Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

14 results about "Security policy management" patented technology

A security policy management program is associated with the management of security policies within an environment. The goal of this program is to keep security policies updated, relevant, and standardized within an environment. The following elements and processes are generally associated with security policy management.

Security policy management

PendingUS20260095487A1Securing communicationEngineeringSecurity policy management
In various examples, input queries (e.g. open user queries) are used combination with predefined queries to perform security policy-related actions using a generative machine learning (GML) model or GML models. In one example, an input query relating to a security policy is matched with a predefined query stored in an instruction database. In some examples, the instruction database contains examples of structured configuration data, which in turn can be used by a GML model to configure a predetermined extractor code module to perform a specific policy-related action. In other examples, a security context relating to a security policy is used together with an input query and template query to generate a GML model query. In some examples, the two approaches are combined.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Depth context aware front-end dynamic depth security protection method and system

The invention relates to the technical field of Web application security, and provides a depth context-aware front-end dynamic depth security protection method, which comprises the following steps of: S1, acquiring a current user role, an authority level, an access routing path and semantic attributes of an operation UI (User Interface) component to form multi-dimensional depth context data; s2, the dynamic CSP strategy engine injects the obtained CSP strategy into a front-end environment by creating or updating a page Meta label; s3, performing double-layer protection during operation, wherein the double-layer protection comprises an input protection layer and an operation protection layer; s4, threat linkage response: if a hostile attack is detected in the step S3, a threat event is encrypted and reported to a security policy management center, and the management center dynamically updates a CSP policy and a sensitive operation verification rule; and S5, global strategy optimization: the management center counts and analyzes threat logs, and automatically adjusts a default strategy of high-risk routing. Through dynamic security policy generation, context-aware semantic analysis and a multi-layer protection linkage response mechanism, a self-adaptive and deep front-end security protection system is constructed.
Owner:GENERATION TIMES TECHNOLOGY (SHANGHAI) CO LTD

A digital tag-based file leakage prevention and traceability evidence system

ActiveCN117675373BSolve the problem of easy leakageEasy to detectSecurity policy managementAsset (computer security)
The application discloses a file anti-leakage and traceability evidence system based on a digital label, and relates to the technical field of computer security. The system comprises a terminal agent unit and a behavior audit center, the terminal agent unit is connected with the behavior audit center through a network to complete information interaction, the terminal agent unit is arranged on each terminal computer in a local area network, and through label embedding, label verification, behavior audit and access control on intranet files, fine-grained access control and behavior audit of the intranet files based on label attributes are realized; the behavior audit center is arranged on a local area network background server, receives file attributes and label information reported by the terminal agent unit, realizes intranet file asset presentation, digital label management, security policy management and behavior log audit, realizes comprehensive presentation of file behavior situation and threat prediction based on artificial intelligence technology, and realizes automatic threat disposal according to preset security policies.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP

Centralized security policy administration using NVMe-oF zoning

Systems and methods extend Non-Volatile Memory express over Fabric (NVMe-oF) zoning to enable security policy administration and authentication of NVMe-oF entities in a centralized manner without requiring per-connection provisioning administered by a Centralized Discovery Controller (CDC). In various embodiments a zone configuration is defined that represents access control rules, which determine which entities can connect with each other, and that may be augmented by specifying in a zone attribute whether members of a zone should authenticate or authenticate and establish a secure channel between themselves. Each entity may be configured with a per-entity global security policy that comprises a security credential and that enables an authentication and / or a secure channel communication between entities. Once an entity issues a Get Log Page request to the CDC to discover other entities, the CDC may provide a list of such entities and specify whether authentication and / or secure channel communication should be performed.
Owner:DELL PROD LP

Security enhancement methods and systems for the IEC 104 protocol on the master station side of power monitoring systems

PendingCN122339686AIEC 62351Embedded system
This invention discloses a security enhancement method and system for the IEC 104 protocol on the master station side of a power monitoring system, comprising: generating input data, dynamically selecting a security mode and issuing configuration commands, generating original ASDU messages, calling application-layer security plugins to generate enhanced ASDU messages, encapsulating them into complete APDUs, generating security messages via transport-layer security plugins, and sending them to the station. This invention adopts a plug-in embedded architecture, integrating IEC 62351-5 application-layer and IEC 62351-3 transport-layer security plugins into the protocol processing module and communication processing module respectively, achieving decoupling of security functions and business functions; establishing a policy-driven mechanism, adding a security policy management module and an operation monitoring module, and providing port differentiation to adapt to different terminals to meet the needs of gradual transformation; controlling terminal concurrent connection latency at the millisecond level to meet the needs of large-scale high-concurrency access at the master station, and establishing a layered security protection system that coordinates the transport layer and application layer, ensuring message security even if transport layer security fails.
Owner:NARI NANJING CONTROL SYSTEM CO LTD +1

Face recognition building intercom system based on VOIP encryption transmission

The invention discloses a face recognition building intercom system based on VOIP encryption transmission, and relates to the technical field of building intercom communication, the system comprises an entrance machine, an indoor machine and a management platform, the entrance machine is integrated with a network state sensing module, a security policy management module, a biological characteristic key generation module and a human body posture recognition model, the entrance machine collects a face image and completes preliminary recognition, the biological feature key generation module extracts feature factors from the face image and dynamically generates a unique encryption key, the security policy management module switches encryption policies such as a ChaCha20 stream cryptographic algorithm and an AES-256 algorithm according to a call stage and network quality parameters, and the security policy management module carries out encryption on the face image. The redundancy error correction strategy is dynamically adjusted based on the data packet priority and the network condition, the management platform is responsible for coordinating system operation, storing logs and pushing strategy suggestions, dynamic balance of communication safety, real-time performance and reliability is achieved, system energy consumption is reduced, user privacy is protected, and the method is suitable for application scenes with complex network conditions.
Owner:SHENZHEN SKYRISE TECH CO LTD

Unified secure access control to software services and applications

Methods and systems of access control to enterprise applications. Embodiments of the invention implement a unified secure access control solution to enable users to securely authenticate with applications no matter whether they are hosted in SAAS cloud or private networks. Intelligence Edge Gateways deployed at a network edge close to users' geographical locations ensure the control of users' secure access to software services and applications with minimized latency. A user only needs one set of credentials to gain access to various applications hosted in SAAS cloud or private networks. In an embodiment, Intelligence Edge Gateways enables IT administrators to set data plane level security policies in addition to the identity and access management policies. IT administrators are able to configure and manage all the security policies at Unified Access Cloud in a centralized manner.
Owner:SPLASHTOP INC

Security policy management

PCT designated stageWO2026075712A3Natural language translationDigital data information retrievalEngineeringSecurity policy management
In various examples, input queries (e.g. open user queries) are used combination with predefined queries to perform security policy-related actions using a generative machine learning (GML) model or GML models. In one example, an input query relating to a security policy is matched with a predefined query stored in an instruction database. In some examples, the instruction database contains examples of structured configuration data, which in turn can be used by a GML model to configure a predetermined extractor code module to perform a specific policy-related action. In other examples, a security context relating to a security policy is used together with an input query and template query to generate a GML model query. In some examples, the two approaches are combined.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

An API behavior prediction and security policy management method based on machine learning

The application provides an API behavior prediction and security policy management method based on machine learning, relates to the field of computer network security, and comprises the following steps: acquiring API original data in real time, preprocessing the original data to obtain preprocessed original data, acquiring API dimension features in real time based on the preprocessed original data, and fusing to obtain unstructured data; a dynamic characteristic validity verification rule is established to preprocess the unstructured data, and a unified dimension standardization feature tensor is obtained; the joint modeling of API behavior space-time features is performed through the collaborative architecture of a multi-head time attention mechanism and a dynamic graph neural network, API behavior prediction is performed, API dynamic security management and control strategies are generated in real time through a strategy engine, strategy execution is performed, the security strategy execution effect is monitored in real time, and iterative optimization is performed. The application solves the problems of fixed and rigid security management and control strategies of a traditional API gateway, and the difficulty in dynamically adjusting security strategies according to real-time access conditions and behaviors.
Owner:应急管理部大数据中心 +1

Methods and systems for protecting a secured network

Methods and systems for protecting a secured network are presented. For example, one or more packet security gateways may be associated with a security policy management server. At each packet security gateway, a dynamic security policy may be received from the security policy management server, packets associated with a network protected by the packet security gateway may be received, and at least one of multiple packet transformation functions specified by the dynamic security policy may be performed on the packets.
Owner:CENTRIPETAL NETWORKS INC

Container behavior supervision method and device based on priority

The invention relates to the technical field of container safety, and provides a priority-based container behavior supervision method and device. The method comprises the following steps: determining a mirror image priority according to a mirror image construction file; appointing a corresponding Seccomp strategy according to the mirror image priority; a mapping relation between the mirror image priority and the Seccomp strategy is established; obtaining a Seccomp strategy according to the mapping relation, and starting a container by using the Seccomp strategy; and monitoring a Seccomp event triggered by the container process, extracting a system calling behavior and performing structured recording to generate a structured log. According to the method and the device, dynamic security policy management based on the mirror image risk level is implemented on the container operation authority, and the problems of relatively low security, isolation and traceability during container operation in the prior art are solved.
Owner:709TH RESEARCH INSTITUTE CHINA STATE SHIPBUILDING CORP LTD

Computer network information security monitoring system and use method

The invention relates to the technical field of computer systems, and provides a computer network information security monitoring system and a use method, and the system comprises an infrastructure and data collection module, a deep learning analysis module, a reinforcement learning strategy optimization module, a security strategy management module and a visual operation and maintenance and decision support module. The infrastructure and data acquisition module is responsible for collecting and transmitting data, the deep learning analysis module is used for identifying abnormal behaviors and predicting threat trends, the reinforcement learning strategy optimization module optimizes security strategies through autonomous learning, and the security strategy management module adjusts protection measures according to the optimization strategies. And the visual operation and maintenance and decision support module provides a visual system state view to assist operation and maintenance personnel to make decisions. According to the invention, through combination of deep learning and reinforcement learning technologies, active protection is realized, functions of firewall dynamic configuration, visual operation and maintenance, decision support and the like are provided, and comprehensive and efficient safety protection services are provided for users.
Owner:TIANJIN YIBU TECHNOLOGY CO LTD

Security policy management

PCT designated stageWO2026075712A2TransmissionSpecial data processing applicationsEngineeringSecurity policy management
In various examples, input queries (e.g. open user queries) are used combination with predefined queries to perform security policy-related actions using a generative machine learning (GML) model or GML models. In one example, an input query relating to a security policy is matched with a predefined query stored in an instruction database. In some examples, the instruction database contains examples of structured configuration data, which in turn can be used by a GML model to configure a predetermined extractor code module to perform a specific policy-related action. In other examples, a security context relating to a security policy is used together with an input query and template query to generate a GML model query. In some examples, the two approaches are combined.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Security event global visualization and security policy management method based on situation awareness platform

The invention discloses a situation awareness platform-based security event global visualization and security policy management method. The visual situation awareness platform comprises a situation analysis and large-screen display system, a big data and artificial intelligence system, a security information and event management system, a security monitoring system and an automatic response system. Internal and external information is integrated through the situation awareness platform, a global security view angle is provided, security managers are helped to quickly understand the security situation, and the security management efficiency is improved. Intelligent identification and analysis of security threats are realized, and the intelligent level of security defense is improved. According to the dynamic defense strategy based on situation awareness, defense measures can be adjusted according to actual security threats, the defense capability, visual display and rapid analysis of situation awareness of enterprises on novel attacks are enhanced, the time of the enterprises from finding the security threats to taking the defense measures is greatly shortened, and the response speed of security events is increased.
Owner:HUADI COMP GROUP