Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

20 results about "Security policy management" patented technology

A security policy management program is associated with the management of security policies within an environment. The goal of this program is to keep security policies updated, relevant, and standardized within an environment. The following elements and processes are generally associated with security policy management.

Security policy management

PendingUS20260095487A1Securing communicationEngineeringSecurity policy management
In various examples, input queries (e.g. open user queries) are used combination with predefined queries to perform security policy-related actions using a generative machine learning (GML) model or GML models. In one example, an input query relating to a security policy is matched with a predefined query stored in an instruction database. In some examples, the instruction database contains examples of structured configuration data, which in turn can be used by a GML model to configure a predetermined extractor code module to perform a specific policy-related action. In other examples, a security context relating to a security policy is used together with an input query and template query to generate a GML model query. In some examples, the two approaches are combined.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

High-altitude anti-falling comprehensive analysis method based on high-altitude operation monitoring multi-dimensional data and related device

The invention provides a high-altitude anti-falling comprehensive analysis method based on high-altitude operation monitoring multi-dimensional data and a related device, and belongs to the field of high-altitude operation safety monitoring. The method comprises the following steps: acquiring position and posture data, physiological data, working environment data and group management data of each operator, and preprocessing to obtain a real-time data set; using the risk evaluation model to obtain a real-time risk score of high-altitude operation; using the risk prediction model to obtain a prediction risk probability of high-altitude operation; and carrying out real-time anti-falling alarm on high-altitude operation based on the real-time risk score and the predicted risk probability. According to the invention, by integrating position, physiology, environment, group management and other multi-dimensional data and through risk evaluation and prediction model comprehensive analysis, the comprehensiveness and accuracy of safety evaluation are significantly improved; and real-time anti-falling alarm is carried out based on a double-model result, so that the early warning accuracy and reliability are effectively improved, group-level security policy management is realized, and modern aerial work management requirements are met.
Owner:ZHANJIANG POWER SUPPLY BUREAU OF GUANGDONG POWER GRID CO LTD

Depth context aware front-end dynamic depth security protection method and system

The invention relates to the technical field of Web application security, and provides a depth context-aware front-end dynamic depth security protection method, which comprises the following steps of: S1, acquiring a current user role, an authority level, an access routing path and semantic attributes of an operation UI (User Interface) component to form multi-dimensional depth context data; s2, the dynamic CSP strategy engine injects the obtained CSP strategy into a front-end environment by creating or updating a page Meta label; s3, performing double-layer protection during operation, wherein the double-layer protection comprises an input protection layer and an operation protection layer; s4, threat linkage response: if a hostile attack is detected in the step S3, a threat event is encrypted and reported to a security policy management center, and the management center dynamically updates a CSP policy and a sensitive operation verification rule; and S5, global strategy optimization: the management center counts and analyzes threat logs, and automatically adjusts a default strategy of high-risk routing. Through dynamic security policy generation, context-aware semantic analysis and a multi-layer protection linkage response mechanism, a self-adaptive and deep front-end security protection system is constructed.
Owner:GENERATION TIMES TECHNOLOGY (SHANGHAI) CO LTD

A digital tag-based file leakage prevention and traceability evidence system

ActiveCN117675373BSolve the problem of easy leakageEasy to detectSecurity policy managementAsset (computer security)
The application discloses a file anti-leakage and traceability evidence system based on a digital label, and relates to the technical field of computer security. The system comprises a terminal agent unit and a behavior audit center, the terminal agent unit is connected with the behavior audit center through a network to complete information interaction, the terminal agent unit is arranged on each terminal computer in a local area network, and through label embedding, label verification, behavior audit and access control on intranet files, fine-grained access control and behavior audit of the intranet files based on label attributes are realized; the behavior audit center is arranged on a local area network background server, receives file attributes and label information reported by the terminal agent unit, realizes intranet file asset presentation, digital label management, security policy management and behavior log audit, realizes comprehensive presentation of file behavior situation and threat prediction based on artificial intelligence technology, and realizes automatic threat disposal according to preset security policies.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP

Managing data security using a management controller of a data processing system

Methods and systems for managing operations of a data processing system are disclosed. To manage operations of the data processing system, a management controller of the data processing system may provide user access data for the data processing system obtained from hardware resources to a security manager. The management controller may obtain a response from the security manager based on the user access data. In a first instance of the obtaining where the response indicates that the data processing system is exhibiting a level of data vulnerability that meets criteria, the management controller may obtain a security policy comprising an action set for updating the operation of the data processing system. The management controller may perform the action set to update an existing operating state of the data processing system to a new operating state to reduce the level of data vulnerability exhibited by the data processing system.
Owner:DELL PROD LP

Centralized security policy administration using NVMe-oF zoning

Systems and methods extend Non-Volatile Memory express over Fabric (NVMe-oF) zoning to enable security policy administration and authentication of NVMe-oF entities in a centralized manner without requiring per-connection provisioning administered by a Centralized Discovery Controller (CDC). In various embodiments a zone configuration is defined that represents access control rules, which determine which entities can connect with each other, and that may be augmented by specifying in a zone attribute whether members of a zone should authenticate or authenticate and establish a secure channel between themselves. Each entity may be configured with a per-entity global security policy that comprises a security credential and that enables an authentication and / or a secure channel communication between entities. Once an entity issues a Get Log Page request to the CDC to discover other entities, the CDC may provide a list of such entities and specify whether authentication and / or secure channel communication should be performed.
Owner:DELL PROD LP

Security enhancement methods and systems for the IEC 104 protocol on the master station side of power monitoring systems

PendingCN122339686AIEC 62351Embedded system
This invention discloses a security enhancement method and system for the IEC 104 protocol on the master station side of a power monitoring system, comprising: generating input data, dynamically selecting a security mode and issuing configuration commands, generating original ASDU messages, calling application-layer security plugins to generate enhanced ASDU messages, encapsulating them into complete APDUs, generating security messages via transport-layer security plugins, and sending them to the station. This invention adopts a plug-in embedded architecture, integrating IEC 62351-5 application-layer and IEC 62351-3 transport-layer security plugins into the protocol processing module and communication processing module respectively, achieving decoupling of security functions and business functions; establishing a policy-driven mechanism, adding a security policy management module and an operation monitoring module, and providing port differentiation to adapt to different terminals to meet the needs of gradual transformation; controlling terminal concurrent connection latency at the millisecond level to meet the needs of large-scale high-concurrency access at the master station, and establishing a layered security protection system that coordinates the transport layer and application layer, ensuring message security even if transport layer security fails.
Owner:NARI NANJING CONTROL SYSTEM CO LTD +1

Face recognition building intercom system based on VOIP encryption transmission

The invention discloses a face recognition building intercom system based on VOIP encryption transmission, and relates to the technical field of building intercom communication, the system comprises an entrance machine, an indoor machine and a management platform, the entrance machine is integrated with a network state sensing module, a security policy management module, a biological characteristic key generation module and a human body posture recognition model, the entrance machine collects a face image and completes preliminary recognition, the biological feature key generation module extracts feature factors from the face image and dynamically generates a unique encryption key, the security policy management module switches encryption policies such as a ChaCha20 stream cryptographic algorithm and an AES-256 algorithm according to a call stage and network quality parameters, and the security policy management module carries out encryption on the face image. The redundancy error correction strategy is dynamically adjusted based on the data packet priority and the network condition, the management platform is responsible for coordinating system operation, storing logs and pushing strategy suggestions, dynamic balance of communication safety, real-time performance and reliability is achieved, system energy consumption is reduced, user privacy is protected, and the method is suitable for application scenes with complex network conditions.
Owner:SHENZHEN SKYRISE TECH CO LTD

Unified secure access control to software services and applications

Methods and systems of access control to enterprise applications. Embodiments of the invention implement a unified secure access control solution to enable users to securely authenticate with applications no matter whether they are hosted in SAAS cloud or private networks. Intelligence Edge Gateways deployed at a network edge close to users' geographical locations ensure the control of users' secure access to software services and applications with minimized latency. A user only needs one set of credentials to gain access to various applications hosted in SAAS cloud or private networks. In an embodiment, Intelligence Edge Gateways enables IT administrators to set data plane level security policies in addition to the identity and access management policies. IT administrators are able to configure and manage all the security policies at Unified Access Cloud in a centralized manner.
Owner:SPLASHTOP INC

Security policy management

PCT designated stageWO2026075712A3Natural language translationDigital data information retrievalEngineeringSecurity policy management
In various examples, input queries (e.g. open user queries) are used combination with predefined queries to perform security policy-related actions using a generative machine learning (GML) model or GML models. In one example, an input query relating to a security policy is matched with a predefined query stored in an instruction database. In some examples, the instruction database contains examples of structured configuration data, which in turn can be used by a GML model to configure a predetermined extractor code module to perform a specific policy-related action. In other examples, a security context relating to a security policy is used together with an input query and template query to generate a GML model query. In some examples, the two approaches are combined.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

An API behavior prediction and security policy management method based on machine learning

The application provides an API behavior prediction and security policy management method based on machine learning, relates to the field of computer network security, and comprises the following steps: acquiring API original data in real time, preprocessing the original data to obtain preprocessed original data, acquiring API dimension features in real time based on the preprocessed original data, and fusing to obtain unstructured data; a dynamic characteristic validity verification rule is established to preprocess the unstructured data, and a unified dimension standardization feature tensor is obtained; the joint modeling of API behavior space-time features is performed through the collaborative architecture of a multi-head time attention mechanism and a dynamic graph neural network, API behavior prediction is performed, API dynamic security management and control strategies are generated in real time through a strategy engine, strategy execution is performed, the security strategy execution effect is monitored in real time, and iterative optimization is performed. The application solves the problems of fixed and rigid security management and control strategies of a traditional API gateway, and the difficulty in dynamically adjusting security strategies according to real-time access conditions and behaviors.
Owner:应急管理部大数据中心 +1

Methods and systems for protecting a secured network

Methods and systems for protecting a secured network are presented. For example, one or more packet security gateways may be associated with a security policy management server. At each packet security gateway, a dynamic security policy may be received from the security policy management server, packets associated with a network protected by the packet security gateway may be received, and at least one of multiple packet transformation functions specified by the dynamic security policy may be performed on the packets.
Owner:CENTRIPETAL NETWORKS INC

Container behavior supervision method and device based on priority

The invention relates to the technical field of container safety, and provides a priority-based container behavior supervision method and device. The method comprises the following steps: determining a mirror image priority according to a mirror image construction file; appointing a corresponding Seccomp strategy according to the mirror image priority; a mapping relation between the mirror image priority and the Seccomp strategy is established; obtaining a Seccomp strategy according to the mapping relation, and starting a container by using the Seccomp strategy; and monitoring a Seccomp event triggered by the container process, extracting a system calling behavior and performing structured recording to generate a structured log. According to the method and the device, dynamic security policy management based on the mirror image risk level is implemented on the container operation authority, and the problems of relatively low security, isolation and traceability during container operation in the prior art are solved.
Owner:709TH RESEARCH INSTITUTE CHINA STATE SHIPBUILDING CORP LTD

Quantum secure and credible meteorological data system based on quantum key

The invention relates to data security, in particular to a quantum security and credible meteorological data system based on a quantum key, and the system comprises a quantum security service platform which carries out the life cycle management of the quantum key, and carries out the identity authentication of a quantum security application terminal; the quantum security database performs quantum key interaction with the quantum security service platform, realizes encrypted storage of data in an application system by using a quantum cryptography technology in a manner of avoiding development and transformation, and provides a compliant and easy-to-implement data security protection scheme; the quantum application service is in butt joint with the business application service through customized research and development, and after business application is simply configured, automatic encryption and decryption of data can be realized, and abundant data security policy management capability is provided; according to the technical scheme provided by the invention, the defect that the safety of meteorological data is difficult to effectively guarantee in the prior art can be effectively overcome.
Owner:ANHUI PROVINCIAL METEOROLOGICAL INFORMATION CENTER (ANHUI PROVINCIAL METEOROLOGICAL ARCHIVES)

Basin information security architecture construction method and device, computer equipment and product

ActiveCN119484154BSecuring communicationEnvironmental resource managementInformation Operations
The present application relates to the technical field of river basin information management, and discloses a river basin information security architecture construction method and device, computer equipment and products, the river basin information security architecture construction method comprises: constructing a security policy management layer, a security policy control layer and a security policy execution layer based on a river basin information network, constructing a river basin information production area, a river basin information operation area and a river basin information Internet of Things area based on river basin information data, and data is unidirectionally transmitted in the security policy management layer, the security policy control layer and the security policy execution layer according to transmission permissions; a river basin information security policy is constructed by using the security policy management layer, applied to a river basin information general platform and transmitted to the security policy control layer; a river basin information security sub-policy is generated by using the security policy control layer, applied to a river basin information sub-platform and transmitted to the security policy execution layer; and the river basin information security sub-policy is executed by using the security policy execution layer. The present application can improve the security of river basin information data.
Owner:THREE GORGES GROUP IND DEVELOPMENT (BEIJING) CO LTD +1

Computer network information security monitoring system and use method

The invention relates to the technical field of computer systems, and provides a computer network information security monitoring system and a use method, and the system comprises an infrastructure and data collection module, a deep learning analysis module, a reinforcement learning strategy optimization module, a security strategy management module and a visual operation and maintenance and decision support module. The infrastructure and data acquisition module is responsible for collecting and transmitting data, the deep learning analysis module is used for identifying abnormal behaviors and predicting threat trends, the reinforcement learning strategy optimization module optimizes security strategies through autonomous learning, and the security strategy management module adjusts protection measures according to the optimization strategies. And the visual operation and maintenance and decision support module provides a visual system state view to assist operation and maintenance personnel to make decisions. According to the invention, through combination of deep learning and reinforcement learning technologies, active protection is realized, functions of firewall dynamic configuration, visual operation and maintenance, decision support and the like are provided, and comprehensive and efficient safety protection services are provided for users.
Owner:TIANJIN YIBU TECHNOLOGY CO LTD

End-to-end built-in safety communication device based on electric power trusted computing platform communication

The invention discloses a communication end-to-end built-in security communication device based on an electric power trusted computing platform, a security layer adopts an encryption algorithm to encrypt communication data, identity authentication is performed on two communication parties through a digital certificate and an identity authentication protocol, and the confidentiality and integrity of the data are ensured; the adaptation layer deeply adapts to various power communication protocols and equipment interfaces, supports transmission power setting of different groups of data signal states, and improves the universality and applicability of the device; the physical layer adopts a corresponding modulation and demodulation technology according to a transmission medium and signal characteristics to ensure high-efficiency transmission of signals; the system further comprises a security policy management module and an anomaly detection and processing module, flexibly configures security policies according to the security requirements of the power system, monitors communication data and network states in real time, quickly discovers and processes abnormal conditions, effectively guarantees the security, integrity and availability of the communication data of the power system, and improves the safety of the power system. And a solid technical support is provided for stable operation of a power system.
Owner:新疆华电苇湖梁新能源有限公司

Security policy management

PCT designated stageWO2026075712A2TransmissionSpecial data processing applicationsEngineeringSecurity policy management
In various examples, input queries (e.g. open user queries) are used combination with predefined queries to perform security policy-related actions using a generative machine learning (GML) model or GML models. In one example, an input query relating to a security policy is matched with a predefined query stored in an instruction database. In some examples, the instruction database contains examples of structured configuration data, which in turn can be used by a GML model to configure a predetermined extractor code module to perform a specific policy-related action. In other examples, a security context relating to a security policy is used together with an input query and template query to generate a GML model query. In some examples, the two approaches are combined.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Security event global visualization and security policy management method based on situation awareness platform

The invention discloses a situation awareness platform-based security event global visualization and security policy management method. The visual situation awareness platform comprises a situation analysis and large-screen display system, a big data and artificial intelligence system, a security information and event management system, a security monitoring system and an automatic response system. Internal and external information is integrated through the situation awareness platform, a global security view angle is provided, security managers are helped to quickly understand the security situation, and the security management efficiency is improved. Intelligent identification and analysis of security threats are realized, and the intelligent level of security defense is improved. According to the dynamic defense strategy based on situation awareness, defense measures can be adjusted according to actual security threats, the defense capability, visual display and rapid analysis of situation awareness of enterprises on novel attacks are enhanced, the time of the enterprises from finding the security threats to taking the defense measures is greatly shortened, and the response speed of security events is increased.
Owner:HUADI COMP GROUP

Security policy management method and device, storage medium and computer equipment

The invention discloses a security policy management method and device, a storage medium and computer equipment, and relates to the technical field of data management. The method comprises: receiving security policy information and a policy type identifier sent by a security device, and determining a preset parameter screening rule corresponding to the policy type identifier based on the policy type identifier, the security policy information comprising a plurality of security policy parameters recorded for a parameter sending rule preset by the security device, the security device sends security policy parameters recorded by the parameter sending rule based on the parameter sending rule; screening out at least one target policy parameter from the plurality of security policy parameters based on a preset parameter screening rule; and generating a strategy display page based on the target strategy parameter, and displaying the strategy display page on a display device of the computer equipment. According to the scheme, the security policy management efficiency of the security equipment can be improved.
Owner:BEIJING GUODIAN ZHISHEN CONTROL TONGDY