Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

41 results about "Security rule" patented technology

A metadata model-based code generation method, system and storage medium

This invention discloses a code generation method based on a metadata model, comprising: acquiring a three-layer metadata model of the target application and a preset template file; parsing the three-layer metadata model using a metadata parser to extract data model information, and filling the template file with the data model information to generate an initial code skeleton; calling an AI big model to collaboratively optimize the initial code skeleton to generate target business code; performing dual-engine security verification on the target business code based on a preset security rule base and the AI ​​big model; and outputting the final target code file after the dual-engine security verification passes. This fundamentally overcomes the contradiction between the lack of flexibility in traditional tools and the uncontrollable quality of existing AI-assisted tools, significantly reducing the cost of manual code supplementation and review, and achieving a comprehensive technical effect of cost reduction and efficiency improvement in the rapid construction of enterprise-level applications.
Owner:NINGBO HOLLYSYS INTELLIGENT TECH CO LTD

System for orchestrated management of identity security functions in container-based multi-cloud environments

ActiveDE202026100671U1Resource allocationDigital data authenticationOrchestration (computing)Security rule
System for the orchestrated management of identity security functions in container-based multi-cloud environments, comprehensive an identity data capture unit, trained to capture identity-related security parameters from multiple distributed, container-based computing environments, an orchestration control unit, trained to coordinate the control of identity and access security functions across multiple cloud environments, a policy linking unit, trained to assign safety rules to container-related execution states, and a security enforcement unit trained to execute identity-related security measures within the respective computing environment, the system coordinates identity security functions across environments without imposing a fixed prioritization of individual cloud environments.
Owner:GAHLOT RAKESH EDISON +3

Insecure model context protocol server remediation for artificial intelligence agents

ActiveUS12683991B1Remedial actionEngineering
A system detects changes in model context protocol (“MCP”) processes, and performs a remedial action. A server-sent events (“SSE”) bridge sends a request to an MCP server. A first resource profile is received from the MCP server. This is stored and compared against a second updated version of the resource profile. When a difference is detected, the SSE bridge determines whether to block a resource command from reaching the SSE bridge. The decision is based on comparing the difference to security rules, which can be defined as part of a management profile.
Owner:AIRIA LLC

An artificial intelligence agent hardware security mode switching apparatus

PendingCN122365601AMask ROMData center
This invention discloses a hardware-triggered security mode switching device and method for artificial intelligence agents, belonging to the fields of G06F21 / 71 and G11C17 / 14. Addressing the shortcomings of existing technologies that rely on software / main control chips, this invention employs an independent hardware module design, including a non-electrically erasable storage structure (such as mask ROM, OTP) for storing a security rule set, a hardware instruction monitoring unit for physically intercepting and parsing instruction streams, a hardware anomaly detection unit for comparing security rules, a hardware security mode triggering unit for generating trigger signals, and a physically isolated security mode execution interface for transmitting signals. The device is completely independent of the agent's main control chip and any externally loadable and modifiable software, ensuring that security mode switching can still be performed even if the main control chip fails or is attacked. This solution effectively prevents the execution of harmful commands sent from data centers, provides hardware-level tamper-proof security protection, 100% resists malicious instruction tampering, and significantly improves the security of artificial intelligence agents.
Owner:SHENZHEN BAIMAXUN NETWORK TECHNOLOGY CO LTD

A safety protection method and related product

PendingCN122293391Aachieve sharingimprove accuracySecurity ruleData science
This application discloses a security protection method and related products. The method includes: identifying abnormal behavior in the data to be processed corresponding to a target vehicle based on a preset security rule base and a pre-trained anomaly recognition model to obtain a security recognition result; if the security recognition result indicates a first anomaly level, then performing local security protection on the target vehicle according to a local protection strategy; if the security recognition result indicates a second anomaly level, then obtaining the collaborative protection strategy sent by the cloud platform corresponding to the target vehicle, and performing collaborative security protection with other vehicles according to the collaborative protection strategy. This improves the security of the entire vehicle-to-everything (V2X) environment.
Owner:NEUSOFT REACH AUTOMOBILE TECH (SHENYANG) CO LTD

Unmanned aerial vehicle voice control full-link real-time security verification system

PendingCN122417009AUncrewed vehicleSecurity rule
This invention discloses a real-time security verification system for the entire voice control chain of unmanned aerial vehicles (UAVs), relating to the fields of intelligent UAV control and voice security technology. This invention constructs a high-risk homophone feature library for UAVs with risk weights, employs a lightweight edge-side model to perform secondary verification and error correction on ASR (Automatic Speech Recognition) results, and avoids the risk of misidentification of opposing commands from the source. It achieves accurate flight status perception through multi-source sensor data time synchronization, adaptive fusion filtering, and standardized finite state machines. Based on a hierarchical safety rule expert system, it performs parallel three-dimensional conflict detection of timing, state-command, and multiple command superposition, outputting hierarchical execution decisions. Legitimate commands are issued and executed, while high-risk commands are intercepted and trigger safety fallback actions. Simultaneously, execution results are collected and fed back to update the rule library, forming a closed-loop control system across the entire chain. This invention effectively reduces the misjudgment rate and security risks of voice control, is compatible with mainstream ASR engines and multi-brand UAV flight controllers, and is adaptable to offline edge-side deployment on consumer and industrial-grade UAVs, providing highly reliable security for UAV voice control.
Owner:张方军

A heterogeneous database logical association construction and privacy compliance code generation method for intelligent programming assistance

This invention discloses a method for constructing logical associations and generating privacy-compliant code for heterogeneous databases in intelligent programming assistance. It introduces a custom metadata description file independent of the database's physical schema, defining cross-domain logical association attributes and data security attributes, including the target database identifier. The description file is parsed, comparing the associated target with the database identifier of the current context, and automatically selecting either an intra-database join strategy or an application-layer aggregation strategy based on the comparison result. An enhanced context hint containing architectural constraints and security rules is constructed, and the target code is generated by inputting a large language model. De-identification processing logic is automatically embedded based on the data security attributes. This invention effectively solves the problems of AI programming context breakage, cross-database association code generation errors, and data privacy compliance risks caused by missing physical foreign keys in microservice architectures, achieving automatic code generation and source-level data privacy protection for complex cross-service business logic.
Owner:CHINA LIFE INSURANCE CO LTD

A ladder networking data management and backup method and system under a hybrid cloud architecture

ActiveCN121397092BPlaintextClustered data
The application relates to the technical field of elevator Internet of Things data processing, and discloses an elevator Internet of Things data management and backup method and system under a hybrid cloud architecture, which comprises the following steps: collecting elevator terminal equipment original data streams on the edge side and processing the original data streams to generate pretreatment data; identifying data sensitivity according to a security rule library, encrypting high and medium sensitive data, and keeping low sensitive data in plaintext; dividing the data into three backup priority sets according to business criticality, and respectively distributing the data to an edge side local backup unit, a private cloud and a public cloud backup cluster after clustering based on access frequency and storage occupation; monitoring storage load, link state and backup progress, and scheduling resources when an exception occurs; and regularly recovering and practicing the backup data. Through data hierarchical processing, differential storage, dynamic monitoring and scheduling and regular practice, the application supports intelligent management of large-scale elevator cluster data.
Owner:SHANDONG TIWANG INFORMATION TECHNOLOGY CO LTD

A remote security management method and system

This application discloses a remote security management method and system. The method includes: deploying an edge computing node within the vehicle to receive remote control commands; before executing the command, acquiring the local real-time status parameters of the controlled device and performing security verification according to preset local security rules; and rejecting the command if it is determined that executing the command will violate the security rules. This application also discloses a system for implementing this method. By constructing an edge-first arbitration logic, this application solves the technical problem of traditional cloud control solutions losing security capabilities during network interruptions. Even during network interruptions, it can still independently execute local security rules, rejecting unreasonable commands and improving the system's security and robustness.
Owner:RONGCHENG MOLIN OUTDOOR TECH CO LTD

Safety control device and safety rule adjustment method

ActiveCN116670606BControl systemAction planning
The problem is to achieve work efficiency and ensure safety of actions of control objects in different control systems, i.e., in an environment where heterogeneous systems are mixed. A safety control server (5) for controlling actions of control objects in heterogeneous systems under a plurality of control systems has an action adjustment section (5330) for outputting an action adjustment instruction for adjusting actions to a control object in a control system different from the control object, in the case where a conflict occurs in which the action of the control object deviates from an intended control result, an action plan adjustment section (5320) for adjusting a pre-stored action plan indicating an action rule for avoiding a conflict of the control object and for functioning, in the case where the adjustment of the action satisfies a prescribed condition, and a safety rule adjustment section (5310) for adjusting a pre-stored safety rule indicating an action rule for avoiding a conflict of the control object, in the case where the adjustment of the action plan satisfies a prescribed condition.
Owner:HITACHI LTD

Method, system and program product for path planning of a pipetting robot

PendingCN122442620ADecision modelWorkstation
The disclosure provides a path planning method, system and program product of a pipetting robot. The path planning method comprises: receiving a pipetting task of a user; determining task state information of each target well based on the pipetting task, and collecting a global physical state of a pipetting workstation including the pipetting robot in real time; extracting state data of each entity in the pipetting workstation from the global physical state and the task state information to form a heterogeneous entity set; encoding each entity in the heterogeneous entity set into a state representation sequence of a unified dimension; outputting an initial pipetting instruction parameterized by an upper decision model; and performing motion planning for a target well set based on the initial pipetting instruction and the task state information. The disclosure enhances the adaptability to different experimental scenarios, and significantly improves the automation level and planning quality of pipetting operation on the basis of ensuring absolute compliance with hard safety rules such as anti-pollution.
Owner:EAST CHINA UNIV OF SCI & TECH

A high-value data encryption system and method in a localization environment

This invention discloses a domestically developed encryption system and method for high-value data in the field of data encryption technology, comprising: environment preparation: installing a Docker runtime environment on a Kylin operating system and ensuring that the SELinux security subsystem is in forced mode; encrypted volume preparation: after completing the environment preparation, creating a LUKS encrypted volume for physical storage space on the host machine, initializing the volume using an encryption key, and creating a file system; security policy configuration: after completing the encrypted volume preparation, creating and loading a custom SELinux policy module, wherein the defined security rules are configured to: deny access operations of the host machine process domain to the LUKS encrypted volume device file, while allowing access operations of the Docker container process domain to the LUKS encrypted volume device file. This invention achieves high-value data encryption based on Docker containers and LUKS encrypted volumes in a Kylin operating system environment, realizing strong encrypted data storage.
Owner:SIWEI SHIJING TECH (BEIJING) CO LTD

Systems and Methods for Security Monitoring Through Dynamically Controlled Context-Based Access

The disclosure provides a computer-implemented method including operations of detecting one or more access request queries on a nodal graph, wherein the nodal graph includes nodes representing entities from a plurality of data sources and relationships between the entities, responsive to detecting the one or more access request queries, querying the nodal graph for one or more security rules, evaluating the one or more security rules against the nodal graph in view of historical access requests resulting in detection of a defined behavior, and initiating performance of one or more automated access management actions in response to the detection of the defined behavior. Additionally, one or more access request queries may correspond to requests from a protected system for a determination as to whether a first user has permission to access data of the protected system.
Owner:CROWDSTRIKE

AI-based intelligent dismantling sequence planning method for power batteries

PendingCN122089295ABreaking through the limitations of artificial experiencehigh feasibilityMathematical modelsData processing applicationsPower batterySequence planning
This invention discloses an artificial intelligence-based intelligent dismantling sequence planning method for power batteries, belonging to the field of power battery dismantling technology. The method includes initializing a dismantling sequence simulation environment, loading a dismantling action constraint relationship network, a dismantling tool action model, and a dismantling safety rule base; employing a reinforcement learning agent to drive Monte Carlo tree search, simulating component dismantling order to generate multiple candidate sequences, and simultaneously collecting simulation data such as tool selection, time consumption, safety risk score, and resource consumption assessment for each step; constructing a multi-objective evaluation model with four dimensions: dismantling efficiency, safety, resource cost, and component integrity recovery rate, quantifying and fusing data, and calculating a comprehensive score; selecting the highest-scoring sequence as the recommended sequence, and outputting an executable process guidance document with detailed steps, a tool list, and risk warnings. This invention overcomes the limitations of human experience, covers multiple paths under complex constraints, quantifies and balances multi-objective conflicts, and improves the scientific nature of power battery dismantling.
Owner:HUNAN RAILWAY PROFESSIONAL TECH COLLEGE +1

Interaction method, vehicle, server, and storage medium

ActiveCN115520207BRisk levelIn vehicle
This application discloses an interaction method, comprising: when a customized solution for a completed in-vehicle system function is triggered under certain conditions, and based on pre-set safety rules for execution actions and vehicle status information, and the vehicle's current status information, determining the safety risk level of each execution action and / or function in the customized solution during execution; and sending corresponding execution status feedback to the user based on the safety risk level when each execution action and / or function is executed. Thus, during the execution of the customized solution, the risk level of each upcoming execution action or function is determined based on pre-set safety rules and the vehicle's real-time status information, and corresponding feedback is provided to the user. This allows the user to be aware of the anticipated risks of the upcoming execution and to take timely action based on the actual situation, thereby ensuring the safety of the customized solution's execution to a certain extent.
Owner:GUANGZHOU XIAOPENG MOTORS TECH CO LTD

Automated security rule updates based on alert feedback

ActiveUS12676889B2Internet trafficSecurity rule
Aspects of the disclosure are directed to systems, method, and computer-readable mediums for reducing the number of false positive alerts generated by a SIEM system by adjusting the set of rules the SIEM system uses to analyze attributes of the network traffic and / or system activities based on feedback from a SOAR system. Alert feedback may be received for a set of alerts generated in response to attributes triggering one or more rules. The alert feedback may indicate, for each alert of the set of alerts, whether the alert was a true positive alert or false positive alert. One or more conditions of the at least one rule may be adjusted based on the feedback.
Owner:GOOGLE LLC

Methods and systems for fusing multi-source heterogeneous data in hospital security

PendingCN122310027ASemantic vectorData stream
This invention provides a method and system for fusing multi-source heterogeneous data in hospital security. The method includes: acquiring multi-source heterogeneous data from various security subsystems, processing it through spatiotemporal and semantic dimension normalization to form a standardized data stream; then combining a preset security rule base and a long short-term memory network to calculate the global situational risk level, adjusting the cumulative anomaly score threshold and determining core events; iteratively expanding along the spatiotemporal dimension with the core events as the center; determining the boundary based on the average correlation of newly included regional data points to form a spatiotemporal event window; calculating multimodal fusion weights and weighted aggregation for the data within the window by comprehensively considering semantic vector cosine similarity, spatiotemporal Gaussian kernel similarity, and data source credibility to obtain a fused associated dataset; using high-weight data points as real nodes, inferring potential nodes based on a security logic knowledge base, constructing probability transition edges according to weight and temporal relationship, generating an event evolution probability map, and displaying it on the terminal.
Owner:ZHEJIANG JIAGUANG INFORMATION TECH CO LTD

VR-based 10kv non-power operation simulation and safety verification method and system

The application discloses a VR-based 10kV non-power-off operation simulation and safety verification method and system, which comprises the following steps: establishing a three-dimensional virtual scene of a target 10kV line; based on the three-dimensional virtual scene, a VR immersive interactive environment is constructed, and a simulation operation instruction of an operator is received through a VR interactive device; during the execution of the simulation operation instruction, multi-physical field coupling calculation is performed in real time to quantitatively evaluate the safety risk in the virtual operation process; based on a preset safety rule knowledge base, the simulation operation instruction and the multi-physical field coupling calculation result are checked for real-time compliance, and a dynamic risk early warning is triggered according to the checking result; the execution process data of the simulation operation instruction and the corresponding multi-physical field coupling calculation result are recorded to generate a quantitative evaluation report containing the safety, standardization and skill level dimensions. The application effectively improves the operation safety level and the professional ability of the operator.
Owner:GUIZHOU POWER GRID CO LTD ZUNYI POWER SUPPLY BUREAU

System and method for secure copy-and-paste operations between hosts through a peripheral sharing device

A peripheral sharing device for supporting secure copy-paste operations between hosts comprising: a plurality of copy-emulators and a plurality of paste emulators, configured cach to be connected to a copy-paste driver, wherein cach copy-paste driver is running on one of a plurality of hosts that are connected to the peripheral sharing device, and the copy-paste driver is configured to fetch or store clipboard objects from the clipboard of the corresponding host, a security bridge that is configured to securely pass clipboard objects between pairs of copy emulator and paste emulator. The security bridge performs security operations, such as, enforce unidirectional data transfer of the clipboard object, monitor the clipboard object and enable or disable the copy-paste operation according to a set of security rules; enable or disable the copy-paste operation according to security policy, analyze clipboard object traffic to detect cybersecurity events, locking suspicious peripheral sharing devices, and preventing clipboard object transfer between pairs of copy-paste controllers according to security rules. The copy emulator receives the clipboard object from the copy-paste driver of a first host, transfer the clipboard object to the security bridge and conditioned upon passing the security conditions the security bridge transfer the clipboard object to the paste emulator that further pass the clipboard object to a second computer's copy-paste driver.
Owner:HIGH SEC LABS LTD

Assurance of security rules in a network

ActiveUS12670142B2Computer networkNetwork on
In some examples, a system creates a requirement including EPG selectors representing EPG pairs, a traffic selector, and a communication operator; determines that EPGs in distinct pairs are associated with different network contexts and, for each pair, which network context(s) contains associated policies; creates first data representing the pair, operator, and traffic selector; when only one network context contains the associated policies, creates second data representing a network model portion associated with the only network context and determines whether the first data is contained in the second data to yield a first check; when both network contexts contain the associated policies, also creates third data representing a network model portion associated with a second network context, and determines whether the first data is contained in the second and / or third data to yield a second check; and determines whether policies for the pairs comply with the requirement based on the checks.
Owner:CISCO TECHNOLOGY INC

A trusted bottom layer implementation framework and system of a man-machine collaborative intelligent system

PendingCN122333449AMan machinePublic infrastructure
This invention discloses a trusted underlying implementation framework and system for a human-machine collaborative intelligent system. Through a five-layer closed-loop rigid design, it achieves irreversible hardware-level isolation of raw privacy data, automatic blocking of inducing instructions, full-link traceability of interaction responsibility, non-inducing disclosure of the right to know, positive incentives for compliant behavior, and mandatory binding of trusted authentication with access to national public infrastructure. This invention provides a set of neutral, universal, and unavoidable industry-level security rules, preventing privacy abuse, algorithmic manipulation, responsibility shifting, and human-driven manipulation at the source. While ensuring technological innovation, it provides secure, fair, and sustainable underlying technical support for human-machine collaboration, brain-computer interaction, and hybrid intelligence.
Owner:梁彩虹

Method and system for protecting instructions of a large model based on four-layer cooperative closed loop

The application discloses a kind of big model instruction security protection method, system and storage medium based on four-layer cooperative closed-loop protection mechanism, belong to artificial intelligence security and trusted computing field.The application is deployed non-intrusive independent protection layer between user input layer and big model inference execution layer, through instruction weight dynamic control, context integrity check, multi-modal public power subject credible verification, four big links cooperative linkage of security rule priority rigid locking, combined with shared semantic label library, dynamic threshold value synchronization mechanism and cross-layer abnormal feedback channel constructs whole-link closed-loop protection system.The application realizes high semantic weight content attenuation by instruction weight system, resists split bypass attack by context governance, guarantees public power identity credible by multi-modal double verification, realizes permission control and algorithm transparent by rule priority rigid locking, built-in global multi-jurisdiction compliance rule library, adapt to global regulatory requirements and have anti-black-box auditable characteristics.The application does not need to modify model bottom code, supports hardware-level isolation and national encryption algorithm acceleration, can be widely applied to government, finance, military industry and other high-end security scene, provides non-intrusive, global, high-security compliance protection solution for big model.
Owner:高鹏

Systems and Methods for Governed Release of Clinical Outputs Generated by Automated Reasoning

PendingUS20260196356A1EngineeringMedical decision making
An AI keystone system for medical decision support generates governed, auditable clinical insights. A medical data governance (MDG) engine ingests heterogeneous patient-related data from clinical systems, medical devices, and clinician inputs, validates and normalizes the data under governance rules, and emits structured, context-constrained representations for identified patients and episodes. One or more intermediary components collect and relay real-time device data so downstream processing operates only on governed data. A reasoning layer with artificial-intelligence models, including at least one large language model, cooperates with modular AI components to process clinician queries and generate candidate clinical outputs. A cryptographic governance subsystem evaluates candidate outputs against patient-safety rules, regulatory mandates, institution-specific policies, and stored consent artefacts using machine-verifiable constraints, enforces dual-factor clinician authentication, and maintains immutable, hash-chained audit trails with trusted timestamps that gate workflow progression. The system enables defensible use of AI-assisted clinical insights across hospital, clinic, and virtual-care environments.
Owner:ONESOURCE SOLUTIONS INT INC

Big model red team test data processing method and system fusing prior safety rules

PendingCN122450853AKnowledge sourcesPathPing
The present application belongs to the technical field of large model security test data processing, and relates to a large model red team test data processing method and system fusing prior security rules, the system comprising a rule boundary generation module, a link association processing module, a boundary state determination module, a red team test generation module, a test execution collection module, a boundary crossing identification attribution module and a test result processing module; the method comprising: acquiring security boundary configuration data containing prior security rules and generating rule boundary data; collecting interactive link data and generating interactive link association data; determining the knowledge boundary state corresponding to the test subject and generating multi-stage red team test tasks; collecting test execution link data after executing the test, identifying boundary crossing content that exceeds the use boundary, determining the corresponding knowledge source and trigger path, and generating red team test result data to represent the knowledge content boundary crossing output risk of the large model object being tested.
Owner:ZHEJIANG YUNDUOWANG TECH CO LTD

Security replicator for personal artificial intelligence system

A personal artificial intelligence (AI) system may be used to conduct business with one or more entities. The personal AI system may automatically replicate security rules from another AI system to provide initial security rules and may adjust the initial security rules based on information about the user to generate revised security rules. The rules adjustments may also be based on the entities with which the user does business. An AI firewall may be generated to control access to the personal AI system by a second AI system, with which business may be conducted. To permit interactions with the second AI system, the AI firewall may require that the second AI system provide the personal AI system with data relating to previous transactions between the user and the operator of the second AI system. The data may include the monetary amount of each of multiple recent transactions.
Owner:BANK OF AMERICA CORP

Industrial control multi-mode content security protection method, system, equipment and medium

The invention relates to the technical field of artificial intelligence safety, in particular to an industrial control multi-mode content safety protection method, system and device and a medium, and the method comprises the steps: carrying out the semantic orthographic decomposition of safety rules in the industrial control field, so as to construct an industrial control image-text seed sample library; the method comprises the following steps: repeatedly performing three-stage progressive image-text joint reasoning on an industrial control image-text seed sample library through multi-gear Boltzmann temperature parameters to generate an audit reasoning triple data set and an audit reply text, associating audit question-answer pairs in combination with multi-type rules, and constructing an instruction fine tuning data set; performing safety capability injection fine tuning on the multi-modal base model by using the instruction fine tuning data set to obtain an industrial control content safety protection model; and performing security audit reasoning on the to-be-audited image-text content of the industrial control scene through the industrial control content security protection model to generate an interpretable audit judgment result. According to the invention, rule driving of multi-mode input of the power grid and the industrial control system under a low data scale is realized, and content security protection can be explained.
Owner:STATE GRID ZHEJIANG ELECTRIC POWER CO LTD

Security rule base dynamic linkage code review method, device and related equipment

The application relates to the technical field of computer software, can be applied to the field of science and technology finance / digital medicine, and discloses a dynamic linkage code review method of a security rule base. The method comprises the following steps: receiving a code submission request, obtaining source code data and running environment identification data associated with the code submission request; determining rule screening conditions according to the running environment identification data, generating rule query parameters, and sending a rule acquisition request to the security rule base based on the rule query parameters; receiving a target rule data set returned by the security rule base and corresponding to the running environment identification data; performing matching processing on the source code data according to the target rule data set, and generating risk level data corresponding to the source code data according to the matching processing result; generating a code submission control instruction according to the risk level data, and changing the submission process state of the source code data according to the code submission control instruction. The method improves the pertinence and process controllability of code security review.
Owner:CHINA PING AN PROPERTY INSURANCE CO LTD