIGNAL LTD

Computerized systems and methods for network expansion via connectivity nodes and event detection based therefrom

ActiveUS12677204B2Computerized systemSelf adaptive
Disclosed are systems and methods that provide a computerized framework that provides functionality for an expanded node-based network that can dynamically adapt to the location / position of a location tracker, while enabling the tracker to automatically trigger security and / or safety features for its associated user / item. The disclosed framework can dynamically and automatically compile connectivity nodes of disparate networks to provide (both low-cost and high-end) trackers continuous network coverage. Effectively, the disclosed framework can provide trackers with an adaptive Internet of Things (IoT)-type network that leverages connectivity nodes of specific networks to provide and maintain connectivity the tracker as the tracker traverses the real-world. Moreover, the tracker can provide capabilities that automatically can detect specific types of events, which can trigger notifications, alerts and / or remedial measures that are all enabled via the novel network connectivity provided via the disclosed framework.
Owner:PLUME DESIGN INC

Elevator system

To improve user convenience. [Solution] An elevator system according to one embodiment is an elevator installed in a building where an automatic door with an auto-lock function is provided at the entrance, and includes an elevator with a security function that restricts the buttons for registering calls. The elevator system comprises a first wireless signal transmitter installed at the entrance and transmitting a first wireless signal to the surroundings, and a second wireless signal transmitter installed at the landing of each floor of the building and transmitting a second wireless signal to the surroundings. An application is installed on the resident's mobile terminal that allows setting a security number to release the restrictions placed on the elevator and floor information indicating the floor used by the resident. When the mobile terminal receives the first wireless signal, it transmits a request to release the restrictions placed on the elevator, and when it receives the second wireless signal, it transmits a request to register a destination call corresponding to the floor information.
Owner:TOSHIBA ELEVATOR KK

Method and electronic device for evaluating at least one cybersecurity function of a computer system, associated computer program

PendingFR3170657A1Cyber-attackSimulation
Method and electronic device for evaluating at least one cybersecurity function of a computer system, associated computer program. This method for evaluating at least one cybersecurity function (D, P) of a computer system (15) is implemented by an electronic device and comprises: - measuring a level of a reaction generated by a cybersecurity function (D, P), in response to at least one cyberattack stimulus against said system; - determining an evaluation score for the cybersecurity function (D, P), from unit evaluation score(s) calculated each for at least one stimulus, by comparing the measured reaction level with a predefined expected reaction level, associated with said at least one stimulus and with the cybersecurity function;The unit score when the measured reaction level is equal to the expected level differs from the unit score when the measured reaction level is greater than the expected level; - implementation of at least one action associated with the determined evaluation score. Figure for the abbreviation: Figure 1;
Owner:NAVAL GRP

Automatic, security-induced relocation of at least one container instance

A method and device for the automatic, security-induced relocation of at least one container instance in an orchestrated environment that contains more than one guest computer managed by an orchestration apparatus is provided, including the following steps: the orchestration apparatus launching the container instance on a first guest computer that comprises security functions in accordance with a first security level, receiving a security alarm message including at least one criticality parameter that indicates a security status of the orchestrated environment from a monitoring apparatus in the orchestration apparatus, the orchestration apparatus determining a second security level, different from the first security level, for the container instance based on a relocation policy depending on the criticality parameter, the orchestration apparatus relocating the container instance to a second guest computer in the orchestrated environment that includes security functions in accordance with the second security level.
Owner:SIEMENS AG

Method and device for implementing successful channel of safety function of nuclear power plant and storage medium

ActiveCN115983629BOptimizing Emergency Response Mission PlanningRealize task planning for specific working conditionsPower plant safety arrangementData processing applicationsNuclear powerPower apparatus
The application discloses a nuclear power plant safety function success channel implementation method and device, computer equipment and a storage medium, and the method comprises the following steps: according to the overall design criteria and the functional structure design features of the nuclear power plant, a hierarchical function coupling structure model of the target tree-success tree-state tree of the nuclear power plant is established; further, according to the key safety parameter supervision feedback and the alarm grading system, the complete or damaged state of the safety function state of the nuclear power plant is determined, the corresponding emergency response task target is formulated, the key safety function relief and recovery structured success channel is generated through the hierarchical function task association structure model deduction analysis, the safety level division of the safety function implementation front system is referred to, the safety function success channel set optimization sorting and visual operation instruction are realized. The method provided by the application can quickly guide the operator to perform safety function recovery and relief, and reduce the consequence harm influence of the accident.
Owner:SOUTH CHINA UNIV OF TECH

Safety protection methods and electronic equipment for energy storage battery management systems

This application discloses a security protection method and electronic device for an energy storage battery management system. The method includes: acquiring monitoring data and data encryption and access control configuration data of the energy storage battery management system, wherein the monitoring data includes at least hardware self-test data, communication link status data, data integrity data, and network connection behavior data; determining the security status of the energy storage battery management system based on the monitoring data and the data encryption and access control configuration data; and determining a security protection strategy for the energy storage battery management system based on the security status, wherein the security protection strategy at least indicates the data acquisition strategy, the data encryption strategy for specified data, and the access control strategy for the energy storage battery management system. This application solves the technical problem in related technologies where the security function modules of energy storage battery management systems are isolated and have static responses, resulting in a lack of dynamic linkage in the protection strategy and an inability to achieve accurate security protection for energy storage batteries.
Owner:HEFEI GUOXUAN HIGH TECH POWER ENERGY

Safety device for flow rate measurement device, and flow rate measurement device

This safety device (10A) for a flow rate measurement device comprises: internal communication units (12a, 12b) (the number of internal communication units may be one) that communicate with a flow rate measurement device for measuring the flow rate of a fluid; a safety assessment processing unit (11) that assesses the execution of a safety function by the flow rate measurement device by using output information from the flow rate measurement device, said output information being obtained through communication performed by the internal communication units (12a, 12b); and an authentication unit (13) that generates, as at least authentication information, an indicator value included in the output information from the flow rate measurement device, and, on the basis of the authentication information, assesses authentication with the flow rate measurement device with which communication is to be performed. This makes it possible, even with, e.g., a flow rate measurement device that does not have a safety function, to implement a safety function that is suitably reliable for the flow rate measurement device.
Owner:PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD

Dynamic Operative and Procedural Report Generator

The Dynamic Operative and Procedural Report Generator is a system designed to create structured operative and procedural reports dynamically. The system receives procedure-specific inputs from a user and, based on predefined templates and logic, requests additional information to ensure a complete and accurate report. The invention allows for seamless customization across various medical specialties and integrates with electronic medical records (EMR) systems. The generated reports follow a structured format, ensuring consistency, efficiency, and accuracy in medical documentation. The system can be implemented as a web application, desktop application, or standalone software, with security features including encryption and role-based access. The invention significantly reduces the time required for medical professionals to document procedures while maintaining compliance with medical documentation standards.
Owner:KATZ JONATHAN

Method and system for monitoring a communications network on board an aircraft

A method for monitoring an onboard communications network of an aircraft including, for a data stream transmitted or received by a switch of the network, a traffic policing function (making it comply with a bandwidth limit) and a security function that obtains measurements of at least one parameter of the traffic; as a function of the measurements obtained, calculates a value of at least one bandwidth consumption parameter, participating in a definition of a measured profile of bandwidth consumption; compares the measured profile with a predetermined profile, by comparing the calculated value with a reference value; and in the case of verification of at least one difference criterion, performs at least one act for safeguarding the network. This allows an unusual profile (although remaining below the bandwidth limit) of bandwidth consumption to be detected, which may constitute a malicious act.
Owner:AIRBUS OPERATIONS (SAS)

Remote verification of the condition of a mobile device

ActiveUS12652539B2Image analysisUnauthorised/fraudulent call preventionGraphical user interfaceMobile device
In various implementations, an acceptable condition of a mobile device may be determined based on a remote verification of a condition of the mobile device, wherein a method to verify the mobile device may comprise a user requesting the verification of the mobile device, the performance of a diagnostic on the mobile device, the reception of a security data object associated with the mobile device by the system, and / or the determination that the mobile device has a security feature either disabled or enabled. When the security feature of the mobile device is enabled or disabled, the system may configure the GUI to direct a user to disable the security feature or the system may configure the GUI to show an acceptable condition when the security feature is disabled.
Owner:ASSURANT INC

Secure data distribution in microprocessor-based system-on-chip

PendingCN122457241AEngineeringSystem on a chip
The present disclosure relates to secure data distribution in microprocessor-based systems on a chip. An example device includes circuitry configured to implement a security function, a first memory configured to store first data including a secret, a processor configured to execute software configured to execute instructions for reading the secret from the first memory and supplying the secret to the circuitry, a second memory whose data is inaccessible by the software, and an interconnect coupled to the first memory, the second memory, the processor, and the circuitry, the interconnect configured to receive a program data transfer request from the processor, read the secret from the first memory, write the secret to the second memory, read the secret from the second memory, and supply the secret to the circuitry.
Owner:AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD

Fixed retail scanner with multi-port network switch and related methods of managing access to network devices

PendingUS20260187393A1TelecommunicationsVirtual LAN
The disclosure includes a fixed retail scanner including a data reader having a multi-port network switch disposed within a housing of the data reader. The multi-port network switch is configured to be configurable to provide security features to the network, including method for locking ports of the switch to specific scanner accessories and other devices, creating virtual local area networks for the devices of the date reading system, and other locating features over the network.
Owner:DATALOGIC IP TECH