Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

153 results about "Security policy" patented technology

Security policy is a definition of what it means to be secure for a system, organization or other entity. For an organization, it addresses the constraints on behavior of its members as well as constraints imposed on adversaries by mechanisms such as doors, locks, keys and walls. For systems, the security policy addresses constraints on functions and flow among them, constraints on access by external systems and adversaries including programs and access to data by people.

Implementation method and device of programmable API security gateway

ActiveCN115913750BSoftware engineeringProgram security
This invention discloses a method and apparatus for implementing a programmable API security gateway. The method includes: identifying API interface characteristics and automatically programming policy templates for the API interfaces based on these characteristics; detecting security events of the API interfaces and automatically programming security policy templates for the API interfaces based on these security events; and monitoring the operational status of the API interfaces and automatically adjusting the flow control and security policies associated with the API interfaces. This method and apparatus improve the maintenance efficiency of API interfaces and reduce operational costs.
Owner:CHINA UNITECHS

Artificial intelligence agent hardware freeze safety device

The present application solves the core problems of tamperability, high delay and insufficient multi-modal coverage of existing AI security protection through hardware solidification rules, special detection acceleration and independent freezing mechanism. The device completes rule solidification during the manufacturing stage, and the user cannot intervene, ensuring the absolute credibility of the security policy; hardware-level detection achieves millisecond-level response, suitable for high-security AI scenarios. The present application meets the application requirements of high-security scenarios in terms of theoretical design and technical scheme demonstration, and has significant industrial application value.
Owner:SHENZHEN BAIMAXUN NETWORK TECHNOLOGY CO LTD

Memory preserved warm reset mechansim

An apparatus is disclosed. The apparatus comprises one or more processors to receive a request to trigger a system management interrupt (SMI), execute policy shim code to enforce access control policy in a first privilege level and dispatch the SMI to shield code to enforce the access security policy to perform a system management mode (SMM) and execute the shield code to perform the SMM, including retrieving an operating system (OS) memory preserved warm reset (MPWR) context, saving the context and issuing a warm reset.
Owner:INTEL CORP

A secure chip based on a configurable lookup table

PendingCN122389098AComputer hardwarePower analysis
This invention discloses a security chip based on a configurable lookup table. The security chip includes: at least one configurable logic block, each containing at least one configurable lookup table unit; a dynamic mask generator connected to the configurable lookup table unit, dynamically generating a mask sequence according to the current processing clock cycle; a reconfiguration controller connected to the dynamic mask generator, changing the configuration values ​​of the configurable lookup table units in real time according to a security policy; and a security execution engine, whose input is connected to the output of the configurable lookup table unit, performing secure operations based on the masked lookup results; wherein the configurable lookup table unit presents different truth table mappings for the same logic input in at least two different clock cycles. This invention enables the lookup table unit to present different truth table mappings in different clock cycles, breaking the deterministic correlation between power consumption characteristics and data, and effectively resisting side-channel attacks such as differential power analysis.
Owner:ZHONGSHAN YUANSHI MICRO TECH CO LTD

Method for monitoring and enforcing secure policies in a device

ActiveUS12671707B2Security policyPacket filtering
A method for monitoring and enforcing secure policies in a device includes collecting kernel data from a kernel space by a packet filtering module operating in a user space. The kernel data is processed into events that are transmitted to a data bus, where the events are stored and provided to a policy enforcement module. The policy enforcement module evaluates the events with an algorithm to detect potential threat events. When a threat event is identified, one or more secure policies are selected and executed in the device as corresponding actions or commands. The method enables real-time monitoring of kernel activity and enforcement of security policies while maintaining the architecture in user space.
Owner:EXEIN SPA

A multi-modal data security sharing method based on information security

This invention discloses a multimodal data security sharing method based on information security. Addressing the problems raised in previous technologies, such as data becoming ineffective when it leaves a controlled domain, and the inability of subsequent dynamic control attempts to be implemented due to the lack of a trusted, data-co-existing execution endpoint, and the inability of security policies to learn and adjust based on real-time feedback during data usage, this invention proposes the following solution: policy-driven multimodal data preprocessing and labeling. For the raw multimodal data to be shared, a sensitive information identification model corresponding to the modality is invoked for analysis. This invention solves the industry problem of data loss of control after leaving the domain, promotes real-time collaboration and evolution of security capabilities, drives the continuous evolution of policies and identification models, and constructs a unified framework and modality-adaptive cross-modal data security management solution. It transforms complex security operation and maintenance problems into simple policy definition problems, significantly reducing the technical threshold and operational costs of secure sharing.
Owner:BEIJING XINRUIXIANGTONG TECH CO LTD

Method and device for joint evaluation of security boundary and communication performance based on 5g-a industrial internet

PendingCN122339853AJoint evaluationComputer network
This application provides a method and apparatus for jointly evaluating security boundaries and communication performance based on 5G-A industrial internet. The method includes: acquiring current network load data and current security policy parameter combinations, and inputting the current network load data and current security policy parameter combinations into a nonlinear latency prediction model to obtain the current overall latency; utilizing the current security policy parameter combinations and the current overall latency to generate a current security-communication global score; when the current security-communication global score is lower than a preset threshold, determining the fine-tuning amount of each security parameter from a multidimensional coupling relationship matrix library based on the current network load data and the current security policy parameter combinations to obtain the optimal security policy parameter combination. Through the nonlinear latency prediction model and the multidimensional coupling relationship matrix library, coupled modeling of security and communication is achieved; it also enables comparison and integration of security and communication in the same dimension, achieving synergistic optimization of security and communication resources.
Owner:CHINA UNITED NETWORK COMM CO LTD SHENZHEN BRANCH +2

A hierarchical encryption storage method and system for a drone

PendingCN122339765ANo-fly zoneSmart contract
The application discloses a hierarchical encryption storage method and system for a UAV. The method comprises the following steps: obtaining a dynamic security policy coded as a smart contract from a block chain network, and calling a static security policy from a local; the dynamic security policy and the static security policy both comprise a no-fly area and an execution action; obtaining a three-dimensional position of the UAV in real time, and judging whether the three-dimensional position of the UAV is in or near the no-fly area of the dynamic security policy or the static security policy; if yes, calling a pre-configured flight task type from the local, and determining a security level according to the flight task type; executing the corresponding dynamic security policy or static security policy according to the security level, and performing hierarchical data encryption storage. When the UAV enters a sensitive area, not only corresponding flight control is implemented, but also encryption of a corresponding level is triggered automatically and in real time, so that linkage protection of flight safety and data safety is realized, and data protection and flight state are ensured to be performed synchronously.
Owner:NANJING QUFEIPAI TECHNOLOGY CO LTD

A data space based data usage dynamic control method and system

PendingCN122394859AData accessDataspaces
This application provides a dynamic control method and system for data usage based on a data space, belonging to the field of network security technology. The method includes: acquiring access requests from data users and storing them in a preset data space, which includes control logic, access requests, and policies; acquiring environmental information of the access requests through a preset context-aware engine; evaluating the environmental information based on a preset blocking rule base and a preset security policy baseline to obtain a risk assessment coefficient; allowing data access when the risk assessment coefficient is less than a preset first threshold, and inputting the interaction pattern generated by the data access into a pre-trained access anomaly detection model to obtain a detection result; generating and outputting a denial information report if the detection result is abnormal behavior; and verifying the normal behavior against the access request and access policy if the verification fails, generating and outputting an alarm message. This application improves data security.
Owner:SHENZHEN YUNCHUANG YOUYI TECH CO LTD

Computer system attack detection

ActiveUS12647431B2Ensemble learningSecuring communicationAttackSocial engineering (security)
In an example embodiment, a combination of machine learning and rule-based techniques are used to automatically detect social engineering attacks in a computer system. More particularly, three phases of detection are utilized on communications in a thread or stream of communications: attack contextualization, intention classification, and security policy violation detection. Each phase of detection causes a score to be generated that is reflective of the degree of danger in the thread or stream of communications, and these scores may then be combined into a single global social engineering attack score, which then may be used to determined appropriate actions to deal with the attack if it transgresses a threshold.
Owner:SAP SE

Recommendation and remediation role-based access control postures for identities

PendingUS20260141091A1Digital data protectionPattern detectionBusiness enterprise
An automated, analytics-driven invention that generates, validates, and orchestrates unified RBAC postures spanning cloud infrastructure, SaaS applications, and on-premise assets. The method ingests entitlement data, HRIS attributes, behavioral data, and security policy constraints to identify common access patterns, detect anomalies, and recommend consolidated roles that embody the principle of least privilege. A dual-perspective algorithm—bottom-up clustering of shared connections and top-down evaluation of organizational context—produces high-fidelity roles annotated with confidence scores. The system surfaces actionable insights such as over-entitlement, under-entitlement, segregation-of-duties conflicts, and duplicate connections, then prescribes remediation playbooks or just-in-time enforcement. By continuously comparing the current state to a dynamically computed ideal state, the invention guides enterprises toward an access model that minimizes risk, streamlines audits, and reduces administrative drag.
Owner:RAMA SUBRAMANIAN +6

Security policy analysis and updating using generative artificial intelligence (AI)

Security policy generation using generative AI, including: accessing data describing one or more requirements for a cloud deployment; providing the data as input to a generative AI model; and generating, by the generative AI model and based on the data, a policy for the cloud deployment.
Owner:PURE STORAGE INC

Azure virtual desktop micro-segmentation monitoring method and system based on zero trust architecture

The application relates to the technical field of network security, and discloses an Azure virtual desktop micro-isolation monitoring method and system based on a zero-trust architecture, which comprises the following steps: collecting and analyzing user operation logs in real time to construct a behavior baseline model and mode distribution; quantifying the operation deviation degree through behavior fluctuation analysis, identifying abnormalities and determining a risk level; detecting session environment threats in combination with device security data; generating a session credibility score and control instruction based on weighted analysis of user behavior and device state; dynamically adjusting access permissions according to the credibility score, and updating security policies in real time to adapt to environmental changes; continuously monitoring and cyclically executing abnormality analysis and permission adjustment to realize dynamic maintenance of system security. The method can effectively deal with internal behavior abnormalities and external threats, and improve the accuracy and real-time performance of overall security protection.
Owner:SHANGHAI WICRESOFT

Security policy framework for cloud environments

ActiveUS12676892B2Data sourceEngineering
The present disclosure includes systems and methods for a security policy framework. Various embodiments include responsive to receiving a trigger, fetching one or more policies from a policy catalog service; compiling the one or more policies into a query, wherein the one or more policies can be compiled into a plurality of different query languages; executing the query over customer data, the customer data being located in one or more data sources; and persisting results of the query.
Owner:ZSCALER INC

A login auditing method, device, apparatus and storage medium

The application relates to a login auditing method, device and equipment and a storage medium. The method collects multi-source data on a terminal side, wherein the multi-source data comprises network session data and window input data; whether the multi-source data meets an analysis requirement is judged according to a preset analysis rule, if yes, login behavior related information is extracted from the multi-source data based on the analysis rule; the login behavior related information is matched with a preset security policy to obtain a matching result; a risk level is determined according to the matching result, a corresponding response operation is executed according to the risk level, and an audit record is generated; compared with the prior art, the technical scheme of the application can realize full-process closed-loop management of terminal-side login auditing from multi-source data collection, information analysis to strategy matching, risk response and audit record keeping, can comprehensively extract login behavior information, accurately determine login risks and complete traceable audit records, and improves the overall effectiveness of login auditing.
Owner:SHENZHEN LEAGSOFT TECH

Hybrid signature method and system based on quantum key and puf

This invention provides a hybrid signature method and system based on quantum key distribution and PUF, belonging to the field of information security technology. The method includes: generating a quantum key through a quantum key distribution protocol and generating a derived key seed based on a physically non-cloning function, while simultaneously configuring a trusted region for location and timing; acquiring location and timing information and generating location and timing data; generating a dynamic root key and deriving classical signature key pairs and post-quantum signature key pairs; preprocessing the message to be signed and the location and timing data, matching hierarchical security policies, and selecting the corresponding signature method to generate a signature data packet; during the signature verification process, verifying the location and timing data for signature validity and legality, and verifying the signature result using the corresponding verification method selected according to the hierarchical security policy. This invention achieves dynamic generation of signature keys and hierarchical security policy scheduling, balancing digital signatures in terms of quantum attack resistance, device binding capability, and computational efficiency.
Owner:SICHUAN LIANGSHANSHUILUOHE ELECTRICITY DEV CO LTD

Context-aware security policies and incident identification via automated cloud graph building with security overlays

Context-aware security policies and incident identification, via automated cloud graph building with security overlays, are determined and performed by systems and platforms. Graph nodes, of a graph associated with a computing system, that represent resources associated with the computing system and entities associated with the computing system that have respective associations to the resources are generated. Security attributes are determined and assigned to the graph nodes that represent the entities and resources, and static and dynamic connections between the graph nodes are added to the graph. Additionally, possible connections in the graph between the graph nodes are added based on heuristic relational determinations of the graph nodes. From the graph, security incidents and kill chains are identified, context-aware security policies are generated and validated, and scopes and relationships of applications are identified. Accordingly, security actions are taken for the computing system.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Access control method and electronic device

ActiveCN115706994BUser privacyEngineering
The embodiment of the present application provides an access control method and an electronic device. In the technical scheme provided by the embodiment of the present application, a first application is called to generate a calling request, or a calling request sent by a first electronic device through calling a first application is received, the calling request is used for requesting a second application to call a target service; whether the calling request is allowed is judged according to a security policy pre-configured by a user, the target service, the first application and the second application; if it is judged that the calling request is not allowed, the calling request is rejected, and prompt information for prompting that the first application is abnormally operated is generated. The embodiment of the present application enables the current mobile OS to effectively find and block the user privacy leakage problem in a distributed system composed of multiple devices.
Owner:HUAWEI TECH CO LTD

A security policy matching method, device, storage medium and computing device

The application provides a security policy matching method and device, a storage medium and a computing device. When any security policy tree is constructed, a node priority is set for each tree node, which can accurately reflect the highest policy priority of the subordinate sub-tree of each tree node, thereby providing a core basis for pruning low-priority nodes during security policy matching, ensuring the order of dynamic maintenance of the node priority, and improving the security policy matching efficiency. Furthermore, the early stop attribute is set for the security policy of the leaf node in the multi-security policy tree in stages, which realizes the fast marking of the absolute high-priority security policy and the accurate marking of the non-absolute high-priority security policy without intersection, and the combination of the two realizes the accurate setting of the early stop attribute of the security policy. In this way, the large-scale security policy matching efficiency is improved, the optimal matching result is ensured, the computing cost is reduced, and the matching performance of the security policy tree is significantly improved.
Owner:HANGZHOU DPTECH TECH

Remediation plan generation for security policy violations based on aggregation of related violations

PendingUS20260141060A1Platform integrity maintainanceGraph traversalSearch graph
A cybersecurity service (“service”) obtains alerts indicating security policy violations for assets in a computing environment and the corresponding issue category(ies) associated with each violation. For each alert, the service determines which asset in the computing environment to target for remediation of the associated violation by searching a graph representation of the computing environment based on the affected asset's type and / or the issue category. The service identifies a target asset and other assets related to the affected asset and the target asset as a result of searching the graph and generates a remediation plan indicating actions to take on the target asset to remediate the security policy violation for the affected asset based on the target asset type and the corresponding issue category. The service indicates the remediation plan, the related assets identified due to the graph traversal, and their corresponding security policy violations within the same issue category.
Owner:PALO ALTO NETWORKS INC

Zero changed file trust hardening of endpoint computing devices

Methods, systems, and computer program products for hardening an endpoint computing device include initiating detection of file change operations and detection of file execution operations on an endpoint device. When a file change operation is detected, attributes associated with a process that initiated the file change operation are identified, attributes associated with the file change operation are identified, and the attributes are stored in a changed file list. When a file execution operation is detected, a file in the changed file list that corresponds to a file associated with the file execution operation is identified, and whether to prevent execution of the file is determined by applying a security policy to the one or more attributes in the changed file list that correspond to the identified file.
Owner:SOPHOS LTD

An ap platform management system and method

PendingCN122310512ASecure stateTerm memory
This application provides an AP platform management system and method. In this system, after receiving a startup request from an in-vehicle application, the EM module directly triggers the HSM module to verify the application's legitimacy. After successful application verification, the EM module triggers the runtime monitoring module to perform security monitoring on the application's real-time runtime data, enabling timely identification of abnormal behaviors caused by memory injection and malicious code execution. Simultaneously, the policy analysis module performs risk analysis based on a preset security policy library and outputs response strategies. The EM module then executes the corresponding security response operations, thereby establishing a complete application security status management system and a closed loop for security incident handling. This achieves deep collaboration between the EM and hardware security modules, providing stable security support covering the entire application lifecycle for the AP platform and effectively enhancing the AP platform's ability to respond to various cybersecurity threats.
Owner:NEUSOFT REACH AUTOMOBILE TECH (SHENYANG) CO LTD

Cloud dynamic endpoint group

PendingUS20260181022A1Securing communicationEndpoint securitySecurity policy
The present application discloses a method, system, and computer system for managing endpoint security and protecting a network based on a security posture. The method includes: (a) receiving a set of risk signals for each of a plurality of endpoints, wherein the set of risk signals is received from one or more trusted sources, (b) dynamically creating an endpoint group based at least in part on a risk criteria and the set of risk signals, and (c) applying security policy controls to the endpoint group consistently across access through a cloud security service and gateway firewalls.
Owner:PALO ALTO NETWORKS INC

Secure access methods, devices and vehicles

This application provides a secure access method, apparatus, and vehicle. The method includes: receiving a first message sent by a server, the first message indicating at least one service that the server can provide, the first message including a first random number; determining at least one second key based on a first key, a first security policy option, and the first random number, wherein the first key is a symmetric key, the first security policy option indicating the security level corresponding to at least one interface of at least one service in the service, and the at least one second key used to verify a second message sent by the server, the second message including data corresponding to the first service, and the at least one service including the first service. Through this method, different protection strategies and communication keys can be adopted for different interfaces in the SOME / IP service, ensuring secure communication between the server and client while avoiding over-protection or poor processing performance.
Owner:YINWANG INTELLIGENT TECHNOLOGIES CO LTD

Automated and secure software management process across multiple computer terminals with real-time monitoring and notifications

The present invention relates to a method for managing software on computer terminals (computers, mobile phones, tablets) used by a community within an entity with security policies. Each terminal incorporates a data collection module that monitors user interactions with various applications in real time. The process includes recording usage references, identifying the applications used, and collecting associated data. This data is analyzed to identify applications in real time and detect anomalies compared to normal usage. In the event of abnormal behavior or to optimize software usage, personalized notifications are generated in real time. These notifications can be sent directly to the terminals via email or integrated into the user interface.This process aims for centralized, proactive, and automated governance to strengthen the compliance, security, and efficiency of applications used within an organization. See Figure 1 for an abstract.
Owner:BEAMY

Method and system for secure firmware upgrade of an electric energy meter

This invention provides a method and system for secure firmware upgrades of electricity meters. At the master station, an upgrade package is constructed, consisting of a structured header, firmware payload, authentication tag, and digital signature. The structured header includes a specially configured extensible flag field to flexibly define the context parameter combinations, security policies, and compression policies involved in encryption operations, improving upgrade compatibility. At the device end, all core security operations, such as signature verification, key derivation, and decryption authentication, are executed independently by a secure element, and the keys are never exposed, fundamentally preventing key leakage and unauthorized tampering. The overall solution, through multiple pre-verification checks combined with encryption authentication, digital signatures, and CRC checks, forms an end-to-end, multi-layered protection system, comprehensively ensuring the confidentiality, integrity, source credibility, and device compatibility of firmware upgrades. It effectively resists various attacks and significantly improves the security, reliability, and operational stability of electricity meter firmware upgrades.
Owner:SHENZHEN INHEMETER