Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

125 results about "Security rule" patented technology

Insecure model context protocol server remediation for artificial intelligence agents

A system detects changes in model context protocol (“MCP”) processes, and performs a remedial action. A server-sent events (“SSE”) bridge sends a request to an MCP server. A first resource profile is received from the MCP server. This is stored and compared against a second updated version of the resource profile. When a difference is detected, the SSE bridge determines whether to block a resource command from reaching the SSE bridge. The decision is based on comparing the difference to security rules, which can be defined as part of a management profile.
Owner:AIRIA LLC

Public multi-mode cloud network resource software security enhancement method based on neural symbol fusion reasoning

The invention relates to a public multi-mode cloud network resource software security enhancement method based on neural symbol fusion reasoning, which comprises the following steps: an intermediate representation generation stage: generating and optimizing an intermediate representation of a program through a fine-tuned large language model, and establishing semantic mapping from a source code to a structured logic representation; in the symbol language conversion stage, the intermediate representation generated by the large language model is converted into a domain-specific language fact set which can be recognized in the symbol logic reasoning stage, and formal and logic expression of program semantics is achieved; and a symbol logic reasoning stage: matching the fact set with the rule base through a symbol logic reasoning engine, performing detection and verification according to the safety rule, generating a structured report, and feeding back a result for optimization. The method is suitable for security enhancement of various core software systems in a public cloud network multi-modal network environment, high-precision security analysis is carried out on cross-modal and cross-subsystem fragmented codes in a compiling-free environment, and verifiable technical support is provided for public cloud network security control.
Owner:PEKING UNIV

Ensuring model context protocol server integrity for artificial intelligence agents

A system detects changes in model context protocol (“MCP”) processes, and performs a remedial action. A server-sent events (“SSE”) bridge sends a request to an MCP server. A first list of resource profiles, including tools and instructions, is received from the MCP server. This is stored and compared against a later list of tools and instructions. When a difference is detected, a user interface can display the difference to an administrator. Security rules cause the SSE bridge to be blocked from sending commands to the impacts tool or MCP server until approved by the administrator.
Owner:AIRIA LLC

Proxy-based secure model context protocol server access for artificial intelligence agents

A gateway securely executes model context protocol (“MCP”) processes for artificial intelligence (“AI”) agents by creating nano sandboxes in which the MCP processes execute. A server-sent events (“SSE”) bridge identifies a request to initialize an SSE channel with an MCP server, the request being sent from an MCP client that generates MCP-compliant commands in association with an AI agent. The SSE bridge instantiates a nano sandbox based on a definition extracted from the request, creating a custom and dynamic isolated execution environment. An MCP process is launched within the nano sandbox. The SSE bridge returns a session identifier, and receives a command and the session identifier. The SSE bridge authorizes the command and response by applying security rules, blocking either for non-compliance.
Owner:AIRIA LLC

Railway engineering construction potential safety hazard intelligent identification and classification system and method

The invention relates to the technical field of railway engineering construction safety, in particular to a railway engineering construction potential safety hazard intelligent identification and classification system and method. The system comprises a multi-source heterogeneous data acquisition module, a 5M1E hidden danger feature deconstruction module, a security rule knowledge base module, a risk reasoning and early warning module, a security tag portrait module and a PDCA-SDCA dual-cycle management module. According to the method, a construction site can be comprehensively perceived through multi-modal data, hidden danger characteristics are deeply analyzed based on six dimensions, namely Man, Machine, Material, Method, Envirant and Measurement, of 5MIE, risk reasoning and early warning under a complex scene are realized by using a graph neural network, hidden danger rectification closed loop and knowledge base continuous optimization are realized through double-cycle management, and the method and the system have the advantages that the construction site can be comprehensively perceived, so that the construction efficiency is improved. And the intelligent level and long-term learning ability of railway engineering construction safety management are obviously improved.
Owner:INST OF COMPUTING TECH CHINA ACAD OF RAILWAY SCI +2

Truss robot rehearsal control method based on digital twinning

The invention discloses a truss robot rehearsal control method based on digital twinning, and the method comprises the following steps: S1, constructing a truss robot digital twinning system, including constructing a truss robot virtual scene and constraint, performing data synchronization and bidirectional communication, and configuring a safety rule base and a data recording / playback interface at a twinning end; s2, rehearsing a task to be executed, generating a reference trajectory and a constraint set, and automatically checking the rehearsing process according to the safety rule base to obtain the reference trajectory and the constraint set which pass the rehearsing; and S3, performing parameterized predictive control and real-time tracking on the rehearsed reference trajectory and the constraint set, and controlling a trajectory tracking error to be within a tolerance range. According to the method, a digital twin system corresponding to the physical world is constructed, Laguerre function parameterized model predictive control is introduced to realize low-dimensional rapid solution, high-precision, reproducible and high-reliability rehearsal control of the truss robot is realized, and the field debugging and operation and maintenance cost is remarkably reduced.
Owner:SOUTHWEAT UNIV OF SCI & TECH

Intelligent contract vulnerability detection method and system based on semantic comprehension and program path analysis

The invention discloses an intelligent contract vulnerability detection method and system based on semantic comprehension and program path analysis, and belongs to the technical field of network security. The method comprises the following steps: firstly, analyzing an intelligent contract code by using a large language model, and reasoning to generate a structured security rule for defining a taint source, a taint sink and a purifier; secondly, guiding a taint analysis engine by using a security rule, and tracking on a data flow and a control flow diagram of a program so as to efficiently screen out a high-risk taint path; then, carrying out reachability verification on the high-risk path by adopting a symbolic execution technology; and finally, performing final context review on the verified vulnerability path by using the large language model again to generate a vulnerability report. According to the method, the semantic comprehension ability of the large language model and the preciseness of traditional program analysis are subjected to multi-stage cooperation, so that the detection precision and efficiency of the intelligent contract logic vulnerability can be remarkably improved, the interpretability of a report result is greatly enhanced, and the method has important application value.
Owner:ZHEJIANG UNIV +2

Autonomous driving control system based on LLM context reasoning

The invention provides an autonomous driving control system based on LLM context reasoning, and the system comprises an LLM engine module which is used for receiving and analyzing a semantic natural language request, and outputting a semantic map fusing a context reasoning result; the navigation agent module is used for initiating a semantic analysis request to the LLM engine module and initiating a path planning request to the path planner module; the security agent module is used for querying security rules based on a semantic map and dynamically constructing a security feasible area; the path planner module is used for generating and optimizing the optimal driving path of the vehicle through a multi-objective optimization algorithm; the edge controller module is used for converting the optimal driving path into a bottom layer control instruction of an execution mechanism; the interpretation agent module is used for tracking the decision-making process of each module and generating natural language interpretation corresponding to the optimal driving path and the control instruction; the invention aims to adapt to the autonomous driving requirements of different types of mobile devices, and improve the safety, adaptability and user credibility of control.
Owner:HEBEI ZHISHI DATA TECH CO LTD

User identity security in a content management system

Systems and methods for controlling visibility of user identifying information. In the event that documents or records are shared between different business partners or business organizations, usernames appearing on the documents, notification or records may be selectively masked to preserve the user identity security rules.
Owner:VEEVA SYSTEMS INC

Engineering supervision management system and method based on BIM

The invention relates to the technical field of construction management, in particular to a BIM (Building Information Modeling)-based engineering supervision management system and method.According to the BIM-based engineering supervision management system and method, spatial positions and states of construction machinery, vehicles and personnel are captured in real time through a sensor network deployed on site, and a core dynamic spatial conflict calculation module is used for calculating the safety of the construction machinery, the vehicles and the personnel according to a preset safety rule base; and millisecond-level conflict detection and prediction are carried out on the real-time dynamic safety envelope lines of the moving objects. And after potential risks are found, the system sends early warning of different levels from prompting to forced intervention to related personnel, so that a complete management closed loop from active perception and intelligent prediction to co-processing is constructed. Therefore, through pre-virtual simulation and in-process real-time intervention, the risk of major safety accidents such as collision and overturning caused by space conflicts is greatly reduced, and life safety is guaranteed. And by optimizing the construction space and logistics planning, shutdown and rework caused by conflicts are reduced, and the construction efficiency and the project management refinement level are improved.
Owner:CHONGQING DINGXIN CONSTR SUPERVISION CO LTD

Security posture generation using an artificial intelligence (AI) model

A system and method for exploring security rule chains in a security platform. The method includes providing a natural language description of a set of features of a security posture of an organization as a first input to a trained artificial intelligence (AI) model, providing telemetry data pertaining to a computing environment of the organization as a second input to the trained AI model, obtaining one or more outputs from the trained AI model, and extracting, from the one or more outputs, a set of generated features for the security posture of the organization.
Owner:GOOGLE LLC

A metadata model-based code generation method, system and storage medium

This invention discloses a code generation method based on a metadata model, comprising: acquiring a three-layer metadata model of the target application and a preset template file; parsing the three-layer metadata model using a metadata parser to extract data model information, and filling the template file with the data model information to generate an initial code skeleton; calling an AI big model to collaboratively optimize the initial code skeleton to generate target business code; performing dual-engine security verification on the target business code based on a preset security rule base and the AI ​​big model; and outputting the final target code file after the dual-engine security verification passes. This fundamentally overcomes the contradiction between the lack of flexibility in traditional tools and the uncontrollable quality of existing AI-assisted tools, significantly reducing the cost of manual code supplementation and review, and achieving a comprehensive technical effect of cost reduction and efficiency improvement in the rapid construction of enterprise-level applications.
Owner:NINGBO HOLLYSYS INTELLIGENT TECH CO LTD

Method for secure storage of data for an e-commerce management system

PendingCN122508616AE-commerceSecurity rule
The application relates to a secure storage method for e-commerce management system data, comprising the following steps: obtaining e-commerce data and classifying the e-commerce data; generating a data processing rule based on the classification result; deploying a data security agent for intercepting and analyzing an access request to a business database; when a data write request is intercepted, performing encryption processing or desensitization processing by the data security agent and storing the data write request into the business database; when a data query request is intercepted, performing risk assessment by the data security agent and triggering corresponding defense measures; providing a key for the encryption processing and the desensitization processing through a key management system and recording an execution process audit log of the data security agent; through data classification, security rule application and dynamic access control, the application can effectively solve the passive defense problem in the prior art, realize differentiated protection based on data business attributes and sensitivity, and reduce the global performance influence.
Owner:SHENZHEN GLOBALBRANDS TECH CO LTD

Emergency decision method for nuclear power plant, electronic device, and computer storage medium

PendingCN122511653ANuclear plantAlgorithm
The application provides an emergency decision method for a nuclear power plant. The emergency decision method for the nuclear power plant comprises the following steps: obtaining a plurality of state parameters, an accident type and an operation mode of the nuclear power plant; searching for a plurality of corresponding safety clauses in a safety rule library according to the accident type and the operation mode; mapping the plurality of safety clauses into a plurality of first constraints according to a preset mapping rule; calculating a plurality of second constraints according to the plurality of state parameters and an engineering model; and obtaining a safety envelope by combining the plurality of first constraints and the plurality of second constraints, wherein the safety envelope comprises a plurality of constraint inequalities, the plurality of constraint inequalities correspond to the plurality of state parameters one by one, and a target function and a target constraint are established according to the safety envelope to obtain a decision suggestion.
Owner:SHANGHAI NUCLEAR ENGINEERING RESEARCH & DESIGN INSTITUTE CO LTD

System for orchestrated management of identity security functions in container-based multi-cloud environments

System for the orchestrated management of identity security functions in container-based multi-cloud environments, comprehensive an identity data capture unit, trained to capture identity-related security parameters from multiple distributed, container-based computing environments, an orchestration control unit, trained to coordinate the control of identity and access security functions across multiple cloud environments, a policy linking unit, trained to assign safety rules to container-related execution states, and a security enforcement unit trained to execute identity-related security measures within the respective computing environment, the system coordinates identity security functions across environments without imposing a fixed prioritization of individual cloud environments.
Owner:GAHLOT RAKESH EDISON +3

Adaptive video stream code rate decision-making method and system based on neural symbol reinforcement learning buffer area perception

The invention provides a perception adaptive video stream code rate decision-making method and system based on a neural symbol reinforcement learning buffer area, and belongs to the technical field of computer network and multimedia transmission. According to the method, a neural symbol reinforcement learning agent is constructed, a comprehensive state vector is generated by collecting a playing state, video content information and user preference, and double decisions of code rate selection and buffer area adjustment are jointly output; security rules are formalized in a first-order logic mode, security exploration is achieved through a security monitor and a security layer strategy, and illegal risks such as underflow of a buffer area are avoided; the bandwidth prediction precision is improved by adopting HTTP / 3 stable connection sampling and a hybrid prediction model; and designing a multi-target reward function to balance user experience quality and buffer occupation optimization. According to the method, high-video-quality, low-lagging and low-delay transmission can be stably realized in a low-speed to 5G high-speed network, and unnecessary buffer accumulation can be remarkably reduced on the premise of ensuring smooth playing, so that end-to-end delay is reduced.
Owner:GUANGXI UNIV

Experiment design and supervision system and method

The invention discloses an experiment design and supervision system and method, and belongs to the field of artificial intelligence. According to experiment requirements and sample characteristics, an experiment scheme is generated by adopting an experiment model and combining a local knowledge base and internet retrieval content; according to the experiment scheme, an experiment target is disassembled into specific equipment operation instructions, and instrument equipment and a robot are controlled to complete an action sequence; constructing a structured security rule base, processing unstructured information by using a large model, and checking whether the experimental scheme and the operation instruction violate security rules or not; the method comprises the steps of constructing a multi-field ethical rule base, extracting ethical related elements in an experiment scheme, and examining whether the ethical related elements conform to rules or not based on the ethical rule base, so that an experiment task is automatic and intelligent, the experiment efficiency is improved, and the experiment safety and compliance are guaranteed.
Owner:SUZHOU INST OF BIOMEDICAL ENG & TECH CHINESE ACADEMY OF SCI

Insecure model context protocol server remediation for artificial intelligence agents

ActiveUS12683991B1Remedial actionEngineering
A system detects changes in model context protocol (“MCP”) processes, and performs a remedial action. A server-sent events (“SSE”) bridge sends a request to an MCP server. A first resource profile is received from the MCP server. This is stored and compared against a second updated version of the resource profile. When a difference is detected, the SSE bridge determines whether to block a resource command from reaching the SSE bridge. The decision is based on comparing the difference to security rules, which can be defined as part of a management profile.
Owner:AIRIA LLC

An artificial intelligence agent hardware security mode switching apparatus

PendingCN122365601AMask ROMData center
This invention discloses a hardware-triggered security mode switching device and method for artificial intelligence agents, belonging to the fields of G06F21 / 71 and G11C17 / 14. Addressing the shortcomings of existing technologies that rely on software / main control chips, this invention employs an independent hardware module design, including a non-electrically erasable storage structure (such as mask ROM, OTP) for storing a security rule set, a hardware instruction monitoring unit for physically intercepting and parsing instruction streams, a hardware anomaly detection unit for comparing security rules, a hardware security mode triggering unit for generating trigger signals, and a physically isolated security mode execution interface for transmitting signals. The device is completely independent of the agent's main control chip and any externally loadable and modifiable software, ensuring that security mode switching can still be performed even if the main control chip fails or is attacked. This solution effectively prevents the execution of harmful commands sent from data centers, provides hardware-level tamper-proof security protection, 100% resists malicious instruction tampering, and significantly improves the security of artificial intelligence agents.
Owner:SHENZHEN BAIMAXUN NETWORK TECHNOLOGY CO LTD

Mobile terminal management and control method and system based on type-c interface

ActiveCN121786866BImprove borrowing and returning experienceChange physical withdrawalPower distribution line transmissionDigital data protectionWhitelistSecurity rule
This invention belongs to the field of telecommunications technology, specifically relating to a mobile terminal management and control method based on a Type-C interface, comprising the following steps: mobile terminal access, initialization management, mobile terminal borrowing, offline use, and mobile terminal return. When the mobile terminal is accessed, no applications need to be pre-installed; management policies, application installation / uninstallation, and security rule configuration are directly issued via file transfer or protocol commands. When the mobile terminal is used offline, it operates based on a locally pre-built whitelist / blacklist mechanism and an encrypted cache. Upon return, it is automatically and forcibly synchronized to a designated location on the server and then completely cleared from the mobile terminal, effectively ensuring data security. The management system implementing the above management method includes a server, a mobile terminal, and a management device. The management device integrates a main control module, a Type-C physical interface, a USB controller, a data switch circuit, an RFID card scanning module, a network card module, a storage module, and a display and control module.
Owner:XIAN PLAIN NETWORK TECH CO LTD

A method for generating immersive virtual reality training content

This invention relates to the field of virtual reality simulation technology, and more particularly to a method for generating immersive virtual reality training content. The method includes: a step of constructing a domain knowledge graph: extracting atomic knowledge elements representing operational actions, equipment entities, state parameters, and safety rules from standard documents and case libraries of the target training domain, and establishing multi-dimensional logical relationships between these atomic knowledge elements, including causal, temporal, hierarchical, and probabilistic relationships, to form and store the domain knowledge graph; a step of real-time collection of trainee data; a step of constructing and updating a trainee state model; a step of dynamic content decision-making; and a step of generating and injecting non-linear training content. By collecting trainee data in real time and matching it with the knowledge graph, the system can provide trainees with precise feedback after each training session, helping them identify and overcome their knowledge gaps.
Owner:FUJIAN RHINOCEROS INTELLIGENT TECH CO LTD

Managing Artificial Intelligence Inference Requests That Are Directed to An AI Model External To A Distributed Cloud Computing Network

A compute server of a distributed cloud computing network receives an inference request that is directed to an AI model hosted at a destination external to the distributed cloud computing network. The compute server determines that the inference request satisfies security rules associated with the AI model. Upon determining that the inference request is not answerable from a cache, the compute server transmits the inference request to the AI model hosted at the external destination. The compute server receives an inference response from the AI model in response to the inference request, transmits the inference response, and stores the inference request and the inference response in cache.
Owner:CLOUDFLARE INC

A safety protection method and related product

This application discloses a security protection method and related products. The method includes: identifying abnormal behavior in the data to be processed corresponding to a target vehicle based on a preset security rule base and a pre-trained anomaly recognition model to obtain a security recognition result; if the security recognition result indicates a first anomaly level, then performing local security protection on the target vehicle according to a local protection strategy; if the security recognition result indicates a second anomaly level, then obtaining the collaborative protection strategy sent by the cloud platform corresponding to the target vehicle, and performing collaborative security protection with other vehicles according to the collaborative protection strategy. This improves the security of the entire vehicle-to-everything (V2X) environment.
Owner:NEUSOFT REACH AUTOMOBILE TECH (SHENYANG) CO LTD

Passenger seat determination method and device and electronic equipment

The invention discloses a passenger seat determination method and device and electronic equipment, and relates to the technical field of passenger protection, and the method comprises the steps: determining the safety parameters of a target model based on a target request; based on a safety rule corresponding to the safety parameter, performing safety verification on the passenger information of each passenger in the passenger list; p passenger groups are determined based on the verification result of the security verification; and determining a target seat of each passenger based on the P passenger groups and an original seat of each passenger, the original seat being a passenger seat in the flight model before the change request, and the target seat being a passenger seat in the target model. According to the method and the device, the technical problem of low passenger cabin safety caused by directly distributing seats for passengers in a new target aircraft model only according to a passenger seat distribution scheme of an original aircraft model after the aircraft model is changed is solved.
Owner:TRAVELSKY TECHNOLOGY LIMITED

Tbox-based vehicle network information security protection system and method

This invention discloses a vehicle-to-everything (V2X) information security protection system and method based on a T-box. The in-vehicle T-box collects environmental information and log information from vehicle components. The in-vehicle T-box performs intrusion detection on the collected information. When a security event is detected, the in-vehicle T-box uploads the log information to a cloud server. The cloud server performs data format analysis and filtering on the log information, normalizes the format of sensitive data, and stores the normalized data. Using security rules from a predefined security rule base, the stored data is correlated, analyzed, and matched to generate analysis results. The cloud server displays the analysis results and sends them to the in-vehicle T-box, and implements a coordinated response from the vehicle's security protection devices based on the analysis results. Abnormal data detected on the vehicle is uploaded, and policy rules are updated and distributed on the cloud server's security operation platform to maximize the security of the vehicle.
Owner:CHERY AUTOMOBILE CO LTD

Unmanned aerial vehicle voice control full-link real-time security verification system

This invention discloses a real-time security verification system for the entire voice control chain of unmanned aerial vehicles (UAVs), relating to the fields of intelligent UAV control and voice security technology. This invention constructs a high-risk homophone feature library for UAVs with risk weights, employs a lightweight edge-side model to perform secondary verification and error correction on ASR (Automatic Speech Recognition) results, and avoids the risk of misidentification of opposing commands from the source. It achieves accurate flight status perception through multi-source sensor data time synchronization, adaptive fusion filtering, and standardized finite state machines. Based on a hierarchical safety rule expert system, it performs parallel three-dimensional conflict detection of timing, state-command, and multiple command superposition, outputting hierarchical execution decisions. Legitimate commands are issued and executed, while high-risk commands are intercepted and trigger safety fallback actions. Simultaneously, execution results are collected and fed back to update the rule library, forming a closed-loop control system across the entire chain. This invention effectively reduces the misjudgment rate and security risks of voice control, is compatible with mainstream ASR engines and multi-brand UAV flight controllers, and is adaptable to offline edge-side deployment on consumer and industrial-grade UAVs, providing highly reliable security for UAV voice control.
Owner:张方军

Leveraging quantum computing artificial intelligence to prevent cyberattacks on quantum IoT devices

Systems and methods may prevent or mitigate the possibility of cyberattacks on a heterogeneous network of quantum IoT devices that use AI. An AI algorithm on a device may be trained on data obtained during interaction with third party computer applications or systems. An aggregator may compile and aggregate the data used to train the local AI algorithms operating separately at each of the quantum IoT devices for use in a network-wide AI algorithm. Quantum key distribution may be used to control which of the quantum IoT devices controls security rules to be used in the IoT network. The security rules may be based on the aggregated data and may determine whether or to what extent a quantum IoT device may use the IoT devices to interact with third party applications or systems outside of the network.
Owner:BANK OF AMERICA CORP

Intelligent monitoring method and system for switching operation of transformer substation

The invention provides an intelligent monitoring method and system for switching operation of a transformer substation, and relates to the technical field of power grids. Multi-source sensing data such as SCADA signals, video data, temperature data, vibration data and environment data are collected in real time, a global rule engine and a process state engine are adopted for parallel study and judgment, switching operation is subjected to real-time multi-dimensional cross validation and deep analysis from the two dimensions of a macroscopic safety rule and a microcosmic operation process, and the real-time multi-dimensional cross validation and deep analysis are achieved. And the comprehensiveness and accuracy of risk identification are improved. And then strategy fusion is carried out based on a security priority principle, and an intelligent monitoring instruction including graded early warning and equipment locking is generated, so that differentiated and precise countermeasures are implemented for risks of different grades. By constructing an intelligent monitoring process integrating real-time sensing, intelligent analysis, strategy decision and accurate execution, the problem of safety risk existing in manual switching operation is solved, and the safety and intelligent level of switching operation of the transformer substation are improved.
Owner:MAINTENANCE BRANCH OF STATE GRID HEBEI ELECTRIC POWER +1