Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

196 results about "Security function" patented technology

Security functions are the hardware, software, and/or firmware of the information system responsible for enforcing the system security policy and supporting the isolation of code and data on which the protection is based.

Trusted management and control network platform construction method and device, electronic equipment and storage medium

The invention belongs to the field of network security, and relates to a trusted management and control network platform construction method and device, electronic equipment and a storage medium, the method comprises the following steps: constructing a basic security architecture and a trusted base, the basic security architecture being used for providing a unified root of trust and a management core for collaborative operation of upper security components; based on the basic security architecture and the trusted base, implementing multi-dimensional trusted verification and dynamic access control; an intelligent boundary protection and depth detection system is deployed and is used for constructing an intelligent, three-dimensional and self-adaptive security defense line at the boundary of each region of the network, and various known and unknown threats can be identified and blocked; constructing a unified secure communication tunnel and a cross-domain transmission guarantee; defining and realizing a standardized security function interface and a collaboration protocol; and a continuous trust evaluation and automatic operation management and control closed loop is established. The overall security is enhanced, the secure transmission of data is ensured, the compatibility and collaboration of the system are improved, and the security operation intelligence is realized.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Filtered data lake for enterprise security

A data lake for enterprise security is created from an asynchronous stream of security events by deduplicating objects and creating metadata related to downstream security functions. Deduplication of objects may be efficiently performed with a bloom filter as objects are ingested into the data lake. The objects may also be augmented with metadata arranged in schemas to facilitate monitoring and use within the data lake.
Owner:SOPHOS LTD

Property asset digital operation and intelligent security linkage cooperative processing system and implementation method

The invention discloses a property asset digital operation and intelligent security linkage cooperative processing system and an implementation method, and relates to the technical field of Internet of Things, and the system comprises a protocol adaptive gateway layer which solves the problem of compatibility of multi-manufacturer equipment, and outputs a standardized data stream based on a dynamic protocol sniffing and fingerprint feature library, SDK-free access control, fire protection, monitoring and IoT equipment; the method comprises the following steps: constructing a millimeter-level precision three-dimensional space model by a digital twinborn middle table layer, fusing a security event and operation data, and ensuring that the operation is compliant and audible through blood relationship tracking; the intelligent decision execution layer combines a rule engine and machine learning to generate a linkage instruction, drives a work order to be automatically distributed and positions an equipment fault responsible party; and the edge cooperative computing node locally realizes video millisecond-level analysis, and starts localized linkage according to an emergency plan when the network is disconnected, so as to ensure that the core security function is not interrupted.
Owner:BEIJING TIANRUI CHUANGXIN TECHNOLOGY CO LTD

Storage device including replay protected memory block (RPMB) host device accessing the RPMB, electronic device including storage device and host device, and method of operating the same

Storage devices, host devices and electronic devices are disclosed. In an embodiment of the disclosed technology, an electronic device providing an improved security function may include a storage device including a replay protected memory block (RPMB), and a host device configured to provide a command protocol information unit (PIU) instructing the storage device to access the RPMB. The command PIU may include a basic header segment including a total extra header segment length field having a value other than 0 and an extra header segment including a host RPMB message.
Owner:SK HYNIX INC

Autonomous operation vehicle supervision terminal identity authentication method

The invention discloses an identity authentication method for a supervision terminal of an automatic driving commercial vehicle, which belongs to the field of vehicle supervision, and comprises the steps of deploying a unified password service platform, and calling various password services by a supervision platform so as to support various safety functions. In addition, by supervising terminal device registration, generating a device unified identifier and interacting with a unified password service platform, generation and distribution of a device initial key are realized. According to the method, an equipment SM9 private key acquisition process is introduced, and the secure acquisition of the equipment private key is realized through the generation of an SM2 public and private key pair. Meanwhile, a specific supervision terminal authentication process is provided, and the identity authentication security of the terminal equipment and the unified password service platform is guaranteed through a challenge-response mode. Moreover, the authentication entity relationship and the key updating mechanism are described in detail, and an all-dimensional and multi-level authentication system is constructed.
Owner:ZHONGLU HI TECH TRAFFIC TECH GRP

Self-contained biometric device, system, and method for secure digital transactions, identity verification, and multi-currency asset management

A self-contained biometric device, method, and system for secure digital transactions is provided. The device comprises a housing that may be a subdermal implant, dermally-applied biometric tattoo, ergonomic external wearable, or smart card. The housing maintains consistent secure functionality during offline and online operation modes and includes a biometric verification module that captures a biometric input of a user and performs user authentication entirely within the device. A hardware-isolated storage module physically isolated from external networks stores cryptographic keys, credentials, and biometric templates. The device permits access to the cryptographic keys and credentials only upon successful user authentication. A transaction processing module resident inside the hardware-isolated storage module executes digital asset transactions entirely within the device in offline mode. This self-contained architecture enables secure, autonomous operation without reliance on external networks or computation.
Owner:OMNIUS CORP

Security cooperation system and method in hybrid cloud environment

The invention relates to the field of network security, and particularly provides a security cooperation system and method in a hybrid cloud environment. The system comprises a unified security management module, a security solution cooperation module and a security function module. The unified security management module analyzes a self-healing algorithm through a policy graph, carries out graph modeling on a multi-cloud security policy, automatically identifies policy conflicts and drifts through graph difference analysis, and realizes continuous consistency and self-healing of a cross-cloud policy. And the security solution cooperation module is embedded into a reinforcement learning agent, dynamically decides an optimal deployment scheme of security resources according to a reward function by sensing a threat situation, a resource utilization rate and response delay, and realizes intelligent self-adaptive arrangement of protection resources. The security function module is used for micro-servitizing and containerizing security capability based on a cloud native technology, transparent injection is realized through a service grid, an automatic compliance repair and verification mechanism is built in, and a compliance closed loop for detection, repair and verification is formed. And the management efficiency and the protection accuracy of the security policy are improved.
Owner:STATE GRID SICHUAN ELECTRIC POWER CORP ELECTRIC POWER RES INST

Electronic device including a storage device and a host device and methods of operation

A storage device for providing a security function may include: a nonvolatile memory device including a Replay Protected Memory Block (RPMB); and a memory controller configured for receiving, from an external host, a command UFS Protocol Information Unit (UPIU) including a host RPMB message, and storing data in the RPMB according to authentication performed using the host RPMB message. The command UPIU may include a basic header segment commonly included in UPIUs transmitted / received between the external host and the memory controller, and the basic header segment may include a data segment length field as information indicating that the host RPMB message has been included in the command UPIU.
Owner:SK HYNIX INC

Authorized access to security event data

Various aspects of the present disclosure relate to authorized access to security event data. An apparatus, such as a network equipment (NE) that implements a first network function (NF) (e.g., a network repository function (NRF)), receives a request from a second NF (e.g., an operator security function (OSF)) for a token to access security event data from a third NF (e.g., an NF service producer). The first NF generates the token using a profile of the second NF. The first NF transmits the token to the second NF. A fourth NF (e.g., a data collection function) can request a second token from the first NF to access the security event data for the second NF. The third NF can transmit the security event data to the second NF via the fourth NF or directly. This enables secure and authorized access to security event data in wireless communication networks.
Owner:LENOVO (SINGAPORE) PTE LTD

Method and electronic device for configuring network lock function of electronic device

An electronic device may include: an application processor, a communication processor, and a security subsystem for processing a security function related to the application processor or the communication processor. The security subsystem may decrypt, based on reception of a request for decrypting a nonce value from the communication processor, the nonce value and transmit the decrypted nonce value to the communication processor, and may generate a signature using the nonce value and network lock data based on reception of a request for network lock signature from the communication processor and transmit the generated signature to the communication processor. The communication processor may receive a signature value generated from the security subsystem, compare a signature value pre-stored in the application processor with a signature value received from the security subsystem, and determine whether to restrict use of the electronic device based on whether the signature value pre-stored in the application processor and the signature value received from the security subsystem are matched to each other.
Owner:SAMSUNG ELECTRONICS CO LTD

Network security gateway onboard an aircraft to connect low and high trust domains of an avionics computing infrastructure

The gateway, which connects a low-trust domain (12) and a high-trust domain (13) of an avionics computing infrastructure, provides a plurality of security functions, each function being performed by a data processing node. The gateway comprises, connected in series along a filtering chain of a data flow received from the low-trust domain: a firewall data processing node (4); a protocol break data processing node (5); a master data processing node (1) and an inverse protocol break data processing node (6), the gateway further including a security data processing node (2) connected to each of the data processing nodes of the filtering chain, the different data processing nodes being physically segregated.
Owner:THALES SA

Systems and methods for hierarchical deep packet inspection for scalable network monitoring and cyber security functions

A system and method for hierarchical network monitoring functions are disclosed. An order of execution for layer functions of a network architecture is determined. The layer functions may be distributed across multiple layers. The layers may include a sensor layer, a federated application layer, and a data lake layer. A machine learning model may be executed at a first layer. The first layer may be the sensor layer.
Owner:NETSCOUT SYSTEMS INC

Safety device for flow rate measuring device and flow rate measuring device

A safety device (10A) comprises: internal communication units (12a, 12b) that communicate with a flow rate measuring device; a safety determination processing unit (11) that determines whether to execute a safety function in the flow rate measuring device using output information of the flow rate measuring device obtained through communication of the internal communication units (12a, 12b); and a safety determination value setting unit (13) that sets and stores a safety determination value to be used for determining whether to execute the safety function by the safety determination processing unit (11). The safety device (10A) may be provided with a flow rate integration unit that calculates, from fluid flow rate information included in the output information, an integrated consumption amount of the fluid, or may be configured as a unit mountable to the flow rate measuring device. This makes it possible to easily implement a safety function in a flow rate measuring device, for example, even if the flow rate measuring device does not have a safety function.
Owner:PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD

SIL2 security level vehicle-mounted signal system and control method thereof

The invention discloses an SIL2 security level vehicle-mounted signal system and a control method thereof. The system comprises a security calculation core, a CLU3 module and an input and output VDU module. The safety calculation core comprises a CLU1 module and a CLU2 module, realizes a system safety function, and performs dual-channel data comparison and internal self-inspection; the VDU executes input acquisition and output control, a safe output channel of the VDU enters and maintains a non-output state when an internal fault is detected, and fault information is reported; the CLU3 is independently responsible for a non-safety function; wherein the security calculation core performs fault diagnosis and security level division by integrating self-inspection, dual-channel comparison and VDU report information, and generates alarm information; and the CLU3 outputs an alarm signal corresponding to the fault level to an external system or a driver according to the fault level, and final safety control is completed by the external system or the driver. Compared with the prior art, the system complexity and cost are effectively reduced on the premise of ensuring the SIL2 security level through fault grading, alarming and man-machine cooperative control mechanisms.
Owner:CASCO SIGNAL LTD

Exchange of flow metadata between network and security services' security functions

Techniques are disclosed that provide for exchange of flow metadata between network and security services' security functions. In some embodiments, a system / process / computer program product for providing for exchange of flow metadata between network and security services' security functions includes receiving, at a network gateway of a security service, a flow from a software-defined wide-area network (SD-WAN) device, inspecting the flow to determine meta-information associated with the flow, and communicating the meta-information associated with the flow to the SD-WAN device.
Owner:PALO ALTO NETWORKS INC

System for orchestrated management of identity security functions in container-based multi-cloud environments

System for the orchestrated management of identity security functions in container-based multi-cloud environments, comprehensive an identity data capture unit, trained to capture identity-related security parameters from multiple distributed, container-based computing environments, an orchestration control unit, trained to coordinate the control of identity and access security functions across multiple cloud environments, a policy linking unit, trained to assign safety rules to container-related execution states, and a security enforcement unit trained to execute identity-related security measures within the respective computing environment, the system coordinates identity security functions across environments without imposing a fixed prioritization of individual cloud environments.
Owner:GAHLOT RAKESH EDISON +3

Method for verifying the setting of predefined safety functions of a field device in process and automation technology

A method for verifying the setting of predefined safety functions (SF1, ..., SFn) of a field device for process and automation technology, wherein the predefined safety functions (SF1, ..., SFn) relate in particular to access to at least one function of the field device by an unauthorized person, wherein the method provides the following steps: - Determining a security level required at the measuring point and / or at the field device, wherein the determined security level defines the target setting of the predefined safety functions (SF1, ..., SFn) of the field device (1), - Identifying a user by means of an authentication protocol (2), - Starting a query about the actual setting of the safety functions (SF1, ..., SFn) of the field device specified at the measuring point by the user (3), - Comparing the actual setting of the predefined safety functions (SF1, ..., SFn) of the field device with the target setting of the specified safety functions (SF1, ..., SFn) defined by the specified safety level (4),- Issuance of an electronic report to the user regarding a conformity or deviation between the actual setting and the target setting of the specified safety functions (SF1, ..., SFn) of the field device (5),- in the case of conformity between the actual setting and the target setting of the specified safety functions (SF1, ..., SFn) of the field device, the following step is provided:◯ Storage of the electronic report (6), or- in the case of deviation between the actual setting and the target setting of the specified safety functions (SF1, ..., SFn) of the field device, the following steps are provided:◯ Proposal of at least one measure to adjust the actual setting of at least one specified safety function (SF1, ..., SFn) of the field device to the target setting (7), whereby at least one measure is shown to the user,◯ Implementation of the at least one proposed measure to adapt the actual setting to the target setting of the specified safety functions (SF1, ..., SFn) of the field device by the user (8),◯ Repetition of the query about the actual setting of the specified safety functions (SF1, ..., SFn) of the field device by the user (3).
Owner:ENDRESS & HAUSER GMBH & CO KG

Electronic device, method, and non-transitory storage medium for changing screen displayed on display

The present document relates to an electronic device, a method, and a non-transitory storage medium for changing a screen displayed on a display. According to one embodiment, the electronic device may comprise: a display; at least one processor including a processing circuit; and a memory for storing instructions. The instructions, when executed individually or collectively by the at least one processor, may instruct the electronic device to: display, on the display, a screen including a first image indicating first information; on the basis of performing a security function for the screen, identify information related to at least one pixel of an inner part or an outer part with respect to a boundary between an object indicating the first information included in the first image and a background excluding the object; on the basis of the information related to the pixel, obtain a second image in which at least one of the inner part or the outer part is adjusted; obtain a third image in which the background included in the first image is blurred; obtain a fourth image in which the first information is processed so as not to be visually identified at a specified distance or more, by using the second image and the third image; and replace the first image displayed on the screen with the fourth image. Various other embodiments are also possible.
Owner:SAMSUNG ELECTRONICS CO LTD

Method for reprogram with enhanced security

ActiveUS12699776B2PasswordCryptogram
A method performed by an electronic control unit (ECU) for reprogramming with enhanced security. The method includes checking whether a cyber security function of a ROM of the ECU is applied while the ECU is running in a NORMAL area, receiving, when it is confirmed that the cyber security function of the ROM of the ECU is applied, a first backdoor password for the cyber security function of the ROM of the ECU, and performing, when the received first backdoor password is the same as a second backdoor password included in program data stored in the ROM of the ECU, reprogramming of the ECU without additional procedures related to the cyber security function.
Owner:HYUNDAI AUTOEVER

Diagnosis interface authentication method and device, electronic equipment, storage medium and vehicle

The invention discloses a diagnosis interface authentication method and device, electronic equipment, a storage medium and a vehicle, and relates to the technical field of vehicle-mounted safety certification, and the method comprises the steps: detecting a message receiving instruction, and determining a controller receiving the message receiving instruction; responding to the condition that the controller performs diagnosis through an OBD diagnosis interface, and obtaining a controller type determined for the controller in advance; and determining a security authentication mode corresponding to the controller type, and performing authentication with a vehicle-mounted gateway based on the security authentication mode. According to the method, the controller in the vehicle can be graded, more safety functions are realized by the controller with high computing power and sufficient resources, the safety development difficulty of the controller with low computing power is liberated, the unnecessary cost is reduced, the authentication times of a diagnostic instrument through an OBD (On-Board Diagnostic) diagnosis interface are reduced, and the diagnosis efficiency is improved.
Owner:FAW CAR CO LTD

Network management method, system and device and storage medium

The invention provides a network management method, system and device and a storage medium, the method is applied to a cloud service device, and the method comprises the following steps: receiving a service subscription request of a target device, the target device comprising a device for realizing a security function; and determining at least one target security service in the plurality of security services based on the service subscription request, so as to manage an access request of an electronic device in communication connection with the target device based on the target security service, the target security service being used for realizing a security function different from that of the target device.
Owner:SANGFOR TECH INC

User Interface for Health Applications

Provides a computer user interface for managing and / or presenting health data. [Solution] An exemplary user interface for managing health and safety functions on an electronic device is described, and an exemplary user interface for managing the setup of health functions on an electronic device is described. An exemplary user interface for managing background health measurements on an electronic device is described, and an exemplary user interface for managing biometric measurements performed using an electronic device is described. An exemplary user interface for providing the results of health information captured on an electronic device is described, and an exemplary user interface for managing background health measurements on an electronic device is described.
Owner:APPLE INC

Non-intrusive signature encryption video playing method based on secure decoding library

The embodiment of the invention discloses a non-intrusive signature encryption video playing method based on a secure decoding library. A specific embodiment of the method comprises the steps of configuring a decoding library supporting a security function in response to a situation that a target video monitoring platform does not support a preset protocol; initializing a decoding library, and transmitting the security gateway address and the target front-end equipment identifier to the decoding library; sending a video playing request to the target video monitoring platform through a transmission protocol of the target video monitoring platform, and receiving a signature encrypted video code stream from the target video monitoring platform; transmitting the signature encrypted video code stream to a decoding library; and based on the decoding library, carrying out adaptive security processing on the signature encrypted video code stream to obtain decoded video data, receiving the decoded video data from the decoding library, and playing the decoded video data. According to the embodiment, for a video monitoring platform of a non-GB35114 standard, the technical effects of reducing video playing delay and gateway load and meeting data security requirements are achieved.
Owner:北京中星天视科技有限公司 +1

MEMS relay with safety function

A micromechanical electrically actuable switch. The switch has a first relay with a first operating contact, and a second relay with a second operating contact. The first operating contact and the second operating contact are arranged in series in a common load path. The switch further includes a detection device for detecting a switching state of the first operating contact, and a control circuit for registering the switching state of the first operating contact and for switching on the electrically actuable switch. The control circuit is configured, upon a switch-on signal, to switch on the first relay and the second relay in a first case, in which the switching state of the first operating contact is “open”, and to not switch on at least the second relay in a second case, in which the switching state of the first operating contact is “closed”.
Owner:ROBERT BOSCH GMBH

Safety function block active defense method and system for safety instrument system

PendingCN121596840AProgramme total factory controlSafety instrumented systemReverse analysis
The invention provides a safety function block active defense method and system for a safety instrument system. The method comprises the following steps: before executing a core algorithm, performing pointer security check and numerical field check on input data of a security function block; if the check is passed, entering a pre-operation stage, and monitoring an operation risk in real time through a preset check point by utilizing a reverse analysis pre-operation algorithm or a soft floating point pre-operation algorithm on the premise of not executing an actual instruction which possibly causes hardware exception; and executing a deterministic output strategy according to a pre-operation result, and outputting a unified hierarchical state code (ERR) through a special state pin. The method has the advantages of endogenous safety, fault behavior determination, high diagnosis precision, high configuration efficiency and the like, controller shutdown caused by data exception can be effectively avoided, and the robustness of an industrial control system is improved.
Owner:BEIJING CONSEN AUTOMATION CONTROL

Security function management within a multi-port memory system

Methods, systems, and devices for security function management within a multi-port memory system are described. A memory system may include multiple ports each coupled with one or more host systems. The memory system may receive a namespace configuration indicating an allocation of one or more logical block addresses (LBAs) to one or more of the ports. The memory system may further receive one or more requests for access to one or more LBA ranges, and may perform an authorization procedure to authorize a single entity to provision and unlock corresponding LBA ranges. In some examples, LBA ranges may be locked by default on bootup of the memory system. In some cases, host systems may request a management controller to coordinate authorization, or may request authorization from a memory system directly using one or more credentials or identifiers. Further, a management port may be indicated via one or more commands.
Owner:MICRON TECHNOLOGY INC

Electronic device, method and processor for executing hypervisor

This electronic device may comprise a memory, and a processor including processing circuit. The processor can use an image file for a kernel at a first privilege, a hypervisor at a second privilege higher than the first privilege, and a security function at a third privilege higher than the second privilege. The processor can execute, in response to the execution of a bootloader including address information for the hypervisor, an instruction for requesting the security function to load the address information; use, on the basis of using the security function to verify the reliability of the address information, the security function to load the address information in a security area within the memory; use, in response to the execution of the kernel at the first privilege, the security function to load execution information for the hypervisor in the image file into the secure area; and execute the hypervisor.
Owner:SAMSUNG ELECTRONICS CO LTD

Network-bound data security techniques

Techniques are described for securing data stored on a non-volatile storage medium from unauthorized access using improved network-bound data security techniques. The data is secured using network-bound security techniques without the entities involved in the processing (e.g., clients and servers) having to exchange any client-specific or server-specific keys, secrets, or other secret data with each other. The techniques disclosed herein provide the network-bound data security functionality using a sequence of Message Authentication Codes (macs) generated using Hash-based Message Authentication Code (HMAC) generation techniques.
Owner:ORACLE INT CORP