Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

280 results about "Security function" patented technology

Security functions are the hardware, software, and/or firmware of the information system responsible for enforcing the system security policy and supporting the isolation of code and data on which the protection is based.

Trusted management and control network platform construction method and device, electronic equipment and storage medium

The invention belongs to the field of network security, and relates to a trusted management and control network platform construction method and device, electronic equipment and a storage medium, the method comprises the following steps: constructing a basic security architecture and a trusted base, the basic security architecture being used for providing a unified root of trust and a management core for collaborative operation of upper security components; based on the basic security architecture and the trusted base, implementing multi-dimensional trusted verification and dynamic access control; an intelligent boundary protection and depth detection system is deployed and is used for constructing an intelligent, three-dimensional and self-adaptive security defense line at the boundary of each region of the network, and various known and unknown threats can be identified and blocked; constructing a unified secure communication tunnel and a cross-domain transmission guarantee; defining and realizing a standardized security function interface and a collaboration protocol; and a continuous trust evaluation and automatic operation management and control closed loop is established. The overall security is enhanced, the secure transmission of data is ensured, the compatibility and collaboration of the system are improved, and the security operation intelligence is realized.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Security service distribution

This disclosure describes techniques for distributing security service by performing security policy-based routing among network devices. The techniques include determining a security function to be applied to a packet of a data traffic flow. The security function may be determined based on a security policy and an intended destination of the packet. The techniques may also include determining whether a network device is capable of performing the security function. A route for the packet to the destination may be determined based on whether the network device is capable of performing the security function. As such, distributing security service techniques may improve efficiency in data traffic routing, and may reduce cost and / or prevent redundancy in security service application.
Owner:CISCO TECHNOLOGY INC

Filtered data lake for enterprise security

A data lake for enterprise security is created from an asynchronous stream of security events by deduplicating objects and creating metadata related to downstream security functions. Deduplication of objects may be efficiently performed with a bloom filter as objects are ingested into the data lake. The objects may also be augmented with metadata arranged in schemas to facilitate monitoring and use within the data lake.
Owner:SOPHOS LTD

Multi-chip secure and programmable systems and methods

Various techniques are provided to implement multi-chip secure and programmable systems and methods. In one example, a multi-chip module system for providing an integrated programmable logic functionality and security functionality. The multi-chip module system includes a first die including a programmable logic device (PLD) configured to provide at least a portion of the programmable logic functionality. The multi-chip system further includes a second die including a security engine configured to perform at least a portion of the security functionality. The security engine is further configured to receive, from the first die, data associated with a first and second configuration image; perform a read operation on a memory for the second configuration image based on the data; and authenticate the second configuration image. The multi-chip system further includes a configuration engine configured to program the PLD according to the first configuration image. Related devices and methods are provided.
Owner:LATTICE SEMICON CORP

Property asset digital operation and intelligent security linkage cooperative processing system and implementation method

The invention discloses a property asset digital operation and intelligent security linkage cooperative processing system and an implementation method, and relates to the technical field of Internet of Things, and the system comprises a protocol adaptive gateway layer which solves the problem of compatibility of multi-manufacturer equipment, and outputs a standardized data stream based on a dynamic protocol sniffing and fingerprint feature library, SDK-free access control, fire protection, monitoring and IoT equipment; the method comprises the following steps: constructing a millimeter-level precision three-dimensional space model by a digital twinborn middle table layer, fusing a security event and operation data, and ensuring that the operation is compliant and audible through blood relationship tracking; the intelligent decision execution layer combines a rule engine and machine learning to generate a linkage instruction, drives a work order to be automatically distributed and positions an equipment fault responsible party; and the edge cooperative computing node locally realizes video millisecond-level analysis, and starts localized linkage according to an emergency plan when the network is disconnected, so as to ensure that the core security function is not interrupted.
Owner:BEIJING TIANRUI CHUANGXIN TECHNOLOGY CO LTD

Storage device including replay protected memory block (RPMB) host device accessing the RPMB, electronic device including storage device and host device, and method of operating the same

Storage devices, host devices and electronic devices are disclosed. In an embodiment of the disclosed technology, an electronic device providing an improved security function may include a storage device including a replay protected memory block (RPMB), and a host device configured to provide a command protocol information unit (PIU) instructing the storage device to access the RPMB. The command PIU may include a basic header segment including a total extra header segment length field having a value other than 0 and an extra header segment including a host RPMB message.
Owner:SK HYNIX INC

Clean room

Embodiments of the present disclosure may provide a data clean room allowing secure data analysis across multiple accounts, without the use of third parties. Each account may be associated with a different company or party. The data clean room may provide security functions to safeguard sensitive information. For example, the data clean room may restrict access to data in other accounts. The data clean room may also restrict which data may be used in the analysis and may restrict the output. The overlap data may be anonymized to prevent sensitive information from being revealed.
Owner:VIDEOAMP INC

Autonomous operation vehicle supervision terminal identity authentication method

The invention discloses an identity authentication method for a supervision terminal of an automatic driving commercial vehicle, which belongs to the field of vehicle supervision, and comprises the steps of deploying a unified password service platform, and calling various password services by a supervision platform so as to support various safety functions. In addition, by supervising terminal device registration, generating a device unified identifier and interacting with a unified password service platform, generation and distribution of a device initial key are realized. According to the method, an equipment SM9 private key acquisition process is introduced, and the secure acquisition of the equipment private key is realized through the generation of an SM2 public and private key pair. Meanwhile, a specific supervision terminal authentication process is provided, and the identity authentication security of the terminal equipment and the unified password service platform is guaranteed through a challenge-response mode. Moreover, the authentication entity relationship and the key updating mechanism are described in detail, and an all-dimensional and multi-level authentication system is constructed.
Owner:ZHONGLU HI TECH TRAFFIC TECH GRP

Self-contained biometric device, system, and method for secure digital transactions, identity verification, and multi-currency asset management

A self-contained biometric device, method, and system for secure digital transactions is provided. The device comprises a housing that may be a subdermal implant, dermally-applied biometric tattoo, ergonomic external wearable, or smart card. The housing maintains consistent secure functionality during offline and online operation modes and includes a biometric verification module that captures a biometric input of a user and performs user authentication entirely within the device. A hardware-isolated storage module physically isolated from external networks stores cryptographic keys, credentials, and biometric templates. The device permits access to the cryptographic keys and credentials only upon successful user authentication. A transaction processing module resident inside the hardware-isolated storage module executes digital asset transactions entirely within the device in offline mode. This self-contained architecture enables secure, autonomous operation without reliance on external networks or computation.
Owner:OMNIUS CORP

Security cooperation system and method in hybrid cloud environment

The invention relates to the field of network security, and particularly provides a security cooperation system and method in a hybrid cloud environment. The system comprises a unified security management module, a security solution cooperation module and a security function module. The unified security management module analyzes a self-healing algorithm through a policy graph, carries out graph modeling on a multi-cloud security policy, automatically identifies policy conflicts and drifts through graph difference analysis, and realizes continuous consistency and self-healing of a cross-cloud policy. And the security solution cooperation module is embedded into a reinforcement learning agent, dynamically decides an optimal deployment scheme of security resources according to a reward function by sensing a threat situation, a resource utilization rate and response delay, and realizes intelligent self-adaptive arrangement of protection resources. The security function module is used for micro-servitizing and containerizing security capability based on a cloud native technology, transparent injection is realized through a service grid, an automatic compliance repair and verification mechanism is built in, and a compliance closed loop for detection, repair and verification is formed. And the management efficiency and the protection accuracy of the security policy are improved.
Owner:STATE GRID SICHUAN ELECTRIC POWER CORP ELECTRIC POWER RES INST

Electronic device including a storage device and a host device and methods of operation

A storage device for providing a security function may include: a nonvolatile memory device including a Replay Protected Memory Block (RPMB); and a memory controller configured for receiving, from an external host, a command UFS Protocol Information Unit (UPIU) including a host RPMB message, and storing data in the RPMB according to authentication performed using the host RPMB message. The command UPIU may include a basic header segment commonly included in UPIUs transmitted / received between the external host and the memory controller, and the basic header segment may include a data segment length field as information indicating that the host RPMB message has been included in the command UPIU.
Owner:SK HYNIX INC

Efficiently Scalable Assurance Assessment for Hard 3PIP

Solutions for efficiently scalable assurance assessments for hard third party intellectual property (3PIP) are disclosed. Examples parse a data file (e.g., a netlist, GDSII, or OASIS) identifying components and connections for a functional component of an integrated circuit (e.g., ASIC, FPGA) and generate a graph having nodes and edges corresponding to the components and connections. Subgraph matching identifies portions of the graph that match subgraphs in a library of known secure functionality. Unmatched portions are then further analyzed for security, such as by extracting a schematic, performing a Boolean analysis, or performing a circuit simulation. When all portions of the data file are found to be secure, the data file is flagged and the integrated circuit may be fabricated or programmed.
Owner:TENET 3 LLC

Authorized access to security event data

Various aspects of the present disclosure relate to authorized access to security event data. An apparatus, such as a network equipment (NE) that implements a first network function (NF) (e.g., a network repository function (NRF)), receives a request from a second NF (e.g., an operator security function (OSF)) for a token to access security event data from a third NF (e.g., an NF service producer). The first NF generates the token using a profile of the second NF. The first NF transmits the token to the second NF. A fourth NF (e.g., a data collection function) can request a second token from the first NF to access the security event data for the second NF. The third NF can transmit the security event data to the second NF via the fourth NF or directly. This enables secure and authorized access to security event data in wireless communication networks.
Owner:LENOVO (SINGAPORE) PTE LTD

Method and electronic device for configuring network lock function of electronic device

An electronic device may include: an application processor, a communication processor, and a security subsystem for processing a security function related to the application processor or the communication processor. The security subsystem may decrypt, based on reception of a request for decrypting a nonce value from the communication processor, the nonce value and transmit the decrypted nonce value to the communication processor, and may generate a signature using the nonce value and network lock data based on reception of a request for network lock signature from the communication processor and transmit the generated signature to the communication processor. The communication processor may receive a signature value generated from the security subsystem, compare a signature value pre-stored in the application processor with a signature value received from the security subsystem, and determine whether to restrict use of the electronic device based on whether the signature value pre-stored in the application processor and the signature value received from the security subsystem are matched to each other.
Owner:SAMSUNG ELECTRONICS CO LTD

Network security gateway onboard an aircraft to connect low and high trust domains of an avionics computing infrastructure

The gateway, which connects a low-trust domain (12) and a high-trust domain (13) of an avionics computing infrastructure, provides a plurality of security functions, each function being performed by a data processing node. The gateway comprises, connected in series along a filtering chain of a data flow received from the low-trust domain: a firewall data processing node (4); a protocol break data processing node (5); a master data processing node (1) and an inverse protocol break data processing node (6), the gateway further including a security data processing node (2) connected to each of the data processing nodes of the filtering chain, the different data processing nodes being physically segregated.
Owner:THALES SA

Systems and methods for hierarchical deep packet inspection for scalable network monitoring and cyber security functions

A system and method for hierarchical network monitoring functions are disclosed. An order of execution for layer functions of a network architecture is determined. The layer functions may be distributed across multiple layers. The layers may include a sensor layer, a federated application layer, and a data lake layer. A machine learning model may be executed at a first layer. The first layer may be the sensor layer.
Owner:NETSCOUT SYSTEMS INC

Communication method and apparatus

A communication method is described where a first security module executes a first security service or managing the first security module based on a first request message received from a requester, wherein the first security service is usable to call a security capability, the requester comprises a first node, a second node, or a second security module, the first security module serves the first node, and the second security module serves the second node. The first security module sends a first feedback message to the requester, wherein the first feedback message is usable to feed back, to the requester, an execution result of the first security service or a management result of the first security module.
Owner:HUAWEI TECH CO LTD

Vehicle unlocking method and related device

The invention relates to a vehicle unlocking method and a related device, and relates to the technical field of information security, the vehicle unlocking method is applied to terminal equipment, the terminal equipment comprises a security chip, and a storage unit of the security chip is used for storing target identity information of a legal user. Obtaining to-be-confirmed identity information of the user; obtaining an identity authentication result according to the to-be-confirmed identity information and target identity information stored in a storage unit; and at least according to the identity authentication result, sending an unlocking signal to the target vehicle, so that the target vehicle performs unlocking processing on the target vehicle according to the unlocking signal. When the vehicle is unlocked, the user identity is authenticated through the information stored in the security chip, and the target vehicle can be safely unlocked by using the tamper-proof security function of the security chip.
Owner:BEIJING XIAOMI MOBILE SOFTWARE CO LTD

Safety device for flow rate measuring device and flow rate measuring device

A safety device (10A) comprises: internal communication units (12a, 12b) that communicate with a flow rate measuring device; a safety determination processing unit (11) that determines whether to execute a safety function in the flow rate measuring device using output information of the flow rate measuring device obtained through communication of the internal communication units (12a, 12b); and a safety determination value setting unit (13) that sets and stores a safety determination value to be used for determining whether to execute the safety function by the safety determination processing unit (11). The safety device (10A) may be provided with a flow rate integration unit that calculates, from fluid flow rate information included in the output information, an integrated consumption amount of the fluid, or may be configured as a unit mountable to the flow rate measuring device. This makes it possible to easily implement a safety function in a flow rate measuring device, for example, even if the flow rate measuring device does not have a safety function.
Owner:PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD

SIL2 security level vehicle-mounted signal system and control method thereof

The invention discloses an SIL2 security level vehicle-mounted signal system and a control method thereof. The system comprises a security calculation core, a CLU3 module and an input and output VDU module. The safety calculation core comprises a CLU1 module and a CLU2 module, realizes a system safety function, and performs dual-channel data comparison and internal self-inspection; the VDU executes input acquisition and output control, a safe output channel of the VDU enters and maintains a non-output state when an internal fault is detected, and fault information is reported; the CLU3 is independently responsible for a non-safety function; wherein the security calculation core performs fault diagnosis and security level division by integrating self-inspection, dual-channel comparison and VDU report information, and generates alarm information; and the CLU3 outputs an alarm signal corresponding to the fault level to an external system or a driver according to the fault level, and final safety control is completed by the external system or the driver. Compared with the prior art, the system complexity and cost are effectively reduced on the premise of ensuring the SIL2 security level through fault grading, alarming and man-machine cooperative control mechanisms.
Owner:CASCO SIGNAL LTD

Exchange of flow metadata between network and security services' security functions

Techniques are disclosed that provide for exchange of flow metadata between network and security services' security functions. In some embodiments, a system / process / computer program product for providing for exchange of flow metadata between network and security services' security functions includes receiving, at a network gateway of a security service, a flow from a software-defined wide-area network (SD-WAN) device, inspecting the flow to determine meta-information associated with the flow, and communicating the meta-information associated with the flow to the SD-WAN device.
Owner:PALO ALTO NETWORKS INC

Communication method, communication system, security control device, terminal device, and program

To provide a communication system that implements a security function required by a communication terminal and enables secure communication, even when the security function required by the communication terminal cannot be provided at the current location of the communication terminal.SOLUTION: In a communication system 1000, whether communication at a security level required by a terminal device 1 can be performed can be determined by a security control device 4 performing a security function matching process. In the communication system 1000, if it is determined that communication at the security level required by the terminal device 1 cannot be performed, the terminal device 1 executes a security function activation process and, for example, establishes a secure session with a security communication device installed in a core network, and secure communication can be implemented through the secure session.SELECTED DRAWING: Figure 1
Owner:ATR ADVANCED TELECOMM RES INST INT

System for orchestrated management of identity security functions in container-based multi-cloud environments

System for the orchestrated management of identity security functions in container-based multi-cloud environments, comprehensive an identity data capture unit, trained to capture identity-related security parameters from multiple distributed, container-based computing environments, an orchestration control unit, trained to coordinate the control of identity and access security functions across multiple cloud environments, a policy linking unit, trained to assign safety rules to container-related execution states, and a security enforcement unit trained to execute identity-related security measures within the respective computing environment, the system coordinates identity security functions across environments without imposing a fixed prioritization of individual cloud environments.
Owner:GAHLOT RAKESH EDISON +3

Method for verifying the setting of predefined safety functions of a field device in process and automation technology

A method for verifying the setting of predefined safety functions (SF1, ..., SFn) of a field device for process and automation technology, wherein the predefined safety functions (SF1, ..., SFn) relate in particular to access to at least one function of the field device by an unauthorized person, wherein the method provides the following steps: - Determining a security level required at the measuring point and / or at the field device, wherein the determined security level defines the target setting of the predefined safety functions (SF1, ..., SFn) of the field device (1), - Identifying a user by means of an authentication protocol (2), - Starting a query about the actual setting of the safety functions (SF1, ..., SFn) of the field device specified at the measuring point by the user (3), - Comparing the actual setting of the predefined safety functions (SF1, ..., SFn) of the field device with the target setting of the specified safety functions (SF1, ..., SFn) defined by the specified safety level (4),- Issuance of an electronic report to the user regarding a conformity or deviation between the actual setting and the target setting of the specified safety functions (SF1, ..., SFn) of the field device (5),- in the case of conformity between the actual setting and the target setting of the specified safety functions (SF1, ..., SFn) of the field device, the following step is provided:◯ Storage of the electronic report (6), or- in the case of deviation between the actual setting and the target setting of the specified safety functions (SF1, ..., SFn) of the field device, the following steps are provided:◯ Proposal of at least one measure to adjust the actual setting of at least one specified safety function (SF1, ..., SFn) of the field device to the target setting (7), whereby at least one measure is shown to the user,◯ Implementation of the at least one proposed measure to adapt the actual setting to the target setting of the specified safety functions (SF1, ..., SFn) of the field device by the user (8),◯ Repetition of the query about the actual setting of the specified safety functions (SF1, ..., SFn) of the field device by the user (3).
Owner:ENDRESS & HAUSER GMBH & CO KG

Electronic device, method, and non-transitory storage medium for changing screen displayed on display

The present document relates to an electronic device, a method, and a non-transitory storage medium for changing a screen displayed on a display. According to one embodiment, the electronic device may comprise: a display; at least one processor including a processing circuit; and a memory for storing instructions. The instructions, when executed individually or collectively by the at least one processor, may instruct the electronic device to: display, on the display, a screen including a first image indicating first information; on the basis of performing a security function for the screen, identify information related to at least one pixel of an inner part or an outer part with respect to a boundary between an object indicating the first information included in the first image and a background excluding the object; on the basis of the information related to the pixel, obtain a second image in which at least one of the inner part or the outer part is adjusted; obtain a third image in which the background included in the first image is blurred; obtain a fourth image in which the first information is processed so as not to be visually identified at a specified distance or more, by using the second image and the third image; and replace the first image displayed on the screen with the fourth image. Various other embodiments are also possible.
Owner:SAMSUNG ELECTRONICS CO LTD

Method for reprogram with enhanced security

ActiveUS12699776B2PasswordCryptogram
A method performed by an electronic control unit (ECU) for reprogramming with enhanced security. The method includes checking whether a cyber security function of a ROM of the ECU is applied while the ECU is running in a NORMAL area, receiving, when it is confirmed that the cyber security function of the ROM of the ECU is applied, a first backdoor password for the cyber security function of the ROM of the ECU, and performing, when the received first backdoor password is the same as a second backdoor password included in program data stored in the ROM of the ECU, reprogramming of the ECU without additional procedures related to the cyber security function.
Owner:HYUNDAI AUTOEVER