Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

48 results about "Security pattern" patented technology

Security patterns can be applied to achieve goals in the area of security. All of the classical design patterns have different instantiations to fulfill some information security goal: such as confidentiality, integrity, and availability. Additionally, one can create a new design pattern to specifically achieve some security goal.

Sidecar Security Pattern for Agent Communications

Systems and methods for securing agent communications in a multi-agent system including deploying an agent to communicate with external servers, instantiating a sidecar security service in communication with the agent and including at least one of a guardrails service, a security layer, an encryption module, and an integrity checker configured to validate resources tools using hash-based verification mechanisms. Communications including messages between the primary and the external servers are intercepted by the sidecar security service, which then performs at least one of filtering the one or more messages by the guardrails service, authenticating one or more server connections by the security layer, encrypting one or more outbound requests by the encryption module, or verifying an integrity of resources and tool definitions by the integrity checker.
Owner:MADISETTI VIJAY

Network security analysis system based on AI algorithm

The invention belongs to the technical field of network security, and particularly relates to a network security analysis system based on an AI algorithm. Comprising a data acquisition and preprocessing module, an abnormal behavior characteristic index construction module, a safety mode evolution law index construction module and a threat risk comprehensive evaluation module. According to the system, multi-source heterogeneous data such as network flow, equipment logs, threat intelligence and user behaviors are analyzed through deep learning, a graph neural network and an attention mechanism, potential attack time periods are recognized in real time, the threat evolution trend is predicted, and dynamic early warning is achieved by fusing multi-dimensional risk factors. Compared with a traditional detection mode based on rules, the method has higher unknown threat detection capacity, interpretability and real-time performance, the network security protection level can be greatly improved, and the method is suitable for various complex network environments.
Owner:SHANDONG INTERNET MEDIA GRP CO LTD

Sidecar security pattern for agent communications

Systems and methods for securing agent communications in a multi-agent system including deploying an agent to communicate with external servers, instantiating a sidecar security service in communication with the agent and including at least one of a guardrails service, a security layer, an encryption module, and an integrity checker configured to validate resources tools using hash-based verification mechanisms. Communications including messages between the primary and the external servers are intercepted by the sidecar security service, which then performs at least one of filtering the one or more messages by the guardrails service, authenticating one or more server connections by the security layer, encrypting one or more outbound requests by the encryption module, or verifying an integrity of resources and tool definitions by the integrity checker.
Owner:MADISETTI VIJAY

High-reliability on-orbit reconstruction method for large satellite-borne software

The invention provides a high-reliability on-orbit reconstruction method for large satellite-borne software, which is characterized in that a BootLoader program solidified on a PROM (programmable read-only memory) is designed with a function of reconstructing any software at a low speed by using a bus, so that the BootLoader program serves as the most fundamental guarantee for the reliability of a reconstruction scheme; a high-speed self-reconfiguration function is designed for the satellite-borne software, so that the high-speed channel self-reconfiguration software can be utilized after the satellite-borne software is started in a normal process; security mode software which is small in size and can exist on an MRAM in a triple modular redundancy mode is constructed, and the main function of the security mode software is to complete high-speed reconstruction of satellite-borne software. And when self-reconfiguration of the satellite-borne software fails and the satellite-borne software cannot be normally started, a special instruction is sent to the BootLoader to start the security mode software, so that high-speed reconfiguration of the satellite-borne software can be continued. The whole satellite-borne software can be reconstructed in a measurement and control arc section through a high-speed channel. Compared with a mode that a comprehensive electronic system spends several measurement and control arc segments to collect data and then distributes the data at a low speed through a bus channel, the method has the advantages that the required time is greatly shortened, and the reliability is high.
Owner:BEIJING RES INST OF TELEMETRY

Energy insights

A method is disclosed. The method includes monitoring, by a security system, a security pattern of a building based on security data corresponding to the building. The method further includes monitoring, by the security system, an energy pattern of the building based on energy information corresponding to the building. The method further includes identifying, based on the security pattern and the energy pattern, a potential reduction in the energy pattern resulting from a change in at least one of the security pattern or the energy pattern. The method further includes identifying an insight comprising an action to at least partially achieve the potential reduction in the energy pattern. The method further includes transmitting the insight to a device in communication with the security system.
Owner:VIVINT LLC

Apparatus, method, and computer program

The present disclosure relates to an apparatus configured to perform: receiving, from a base station, a first message comprising: an authentication and key agreement challenge packet, an access stratum security mode command packet, and a non-access stratum security mode command packet; performing successful verification of the authentication and key agreement challenge packet, the access stratum security mode command packet, and the non-access stratum security mode command packet; and transmitting, to the base station, a second message comprising: an authentication and key agreement response packet, an access stratum security mode command complete packet, and a non-access stratum security mode command complete packet.
Owner:NOKIA TECHNOLOGIES OY

An artificial intelligence agent hardware security mode switching apparatus

PendingCN122365601AMask ROMData center
This invention discloses a hardware-triggered security mode switching device and method for artificial intelligence agents, belonging to the fields of G06F21 / 71 and G11C17 / 14. Addressing the shortcomings of existing technologies that rely on software / main control chips, this invention employs an independent hardware module design, including a non-electrically erasable storage structure (such as mask ROM, OTP) for storing a security rule set, a hardware instruction monitoring unit for physically intercepting and parsing instruction streams, a hardware anomaly detection unit for comparing security rules, a hardware security mode triggering unit for generating trigger signals, and a physically isolated security mode execution interface for transmitting signals. The device is completely independent of the agent's main control chip and any externally loadable and modifiable software, ensuring that security mode switching can still be performed even if the main control chip fails or is attacked. This solution effectively prevents the execution of harmful commands sent from data centers, provides hardware-level tamper-proof security protection, 100% resists malicious instruction tampering, and significantly improves the security of artificial intelligence agents.
Owner:SHENZHEN BAIMAXUN NETWORK TECHNOLOGY CO LTD

An ecological security pattern intelligent simulation optimization system based on reinforcement learning

The application relates to the technical field of ecological safety optimization, and discloses an ecological safety pattern intelligent simulation optimization system based on reinforcement learning. An experience pool forming module of the system divides historical optimization strategies into multiple experience layers to form a multilayer experience pool based on the gap between ecological indexes and strategy confidence of the historical optimization strategies. A strategy determining module determines intelligent optimization strategies at each stage based on a set ecological safety target state, and screens the multilayer experience pool to obtain experience optimization strategies in combination with strategy confidence and target matching degree. A strategy adjusting module adjusts the two strategies by using a dynamic mechanism to cope with real-time ecological changes, and determines a target optimization strategy. A simulation optimization module simulates and optimizes the ecological safety pattern based on the target optimization strategy. A state acquisition module acquires an actual state. An experience pool updating module updates the content of the experience layers based on the difference factors between the actual state and the target state, and perfects the multilayer experience pool data. The system can improve the dynamics and adaptability of ecological safety pattern optimization.
Owner:INST OF GEOGRAPHICAL SCI & NATURAL RESOURCE RES CAS

Banking interface

An example embodiment includes one or more processors configured to execute computer executable instructions stored in a memory to determine a device property of a mobile device including a location of the mobile device using a geographic positioning system detection component, select a security mode for the mobile device based on a device property where a high security mode is selected when the mobile device is located in a first location, and a low security mode is selected when the mobile device is located in a second location where the second location is specified as part of a preference associated with a user account associated with the mobile device, and selectively provide a visualization on a user interface that masks a portion of the visualization in the high security mode and does not mask the portion of the visualization in the low security mode.
Owner:WELLS FARGO BANK NA

Method for additively printing on a medium using fluorescent invisible inks

The invention relates to a method for printing an image on a security document, said method using invisible inks that are fluorescent and visible under ultraviolet radiation, characterised in that it comprises a step of additive colour synthesis, consisting in: - decomposing a visible digital image into three (red, green and blue (R, G, B)) digital image masks (13) such that the superposition of the three masks (13) corresponds to the base image; - applying to each R, G, B digital colour mask (13) computer processing (14) consisting in introducing security patterns into each of the R, G, B digital masks; - printing on a (paper, polycarbonate) physical medium, on top of one another, these three red, green and blue masks provided with their security patterns, using invisible luminescent inks so as to form, on the medium, an invisible image () containing the security patterns () previously introduced into the three RGB digital masks.
Owner:IMPRIMERIE NAT

Fraudulent image detector and a computer-implemented method of detecting a fraudulent image

A fraudulent image detector including a first segmenter configured to compute first probability data from an image showing personal identifiable information of an individual, the first probability data indicating, for each pixel of the image, a probability that the pixel shows a security pattern, a second segmenter configured to compute second probability data from the image, the second probability data indicating, for each pixel of the image, a probability that the pixel is part of a foreground region showing the personal identifiable information or part of a backdrop region showing no personal identifiable information, and a classifier configured to compute score data from the first probability data and the second probability data.
Owner:IDEMIA PUBLIC SECURITY FRANCE

Electronic device and method for supporting burn-in compensation in security mode, and recording medium

An embodiment of the present disclosure provides an electronic device for compensating for burn-in in a display, an operating method thereof, and a recording medium. The electronic device can: generate a de-burn-in layer for a normal screen in a normal mode; identify an event of switching from the normal mode to a security mode; switch from the normal mode to the security mode in response to the switching event; acquire the de-burn-in layer in the security mode; and display, through at least a part of a display, a security screen to which the de-burn-in layer is applied in the security mode. Various embodiments are possible.
Owner:SAMSUNG ELECTRONICS CO LTD

Anti-counterfeiting pattern generation method, device and readable storage medium with arbitrary image distance

The application provides a security pattern generation method with an arbitrary image distance, comprising the following steps: S1, designing pattern data processing; S2, calculating a basic imaging microstructure; S3, obtaining an axis core coordinate according to an array rule; S4, calculating an anisotropic imaging microstructure; and S5, cyclically generating the anisotropic imaging microstructure array according to an arrangement rule, so that the security pattern is realized when a point light source irradiates on the anisotropic imaging microstructure array. The security pattern film with the arbitrary image distance prepared by the method can realize the effects of floating in the air at an arbitrary distance and sinking at the bottom of the film, is not inferior to the double-layer micro-lens imaging technology, and is single-layer in structure, so that the method is not different from the preparation of the traditional holographic security film in process, and thus is easy to realize industrialization and mass production.
Owner:WUHAN MINGYU OPTOELECTRONICS TECHNOLOGY CO LTD

Configuration method, device and system of security mode and computer-readable storage medium

This disclosure discloses a configuration method, a configuration device, and a configuration system of security mode and a computer readable storage medium, relating to mobile communications technologies. The configuration method of security mode includes: acquiring an integrity protection algorithm, an encryption algorithm, an original key and an operator identification of a core network from the core network, wherein the original key is also sent to a user to start a security mode, the core network is a core network of a first operator or a second operator, and the first operator and the second operator use a same shared carrier in a co-construction and sharing base station; determining a key generation algorithm preset by an operator to which the user belongs according to the operator identification; generating an integrity protection key and an encryption key of the user according to the key generation algorithm and the original key; and sending a security mode command to a terminal of the user, wherein the security mode command comprises verification information encrypted by the integrity protection key of the user, the integrity protection algorithm and the encryption algorithm, and the terminal has the key generation algorithm preset by the operator to which the user belongs.
Owner:CHINA TELECOM CORP LTD

Secure tunnelling of a frame in an in-vehicle communication network

A controller may receive a set of messages provided by one or more network nodes included in an in-vehicle communication network. The controller may determine a security pattern associated with generating a tunnel frame including the set of messages. The controller may identify one or more messages from the set of messages based on the security pattern. The controller may compute a tunnel frame message authentication code (TMAC) based on one or more characteristics of the one or more messages. The controller may generate the tunnel frame, the tunnel frame including the TMAC and the set of messages.
Owner:INFINEON TECHNOLOGIES AG

Additive printing process for a substrate using invisible fluorescent inks

The invention relates to a method for printing an image on a security document, said method using invisible inks that are fluorescent and visible under ultraviolet light, characterized in that it comprises an additive color synthesis step, consisting of: decomposing a visible digital image into three digital image masks Red, Green, and Blue (R, G, B) such that the superposition of the three masks corresponds to the base image; applying to each digital color mask R, G, B a computer processing consisting of introducing security patterns into each of the digital masks R, G, B; printing these three Red, Green, and Blue masks one on top of the other on a physical substrate (paper, polycarbonate), using luminescent invisible inks so as to form on the substrate an invisible image containing the security patterns previously introduced into the three RGB digital masks. Figure for the Abstract: Figure 2
Owner:IMPRIMERIE NAT

Method, apparatus, and medium for transmitting security mode command

The present disclosure relates to a method and apparatus for transmitting a security mode command, an electronic device, a chip and a medium, wherein the method comprises: receiving a 5G system non-access layer (5GS NAS) message transmitted by a network device, wherein the 5GS NAS message carries a security mode command; the initiation purpose of the security mode command is distinguished in combination with the security header type of the 5GS NAS message; the security header type includes integrity protection and encryption; wherein part of the security mode command is integrity protected and encrypted, thereby improving the security of the part of the security mode command, avoiding the part of the security mode command from being maliciously attacked, and thereby improving the security of the NAS message.
Owner:BEIJING X RING TECHNOLOGY CO LTD

Security enhancement methods and systems for the IEC 104 protocol on the master station side of power monitoring systems

PendingCN122339686AIEC 62351Embedded system
This invention discloses a security enhancement method and system for the IEC 104 protocol on the master station side of a power monitoring system, comprising: generating input data, dynamically selecting a security mode and issuing configuration commands, generating original ASDU messages, calling application-layer security plugins to generate enhanced ASDU messages, encapsulating them into complete APDUs, generating security messages via transport-layer security plugins, and sending them to the station. This invention adopts a plug-in embedded architecture, integrating IEC 62351-5 application-layer and IEC 62351-3 transport-layer security plugins into the protocol processing module and communication processing module respectively, achieving decoupling of security functions and business functions; establishing a policy-driven mechanism, adding a security policy management module and an operation monitoring module, and providing port differentiation to adapt to different terminals to meet the needs of gradual transformation; controlling terminal concurrent connection latency at the millisecond level to meet the needs of large-scale high-concurrency access at the master station, and establishing a layered security protection system that coordinates the transport layer and application layer, ensuring message security even if transport layer security fails.
Owner:NARI NANJING CONTROL SYSTEM CO LTD +1

A solid state disk assembly with data security function

The application discloses a solid state disk assembly with data security function, and relates to the technical field of solid state disk security protection.The assembly comprises a solid state disk shell and a circuit board, wherein the circuit board is integrated with a master control unit, a NAND flash memory array, an environment sensing module and an interface module, and the modules are electrically connected through the circuit board wiring;the application integrates the environment sensing module composed of three types of sensors of temperature and humidity, vibration and electromagnetic radiation in the solid state disk assembly, matches the safety strategy control module built in the master control unit, realizes real-time collection of working environment parameters and threshold comparison, simultaneously designs the linkage control logic of encryption level control, interface locking, data temporary backup and storage area read-only protection in the master control unit, presets multiple safety modes and environment parameter thresholds and realizes dynamic switching, and performs differentiated safety protection operation on different environment abnormal scenes such as high temperature, strong electromagnetic interference and violent vibration.
Owner:YUETE INTELLIGENT TECHNOLOGY (XUZHOU) CO LTD

Method and apparatus for dynamically changing security algorithm

Embodiments of the present disclosure provide a method and an apparatus for dynamically changing security algorithm. An apparatus operating as a terminal device comprises: at least one processor; and at least one memory including computer program code. The at least one memory and the computer program code configured to, with the at least one processor, cause the apparatus operating as the terminal device at least to perform: receiving, from a network entity, a first message for configuring security mode, wherein the first message comprises a list of security algorithms and an indication of a change pattern of security algorithm; and transmitting, to the network entity, an accept message, when the apparatus operating as the terminal device supports the list of security algorithms and the change pattern of security algorithm. With the dynamical change, the number of permutations and combinations of algorithms and keys may be increased. The security level may be further improved.
Owner:NOKIA TECHNOLOGIES OY

Security handling for subsequent mobility

A method and apparatus for security handling for subsequent mobility procedure is provided. A wireless device receives a security mode command including a security configuration from a network, receives information informing whether a target cell belongs to a security group from the network, and continues using the security configuration based on the information informing that the target cell belongs to the security group.
Owner:LG ELECTRONICS INC

Security system, portable terminal, program, and security method

To provide a security system that improves user convenience when the mode switching operation is performed.SOLUTION: A security system includes a security device that monitors intrusion into a monitored area by a plurality of security modes, and a portable terminal that can switch the security modes remotely by communication with the security device. The security system includes storage means, determination means, control means, and communication means. The storage means stores mode identification information indicating the security mode set in the monitored area. The determination means determines whether or not the portable terminal has moved from inside the monitored area to outside the monitored area, or whether or not the portable terminal has intruded into a first area within a predetermined distance range near the monitored area outside the monitored area from a second area outside the predetermined distance range. The control means causes the portable terminal to display a switching screen on which the switching operation of the security modes can be input according to a determination result of the determination means and the set security mode. The communication means transmits a switching request for the security mode when the switching operation is input on the switching screen.SELECTED DRAWING: Figure 6
Owner:SECOM CO LTD

Physical layer security

A method includes a wireless terminal device indicating, and a wireless access network node receiving an indication of, security information for a lower layer, wherein the security information comprises a security level and / or a security mode. Similarly, a method includes a wireless access network node indicating, and a wireless terminal device receiving an indication of, a security command for a lower layer, wherein the security command comprises a security level and / or a security mode.
Owner:ZTE CORP

Interactive Linux kernel signature verification loading method, device and equipment

The invention relates to an interactive Linux kernel signature verification loading method, device and equipment, belongs to the technical field of information security, and solves the problems of insufficient system flexibility and lack of third-party module loading operation log records caused by too strict kernel module signature verification mechanism in the prior art. Comprising the following steps: integrating a predefined kernel module white list into an initial memory disk image, and configuring an access control strategy; when the system is in a loose and safe mode, judging whether an interactive verification function is enabled or not, if so, judging whether a to-be-loaded kernel module is located in the kernel module white list or not when a loading request of an unsigned or invalid-signed to-be-loaded kernel module is detected, and if so, allowing to load the to-be-loaded kernel module; if not, triggering a user interaction confirmation process, and determining whether the to-be-loaded kernel module is allowed to be loaded or not according to a confirmation result; wherein the loading event information of the kernel module to be loaded is recorded to the audit log.
Owner:BEIJING LINX SOFTWARE CORP

Access control systems and methods

Computer security techniques are described. One example provides a security module. The security module executes on a computing system and determines whether to allow a user or a program (e.g., native executable, script, etc.) associated with the user to access a resource, such as by reading, writing, or executing a file. An example operation system provides a new system administration mechanism that enforces rights and limitations for specific administrative and application groups that each have their own super user. Such a system may include a safe mode superuser who is required to log in when the system is in maintenance mode (e.g., single user console mode) at which time the safe mode superuser is the only user who is allowed to make programs executable.
Owner:CHIEN DANIEL

Secure communications in modular non-access stratum architecture

Techniques are provided for secure communication management in a communication network environment, such as in a roaming scenario, between a device (e.g., a user equipment) and its home network. For example, one method receives a security mode command message from a first network entity in a first communication network via a second communication network. The security mode command message has security information including a key set identifier, which is one or more key set identifiers previously received from the first communication network and associated with a first key, and the first communication network is the user equipment's home network. The method then uses the security information to establish a security context between the user equipment and the first network entity in the first communication network for secure data exchange.
Owner:NOKIA TECHNOLOGIES OY

Systems and methods for updating a security user interface based on scheduled modes

Example implementations include a method, apparatus and computer-readable medium for controlling a user interface of a video monitoring system, comprising generating, at a first time, a graphical user interface that depicts a first plurality of camera views that correspond to a first camera view configuration of a first security mode captured from cameras installed in an environment. The implementations further include detecting a start of a second security mode at a second time and updating the graphical user interface to depict a second plurality of camera views that correspond to a second camera view configuration of the second security mode in response to detecting the start of the second security mode. Additionally, the implementations further include detecting an end of the second security mode at a third time and updating the graphical user interface to a third camera view configuration of a third security mode.
Owner:TYCO FIRE & SECURITY GMBH

System attribute simulation method and system based on swan NEXT simulator

The invention relates to the technical field of computer software, in particular to a system attribute simulation method and system based on a swan NEXT simulator. The method comprises the following steps: loading a read-only copy of a mirror image of a swan NEXT system in a target test environment in a controlled host, and analyzing a mirror image file system to position a user configuration file, a system attribute configuration file and a security configuration file; adding a super user configuration item in the user configuration file, setting a user identifier and a group identifier to be zero, and recording a creation state of the configuration item; and declaring to start an equipment connector debugging mode and a global debugging mark in the system attribute configuration file, declaring operation parameters of a tolerance mode in the security configuration file, and respectively recording the effective states of the debugging mode and the security mode. Through a controllable simulator Root technology, a high-privilege and deep swan NEXT simulator analysis environment is successfully constructed.
Owner:BEIJING BANGCLE TECH CO LTD

Method and computers system to execute safe code

A Method and a Computer system wherein the computer system comprises a device (DEV), wherein said device includes an unsafe operating system (UnSafOS) configured to execute at a first execution level (EL i), at least a first program (PROG3) configured to execute at a second execution level (EL i-k), and a second program (ModCh) for changing the mode of said at least one processor core (MODE) from unsafe mode (Un-SafMod) to safe mode (SafMod) and from safe mode (SafMod) to unsafe mode (Un-SafMod), said second program (ModCH) is configured to execute on a third execution level (EL i+j) said first program (PROG3) includes safe code (SafCo) and unsafe code (UnSafCo), and said first program (PROG3) executes as process of said unsafe operating system (Un-SafOS) and said first program (PROG3) triggers a change from unsafe mode (Un-SafMod) to safe mode (SafMod) by executing a first command (SZ_Enter) and triggers a change from safe mode (SafMod) to unsafe Mode (UnSafMod) by executing a second command (SZ_Exit).
Owner:TTTECH AUTO AG