Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

103 results about "Security properties" patented technology

Method and system for analyzing embedded systems

Method and system for analyzing software or firmware of computing systems to assess security properties includes loading predicate device input data including characteristics about predicate devices; translating predicate device input data into predicate device model data describing characteristics or dependencies of the predicate device input data relevant to the analysis; determining digital twin configuration data used to configure digital twin; loading the digital twin configuration data onto the digital twin; storing configuration data in the memory; instructing the digital twin to configure itself to implement the loaded digital twin configuration data; determining security analysis to be carried out on the digital twin; simulating the predicate device; executing security analysis on the digital twin; generating output data describing the result of execution of the security analysis; storing output data pertaining to the result; and determining if the result satisfies a predetermined condition, and if so, executing action corresponding to the result.
Owner:OBJECTSECURITY LLC

Test case sample cutting method, device and system and storage medium

The embodiment of the invention provides a test case sample cutting method, device and system and a storage medium, and relates to the technical field of network security testing. The method comprises the following steps: constructing an industrial control system attack tactical library; wherein the tactical library comprises classified and arranged attack techniques and corresponding security attributes; performing information analysis and semantic analysis on the test case sample to generate structured data of the test case sample and / or function points in the test case sample; and cutting the test case sample according to the security attribute and / or the structured data and / or the function point to obtain a test fragment corresponding to the security attribute and / or the function point. According to the method, classification-based attack techniques and security attributes are cut by constructing a tactical library, key information can be accurately extracted and test intentions can be understood through information analysis and semantic analysis, redundant tests are avoided, cut test fragments can concentrate on specific security attributes or function points, the test coverage range is more accurate, and the test efficiency is improved. And the distributed security test effect is improved.
Owner:STATE GRID SHANDONG ELECTRIC POWER CO +2

Method for automatic detection and remediation of security posture in web-applications using large vision models

A method for automatic detection and remediation of security posture in web-applications using large vision models is fulfilled in the ongoing description by (a) initiating a headless browser as an agent to access an administrative section of a web-application, (b) enabling a pre-trained large vision model to navigate through a web user-interface of the web-application using a state transition graph, (c) determining subsequent navigation actions of the navigated web-user interface using screenshots of the navigated web-user interface with the large vision model, (d) detecting and analyzing a final state of navigation sequence of the administrative section to extract security attributes, (e) monitoring and collecting data associated with security posture of the web-application based on the security attributes, and (f) initiating automated corrective actions through a security posture remediation module upon identifying a security issue in the web-application.
Owner:REDBLOCK SECURITY INC

Artificial intelligence-enhanced database security systems and methods using semantic data proxies

Exemplary embodiments for data security include a data access proxy coupled with a database, further coupled with a server configured to operate the data access proxy to: identify a user and request to access a data item; validate the user and request, including inspecting the user's identity, evaluating the user's history, and evaluating permissions and restrictions associated with the user and the data item; access the database to retrieve the data item; inspect security attributes related to the data item; and transform the data item based on one or more privacy rules, including redacting the at least one data item, deleting information from the at least one data item, substituting information from the at least one private data item with other information, adding information to the at least one data item, providing synthetic data as a private data item, or providing proxy data for the data item.
Owner:DYMIUM INC

Trust-based crowd sensing distributed privacy protection method and system

The invention belongs to the technical field of crowd sensing, and discloses a trust-based crowd sensing distributed privacy protection method and system, and the method comprises the steps: constructing a detailed reputation evaluation system, covering the calculation of a reputation value and the setting of a reputation threshold value of a participating user, and integrating a game model in an evaluation stage, the user is guided to avoid malicious behaviors through an income incentive mechanism so as to obtain higher income; a dobby machine model is introduced to dynamically balance the decision-making process of'exploring 'new users and'utilizing' high-reputation users, so that the cold start problem of insufficient reputation of the new users is effectively solved; and finally, verifying the security of the scheme through theoretical derivation of the security attribute of the scheme, verifying the validity of the scheme in the aspects of data credibility, privacy protection effect and the like in combination with experimental analysis, and providing support for credible operation and privacy protection of the crowd sensing system.
Owner:GUIZHOU UNIVERSITY OF FINANCE AND ECONOMICS +1

Enabling large frames for secure virtual machines

The computer-implemented methods, computer program products, and computer systems include computer operations that include executing, in a trusted computing environment, a call from a host in an untrusted computing environment, where the call is to determine a status of a large page of memory for use by a secure guest, where the secure guest is managed by the host in the untrusted computing environment. The executing includes determining that all small pages comprising the large page and the large page meet pre-defined security requirements. The executing also includes, based on the determining, setting security properties of the large page and the small pages comprising the large page to enable translation for the large page for a given block of memory of the secure guest. The executing also includes storing in a computing element, a designation identifying the large page as belonging to the secure guest.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION +1

Road cargo transportation management method and system based on electronic waybill

The invention discloses a road cargo transportation management method and system based on an electronic waybill, and relates to the technical field of the Internet of Things, and the method comprises the steps: carrying out the real-time collection and comparison of transportation data and a safety domain through a vehicle-mounted OBD device and a roadside RFID reader-writer according to a digital twinborn body updated for the first time and a safe passing time-space map, and carrying out the real-time collection and comparison of the transportation data and the safety domain; when a composite anomaly is detected, the digital twin state is updated, and a third-level alarm code is triggered; and according to the five-dimensional auditing report, splitting the transportation attribute and the security attribute, respectively anchoring the transportation attribute and the security attribute to a transportation chain and a security chain, and generating a verifiable cross-chain evidence packet through a cross-chain relay technology. According to the method, the transport attributes and the security attributes are split and anchored to the transport chain and the security chain respectively, and the MPT tree is constructed to generate the double-chain consistency proof, so that joint auditing under data sovereignty separation is realized, and the collaborative response time of multiple departments is shortened; a tamper-resistant evidence chain is formed from waybill initialization, security domain implantation to final audit destruction.
Owner:WUXI XINFENGLAI STAINLESS STEEL CO LTD

Book resource data security collection retrieval monitoring system based on big data

The invention discloses a book resource data security collection retrieval monitoring system based on big data, and relates to the technical field of information technology and data security, and the system comprises a permission-aware association reasoning retrieval module which is in communication connection with a knowledge graph and dynamic index construction module and is used for receiving a user retrieval request and sending the user retrieval request to a database; analyzing a retrieval intention and obtaining a real-time permission context of a user to determine a security level threshold value, verifying a security attribute voucher of the data when retrieving the mixed index, only putting the data with the security level not higher than the threshold value into a result set, and performing association reasoning based on the knowledge graph under permission constraint to expand a result. According to the method, the mixed index structure fusing the inverted index, the vector index and the graph index is constructed, the security attribute voucher is associated, efficient full-text retrieval, semantic retrieval and association reasoning are supported, meanwhile, it is ensured that the retrieval process and result are strictly constrained by permission, and maximum mining of data values on the premise of security is achieved.
Owner:GUANGDONG POLYTECHNIC OF IND & COMMERCE

Business security policy generation method, apparatus, device, and storage medium

The present disclosure provides a business security policy generation method, device, equipment and storage medium, which can be applied to the field of information security technology and the field of financial technology. The business security policy generation method comprises: in response to receiving business data, generating a security attribute table based on the data type of the business sub-data included in the business data; determining target attribute data from a plurality of attribute data included in the security attribute table; determining a risk policy corresponding to the target attribute data from a preset risk database, wherein the preset risk database comprises an association relationship between the target attribute data and the risk policy; and determining a business security policy model based on the risk policy and a target processing policy corresponding to the risk policy.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Dynamic attachment of secure properties to machine identity with digital certificates

Technology is shown for dynamically attaching secure properties to an identity certificate. Claims determining secure properties for an identity are signed and embedded in an identity certificate. Both the identity certificate and the signed claims in the certificate are verified. When a service request is received from the identity, the signed claims from the identity certificate are checked to determine if the request is permitted. If the request is permitted, then the service request is processed. Some examples involve creating claims determining the secure properties for the remote machine, signing the claims to create the signed claims, distributing the signed claims to a certificate authority, embedding the signed claims in the remote machine identity certificate, and distributing the remote machine identity certificate. The claims can be embedded in the certificate as X.509 properties.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Secure cloud computing architecture and security method

A secure cloud computing architecture including: a first data management and / or computer program execution space (A) in which the data management or program execution is controlled by a user; and a second data management and / or computer program execution space (B) in which the data management or program execution is controlled by a third-party operator, first security policies (PSA) applied to the data or execution of programs in the first execution space (A); second security policies (PSB) applied to the data or execution of programs in the second execution space (B); a security property (P) expected by the user, compliance with the first and second security policies guaranteeing a data management and / or computer program execution in accordance with this property (P); and a trusted computing base (TCB) guaranteeing, in the absence of a violation, the application of the second security policies (PSB) in the management of the data and / or execution of the programs in the second execution space (B).
Owner:PROVE&RUN

Privacy protection and traceable anonymous bidirectional authentication method for heterogeneous Internet of Vehicles

The invention discloses a privacy protection and traceable anonymous bidirectional authentication method for heterogeneous Internet of Vehicles, which comprises the following steps: generating public and private keys based on a key generation center, a private key generator and a trusted registration mechanism, and constructing a heterogeneous password system; the vehicle completes key registration by fusing the certificateless public key system, and the roadside unit completes key registration based on the identity public key system; the vehicle registers and uses the pseudonym to communicate with the roadside unit; and the vehicle and roadside unit bidirectional authentication verifies the legality of the opposite side through a hash function and a temporary value, and finally generates a session key. According to the invention, by providing traceable pseudonym and anonymous authentication communication for each vehicle, the privacy of the vehicle can be effectively protected, and an attacker can be prevented from tracking the identity information of the vehicle. Based on various security hypotheses, the method meets various security attributes including anonymity, unlinkability, perfect forward security, security of known temporary information specific to sessions and the like, and the security of data transmission of the Internet of Vehicles can be improved.
Owner:BEIJING UNIV OF TECH

Method and apparatus for data access control

A method, device, equipment and storage medium for data access control are provided. The method described herein comprises: receiving a data query request for characterizing a first user's request for target data; obtaining a business data access capability attribute corresponding to the first user and obtaining a business security attribute corresponding to the target data; calling a data access security model to determine a data query processing strategy corresponding to the data query request according to the business data access capability attribute of the first user and the business security attribute of the target data; and calling the data query processing strategy to process the target data and generating a response message for feedback. According to the fact of the present disclosure, by providing a response to the request based on the business data access capability attribute of the user and the business security attribute of the target data, the access of the user to the data can be effectively controlled.
Owner:DOUYIN VISION CO LTD

Module security protection system and method, computer equipment and storage medium

The invention provides a module safety protection system and method, computer equipment and a storage medium, the system comprises a plurality of main control modules and a plurality of safety gate modules, and each safety gate module corresponds to an internal module; each master control module is used for initiating an access request to the internal module, and the access request carries a hardware identity label and an access security attribute of the master control module; each security gate module is used for receiving the access request and carrying out legality verification on the hardware identity identifier and the access security attribute based on a pre-configured security rule; and each security gate module is also used for allowing access to the corresponding internal module when the hardware identity identifier and the access security attribute pass verification, or blocking the access request. By adopting the scheme, illegal access can be accurately resisted, the data security of the internal module is protected, and the protection capability is improved.
Owner:CIX TECH (SHANGHAI) CO LTD

Data storage method, private cloud device and medium

The invention discloses a data storage method, private cloud equipment and a medium, and relates to the technical field of cloud resource data storage, the method is used for the private cloud equipment, and the method comprises the following steps: obtaining a data file and configuration information sent by a terminal; wherein the configuration information comprises authority information corresponding to a plurality of storage resources; the storage resource comprises at least one of a public cloud server, a private cloud server and private cloud equipment; under the condition that the received configuration information comprises the storage resource of the data file, sending the data file to the storage resource according to the security attribute of the data file and the authority information corresponding to the storage resource; wherein the configuration information further comprises security attributes of the data file; storing a storage record of the storage data file to the private cloud equipment; wherein the storage record comprises a storage resource to which the data file is sent. The method has the advantages that data management is convenient, user operation is non-inductive, and storage resources are expanded.
Owner:YICI NETCOM (HANGZHOU) TECH CO LTD

Operation ticket electronization and process automation method and system

The invention relates to the technical field of operation permission management, in particular to an operation ticket electronization and process automation method and system. Comprising an operation ticket data acquisition unit; a ticket template configuration and electronic generation unit; a process automation scheduling and execution unit; and an approval and authority verification unit. According to the invention, through deep linkage of a personnel positioning function and approval process circulation, the on-duty state of the approval personnel and the security attribute of the area where the approval personnel are located can be captured in real time; and dynamically adjusting the trend of the approval process and the substitution qualification of related personnel according to the information, namely automatically skipping the substitution qualification of the approval personnel in an operation dangerous area, and starting a substitution matching process for the approval personnel in a safe area. The method effectively avoids the stagnation of the examination and approval process caused by the fact that the examination and approval personnel are out of duty or cannot perform duty in a dangerous area, and fully meets the actual demands of flexible adjustment of the examination and approval process in a complex operation scene.
Owner:BEIJING HUAXIA ZHIBANG TECH CO LTD

Context-aware security policies and incident identification via automated cloud graph building with security overlays

Context-aware security policies and incident identification, via automated cloud graph building with security overlays, are determined and performed by systems and platforms. Graph nodes, of a graph associated with a computing system, that represent resources associated with the computing system and entities associated with the computing system that have respective associations to the resources are generated. Security attributes are determined and assigned to the graph nodes that represent the entities and resources, and static and dynamic connections between the graph nodes are added to the graph. Additionally, possible connections in the graph between the graph nodes are added based on heuristic relational determinations of the graph nodes. From the graph, security incidents and kill chains are identified, context-aware security policies are generated and validated, and scopes and relationships of applications are identified. Accordingly, security actions are taken for the computing system.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Generating synthetic signals by a security analytics platform

A response to a request initiated by a client is received by a processing device of a reverse proxy from an application of a plurality of applications associated with a specified entity. A header of a predefined type is identified within the response. One or more metadata items characterizing one or more security features of the application are retrieved from the header. An updated response is produced by removing the header from the response. The updated response is forwarded to the client. One or more synthetic signals characterizing security properties of the application is generated based on the one or more metadata items. The one or more synthetic signals is stored in a memory of a security analytics platform.
Owner:GOOGLE LLC

Government affair data classification and grading method

The invention discloses a government affair data classification and grading method, and relates to the technical field related to data government. Comprising the steps that 1, government affair data resource directories are sorted, and the sorted content comprises the names of the data resource directories, the departments of the data resource directories, the abstracts of the data resource directories, field names and example data; step 2, classifying the government affair data: according to attributes or features of the government affair data, distinguishing and classifying the government affair data according to preset rules and methods, and establishing a classification system and an arrangement sequence; 3, grading the government affair data: dividing the government affair data into four security levels according to influence objects and influence degrees caused after the security attributes of the government affair data are destroyed, the four security levels are a fourth level, a third level, a second level and a first level from high to low, and triggering any level to reach the corresponding lowest security level; and 4, outputting a government affair data classification and grading ledger: outputting the government affair data classification and grading ledger based on the government affair data resource basic ledger and the established data classification and grading standard.
Owner:浪潮智慧城市科技有限公司 +1

A hardware design security vulnerability qualitative analysis method and system

ActiveCN116484385BPlatform integrity maintainanceComputer hardwareSecure by design
The application discloses a hardware design security vulnerability qualitative analysis method and system, according to a mixed attribute label propagation logic element library and a mixed attribute model construction method based on discrete mapping, so that a corresponding mixed attribute model can be constructed for any HDL design in linear time; the label designed by the mixed attribute model integrates two types of attributes, so that the safety behavior related to the safety attribute and the clock attribute can be modeled simultaneously; the method provided by the application can realize effective discrimination of hardware Trojan horses and hardware time measurement channels by verifying the clock attribute and the safety attribute; the application is deployed in the design and verification stage of the EDA process, so that the HDL design security vulnerability can be detected early, and the design basis is provided for high-reliability hardware design.
Owner:XIAN TECH UNIV

Business process-oriented data processing method and device, equipment, storage medium

This invention relates to the field of artificial intelligence technology and discloses a data processing method, apparatus, device, and storage medium for business processes. The method includes: semantically registering each basic tool to obtain a tool capability catalog; parsing the target business process text to obtain a skill script, where the target business process text contains the business process; compiling the skill script based on the tool capability catalog to obtain a tool call graph; wherein, basic tools serve as nodes in the tool call graph, and the data flow relationships between basic tools serve as edges in the tool call graph; integrating information based on the security attribute information of the nodes to obtain a skill-level capability contract text used to constrain the business process; and executing the business process based on the tool call graph and the skill-level capability contract text. This method can be applied to process processing scenarios in fintech and healthcare, improving the execution efficiency of business processes.
Owner:PING AN TECH (SHENZHEN) CO LTD

A three-factor and puf-based vehicle and drone authentication method

PendingCN122661739AProtect against stolen attacksImprove the immunityEdge serverUncrewed vehicle
The application discloses a vehicle and unmanned aerial vehicle authentication method based on three factors and PUF, and comprises the following steps: S1, system initialization is completed by an edge server and a consortium chain network; S2, the unmanned aerial vehicle and the vehicle are registered respectively, and initial trust binding between the vehicle, the unmanned aerial vehicle and the edge server is completed; S3, in an online stage, the vehicle sends an access request to the edge server, the edge server sends authentication information to the unmanned aerial vehicle after verification, the unmanned aerial vehicle generates a response after verification, and a shared session key SK is obtained by negotiation between the vehicle and the unmanned aerial vehicle; and S4, after successful completion of authentication, the edge server calls an intelligent contract interface, and metadata of an authentication event is written into a consortium block chain. The application can realize two-way identity authentication and session key negotiation between the vehicle, the edge server and the unmanned aerial vehicle in a single-domain scenario of a low-altitude logistics park, and can guarantee multiple security attributes while controlling online authentication calculation overhead at a low level.
Owner:NANJING UNIV OF INFORMATION SCI & TECH

Resource processing method and apparatus, electronic device, and readable storage medium

Embodiments of the present application provide a resource processing method and device, electronic equipment and readable storage medium, in response to the target load sent resource processing request, obtain the target security attribute data corresponding to the to-be-processed resource indicated by the resource processing request; the target security attribute data includes a domain attribute field and a processing permission field; in the case of matching between the domain attribute field and the current execution mode corresponding to the target load, execute the resource processing request; in the case of not matching between the domain attribute field and the current execution mode corresponding to the target load, and the permission bit field in the control state register is the first value, if the processing permission field matches the resource processing operation corresponding to the resource processing request, execute the resource processing request. In this way, the flexible resource processing mode can improve the flexibility of resource processing request processing on the basis of maintaining resource security isolation, so that the system can better adapt to the operation requirements in different scenarios.
Owner:BEIJING INSTITUTE OF OPEN SOURCE CHIP

A processor branch prediction attack vulnerability formal verification method

This invention discloses a formal verification method for processor branch prediction attack vulnerabilities, comprising the following steps: S1, establishing the security attributes violated by the branch prediction attack, wherein the security attributes describe the security specifications that a secure branch predictor design should comply with; S2, establishing a branch prediction behavior model, describing the branch prediction attack as a combination of a series of abstract branch operations; wherein the branch operation is a quintuple consisting of operator, operation type, operation address, jump direction, and jump address, which is an abstract representation of a certain branch instruction; S3, modeling the branch predictor design as accepting branch prediction behavior instructions, and designing different variations of the branch prediction model state machine according to different input instructions, outputting the prediction result, checking the security specifications, and converting the branch prediction attack into a path specification on the state machine; S4, performing model verification on the state machine of the branch predictor design to determine whether it has a branch prediction attack vulnerability.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Network adaptive management system based on dynamic network security

The application belongs to the field of network security management, relates to data analysis technology, and is used for solving the problem that the prior art cannot linearly track from the perspective of an operation user and overall risk assessment of short-term behavior of the same network user, and particularly relates to a network adaptive management system based on dynamic network security, which comprises a behavior monitoring module, a security analysis module and a risk analysis module connected in sequence in communication, and the behavior monitoring module, the security analysis module and the risk analysis module are all connected in communication with a database; the application can finely and weightedly quantitatively evaluate the security of each combination element; the evaluation method fully considers the differentiated influence of different security attributes such as permission, privacy and network fluctuation on the security of network behavior, so that the finally calculated security coefficient of the combination element is more representative and accurate.
Owner:GUANGZHOU SIYUN DATA TECH CO LTD

Action based on pre-implementation determination whether a proposed role assignment associated with a role hierarchy conforms to security properties

Techniques are described herein that are capable of performing an action based on a pre-implementation determination whether a proposed role assignment associated with a dynamic role hierarchy conforms to security properties. Role assignments, assigning roles to principals, and a proposed role assignment are identified. Impacted role assignments are selected from the role assignments. A static policy, which is defined by the impacted role assignments and the proposed role assignment, is generated. The static policy is converted into a first logical artifact. A specification and a relationship property are converted into a second logical artifact. The specification includes security properties defining boundaries of allowed actions and disallowed actions. The relationship property defines a relationship between the specification and the static policy. Prior to implementation of the proposed role assignment, the first and second logical artifacts are compared to determine whether the proposed role assignment conforms to the security properties.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

A method for airborne software security modeling and automated testing

The embodiment of the application provides a kind of airborne software security modeling and automated testing method, comprising: according to the field of airborne software, the security property description required for security testing is extracted using security property extraction module, while the SysML model is designed, the XML file of SysML model and security property description are uploaded to model automatic expansion module;Model automatic expansion module is expanded according to the uploaded security property description XML file of SysML model, and the node type and path information of SysML model are supplemented, to generate the extended model;Test case automatic generation module generates the comprehensive test path and test data of the extended model according to the extended model output by model automatic expansion module. Since the scheme adds security testing through security property extraction module, model automatic expansion module and test case automatic generation module, the efficiency of test case generation is improved.
Owner:BEIHANG UNIV

Data storage method and device, equipment and storage medium

The embodiment of the invention provides a data storage method and device, equipment and a storage medium. The method specifically comprises the steps that the security attribute of to-be-stored data is obtained in real time; the security attributes comprise a data volume, a data security level, a data access frequency and a medium security level of the current storage medium; inputting the security attribute into a preset risk assessment model, and obtaining a security risk value and a security capacity threshold value output by the risk assessment model; under the condition that the security risk value exceeds a risk migration threshold value, determining a target security level according to the security risk value and a security capacity threshold value; wherein the risk migration threshold value is determined according to the safety capacity threshold value; and migrating the to-be-stored data to a target storage medium corresponding to the target security level for storage.
Owner:PICC INFORMATION TECH CO LTD

System and method for securing indirect memory accesses

An integrated circuit (IC), including a functional circuit and a security system, is disclosed. The functional circuit generates a request packet for an indirect memory access of a memory. The security system validates the functional circuit based on a security attribute and a functional identifier of the functional circuit. Based on the request packet and the validation of the functional circuit, the security system identifies an instruction sequence associated with the indirect memory access. Further, the security system determines a type of the indirect memory access based on the instruction sequence, and validates the type of the indirect memory access based on the security attribute and the request packet. Based on the validation of the type of the indirect memory access, the instruction sequence is executed, thereby facilitating the indirect memory access for the functional circuit.
Owner:NXP BV

Distribution method of DHCP (Dynamic Host Configuration Protocol) fixed address

The invention discloses a DHCP (Dynamic Host Configuration Protocol) fixed address allocation method, which solves the problems of high maintenance cost, lack of flexibility, insufficient security and strategy stiffness in the prior art. The method comprises the following steps: receiving a DHCP Discover message which is sent by terminal equipment and carries an expansion option field null mark; a dynamic voucher management module is utilized to generate a dynamic voucher in response to the DHCP Discover message, a DHCP Offer message is sent to the terminal, and the DHCP Offer message comprises the dynamic voucher and a short-tenancy temporary IP; wherein the dynamic voucher management module is preset in a DHCP (Dynamic Host Configuration Protocol) server; the dynamic voucher is contained in an extended option field of the DHCP Offer message, is generated through a security mechanism, contains a unique identifier of the terminal equipment, and has a security attribute.
Owner:INTERNET DOMAIN NAME SYST BEIJING ENG RES CENT