Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

603 results about "Security service" patented technology

Security service is a service, provided by a layer of communicating open systems, which ensures adequate security of the systems or of data transfers as defined by ITU-T X.800 Recommendation. X.800 and ISO 7498-2 (Information processing systems – Open systems interconnection – Basic Reference Model – Part 2: Security architecture) are technically aligned.

Industrial control network security service security guarantee system based on behavior analysis

The invention provides an industrial control network security service security guarantee system based on behavior analysis, which belongs to the technical field of industrial control network security, and comprises a multi-source data fusion acquisition module, a dynamic behavior modeling engine, a federal learning analysis cluster, an attack chain prediction module, a self-adaptive protection strategy executor and a model evolution feedback ring, wherein the multi-source data fusion acquisition module synchronously acquires industrial control network flow (including OPC UA / Modbus / DNP3 protocol analysis), equipment operation logs, user operation behavior fingerprints and physical interface state data, and the physical interface state data comprises electrical characteristic fluctuation monitoring of USB / network interfaces. According to the scheme, through multi-technology fusion and closed-loop design, the problems of static performance, single-dimension analysis defects and response lag of a traditional industrial control security scheme are effectively solved, a comprehensive protection system with dynamic modeling, intelligent decision making, privacy protection and continuous optimization is constructed, and the security and service reliability of an industrial control network are remarkably improved.
Owner:CPI NORTHEAST ENERGY SAVING TECH +1

Adaptive dynamic energy coordination device for integrated renewable and conventional energy networks

A data-driven dynamic energy management system for the adaptive coordination of renewable and conventional energy sources, consisting of: a processing unit configured to perform real-time calculations to optimize the generation, storage, and distribution of electrical energy by continuously analyzing operational data, forecasting future energy demand, and generating control instructions to match available generation resources with forecasted consumption demand; a storage unit connected to the processing unit, configured to store records of historical energy production and consumption, environmental data, operating thresholds and learned model parameters, and to provide said data as input for the forecasting and optimization routines performed by the processing unit; a multitude of IoT-based monitoring units, each comprising at least one sensor configured to measure instantaneous parameters of generation, storage level, consumption rate and environmental conditions, with each monitoring unit being configured to periodically transmit measurement packets to the processing unit via a secure communication network; a forecasting unit implemented in the processing unit, configured to process historical and real-time data to create forecast curves for demand and generation using statistical and probabilistic forecasting techniques, and to dynamically update the weights of the forecasting model in response to observed deviations between forecasted and actual output; an optimization control unit implemented in the processing unit and configured to evaluate the outputs of the forecasting unit together with current operational data to determine a set of optimized control variables representing the target generation contribution of each energy source, and to pass these targets to a lower-level controller for execution; a controller that is communicatively connected to the processing unit and the multiple energy generation sources and is configured to regulate the operation of each source by adjusting the activation state, output level and operating priority based on the control signals received from the processing unit; an energy storage management unit comprising at least one battery array and a power conditioning circuit, configured to receive control instructions from the processing unit, store excess generated energy, release stored energy when forecasted demand exceeds available generation, and report charging and discharging characteristics in real time to the processing unit for continuous recalibration; an alarm and notification control unit connected to the processing unit, configured to continuously compare storage levels and generation reserves with stored operating thresholds, trigger predefined responses when critical or abnormal conditions are detected, and transmit acoustic, visual, and digital remote alerts to designated operators; a user interface terminal connected to the processing unit, configured to display real-time generation statistics, demand forecasts, energy storage status, and system alerts, and to accept operator-defined parameter inputs that are transmitted to the processing unit for recalibration of forecast or optimization parameters; and a secure server interface configured to synchronize operational logs, learning data, and performance indicators with a remote monitoring or analysis server for centralized monitoring, long-term data analysis, and distributed decision support.
Owner:CONEJERO RIQUELME NATALIA ELOISA +4

Trusted cloud security confidential privacy three-dimensional grade product service system and method

PendingCN120528631ASecuring communicationComputer networkProduct-service system
The invention belongs to the technical field of cloud security services, and provides a trusted cloud security confidential privacy three-dimensional level product service method, which comprises the following steps that: a cloud service provider matches products and services with different security levels by separating differentiated demands of an application development service provider and a final user in confidential, privacy and security dimensions; configuring different security modules for the product, performing hardware and software type selection matching, and determining a product type in combination with an end-to-end scene; then deploying a dynamic strategy adjustment mechanism, monitoring abnormal access in real time and adaptively adjusting a protection strategy; and continuously optimizing the security configuration. The invention discloses a trusted cloud security confidential privacy three-dimensional grade product service system, which is used for realizing a trusted cloud security confidential privacy three-dimensional grade product service method. The method is beneficial for transparently solving the security demand and conflict problem of the cloud service provider, the application development service provider and the final user, and promoting the healthy development of the cloud computing market.
Owner:WUHAN TRUSTED CLOUD TECH CO LTD

Method and apparatus for repeatedly transmitting uplink data for network cooperative communication

The disclosure relates to a communication technique and system therefor for converging an Internet of Things (IoT) technology and a 5th generation (5G) communication system for supporting a high data rate after a 4th generation (4G) system. The disclosure is applicable to intelligent services (e.g., smart home, smart building, smart city, smart car or connected car, health care, digital education, retail, security, and safety services) based on a 5G communication technology and IoT-related technology. The disclosure provides a method and apparatus for uplink (UL) data repetition transmission by a user equipment (UE) in a next-generation communication system.
Owner:SAMSUNG ELECTRONICS CO LTD

Sidecar Security Pattern for Agent Communications

Systems and methods for securing agent communications in a multi-agent system including deploying an agent to communicate with external servers, instantiating a sidecar security service in communication with the agent and including at least one of a guardrails service, a security layer, an encryption module, and an integrity checker configured to validate resources tools using hash-based verification mechanisms. Communications including messages between the primary and the external servers are intercepted by the sidecar security service, which then performs at least one of filtering the one or more messages by the guardrails service, authenticating one or more server connections by the security layer, encrypting one or more outbound requests by the encryption module, or verifying an integrity of resources and tool definitions by the integrity checker.
Owner:MADISETTI VIJAY

Techniques for token proximity transactions

Systems and methods are provided to enable a user to conduct a transaction using their credentials stored on a secure server computer (e.g., a computer associated with a partner such as another merchant) by merely presenting their authentication data at a physical location via an auxiliary device. An auxiliary device may be provided for interfacing with a partner's backend server (e.g., the secure server computer). In some embodiments, biometric authentication may provide a mechanism for a true seamless and potentially frictionless (in the case of modalities that do not require physical contact) interaction. Payment can occur without any need for a card, phone, wearable, or any other user device as long as the auxiliary device is able to recognize the user and retrieve a credential that can be linked to that user.
Owner:VISA INTERNATIONAL SERVICE ASSOCIATION

Unknown exploit detection using attack traffic analysis and real-time attack event streaming

Techniques for unknown exploit detection using attack traffic analysis and real-time attack event streaming are disclosed. In some embodiments, a system / process / computer program product for exploit detection using attack traffic analysis and real-time attack event streaming includes receiving a stream that includes a plurality of attack events from a security platform at a cloud security service; generating a cluster of attack events from the stream; and tagging the cluster with an unknown attack pattern for further automated security analysis at the cloud security service, wherein the tagged unknown attack pattern cluster does not match a preexisting signature for a known attack pattern.
Owner:PALO ALTO NETWORKS INC

Malicious uniform resource locator (URL) detection

Apparatuses, systems, and techniques for classifying a candidate uniform resource locator (URL) as a malicious URL using a machine learning (ML) detection system. An integrated circuit is coupled to physical memory of a host device via a host interface. The integrated circuit hosts a hardware-accelerated security service that obtains a snapshot of data stored in the physical memory and extracts a set of features from the snapshot. The security service classifies the candidate URL as a malicious URL using the set of features and outputs an indication of the malicious URL.
Owner:MELLANOX TECHNOLOGIES LTD(IL)

Artificial intelligence chatbot for data platform security analysis

In general, techniques are described that enable a computing system to execute an artificial intelligence model for data security analysis. A computing system that includes a memory and processing circuitry may be configured to implement the techniques. The memory may store a query from an end user regarding security services provided by the data platform. The processing circuitry may parse the query to identify one or more intents, and process the one or more intents to retrieve data for formulating a natural language response to the query. The processing circuitry may also process, using a large language model, the intents and the data to generate the natural language response, and output the natural language response to a user interface for display to the end user.
Owner:COHESITY INC

Fused secure storage system, electronic equipment, data management method and computer readable storage medium

The invention provides a fusion type secure storage system, electronic equipment, a data management method and a computer readable storage medium. The system comprises a hardware security layer, an encryption processing layer, a verification error correction layer, a data stream processing layer and an intelligent management layer which are in communication connection, the hardware security layer provides a physical trusted root for the system and executes a security policy; the encryption processing layer is used for carrying out encryption processing on data based on the security service provided by the physical trusted root; the verification and error correction layer is used for carrying out integrity verification and self-adaptive error correction coding on the encrypted data; the data stream processing layer is used for executing a near data calculation task on the data subjected to verification and error correction; and the intelligent management layer collects real-time state data from the hardware security layer, the encryption processing layer, the check error correction layer and the data stream processing layer, and performs dynamic strategy configuration and global optimization decision, thereby improving the active calculation, dynamic adaptation and intelligent optimization capabilities of the system.
Owner:深圳华芯星半导体有限公司

Secure identification system

The present disclosure relates to a method of enrolling an individual at a secure server and subsequently authenticating and identifying the individual at an authenticating party using an authentication token created during the enrolment and a secure server performing the method. The method comprises engaging, via a user device, in an enrolment process with the individual, registering the user device by receiving a public key, the public key being created by the user device along with a private key corresponding to the public key, acquiring a trusted identifier of the individual, associating the acquired trusted identifier of the individual with at least one database index to create an authentication token, the database index being utilized for look-up at the secure server, signing the authentication token, and sending the signed authentication token to the user device, while deleting the acquired trusted identifier at the secure server.
Owner:FINGERPRINT CARDS ANACATUM IP AB

Secure communications in a firmware framework

Systems and methods for secure communications in a firmware framework. In some embodiments, an Information Handling System (IHS) may include: a controller, wherein the controller comprises firmware that, upon execution by a processing core, causes the processing core to instantiate an orchestrator; and a plurality of devices coupled to the controller, where each device comprises firmware that, upon execution by a corresponding processing core, causes the corresponding processing core to instantiate a node as part of a firmware framework, and where a given node is configured to communicate with the orchestrator, at least in part, using a security service of the firmware framework without any involvement by any Operating System (OS) of the IHS.
Owner:DELL PROD LP

Resource elastic scaling decision-making method, system and device and medium

The invention relates to a resource elastic scaling decision-making method, system and device and a medium. The method comprises the following steps: collecting real-time operation data of a security service node, and performing multi-dimensional security index analysis according to the real-time operation data to obtain a portrait data packet; predicting the security service weight value to obtain a prediction result, performing dynamic error compensation on the prediction result to generate a corrected weight prediction value, and generating a control instruction based on the corrected weight prediction value and the active session state; and when the instruction is a migration instruction, analyzing a session state snapshot of the instruction, calling a preset kernel state locking function to lock a memory session block of a source node, obtaining incremental state change data to generate a migration snapshot packet, and performing block verification injection operation on a target node. According to the method, by integrating multi-dimensional safety index analysis, prediction error compensation and stateful transition verification mechanisms, the accuracy and response efficiency of resource elastic scaling decision making are improved, and the continuity of stateful service transition and the consistency of safety strategies are enhanced.
Owner:STATE GRID INFORMATION & TELECOMM BRANCH +1

Security service distribution

This disclosure describes techniques for distributing security service by performing security policy-based routing among network devices. The techniques include determining a security function to be applied to a packet of a data traffic flow. The security function may be determined based on a security policy and an intended destination of the packet. The techniques may also include determining whether a network device is capable of performing the security function. A route for the packet to the destination may be determined based on whether the network device is capable of performing the security function. As such, distributing security service techniques may improve efficiency in data traffic routing, and may reduce cost and / or prevent redundancy in security service application.
Owner:CISCO TECHNOLOGY INC

Encrypted applications verification

Concepts and technologies disclosed herein are directed to encrypted applications verification. According to one aspect disclosed herein, a device can execute an application verification module to perform operations. The device can receive a hash function from a master security server. The hash function can be used to verify an application installed on the device. The device can apply the hash function to application code of the application to determine a hash result. The master security server can determine whether the application is verified based upon the hash result. The device can execute the application thereby generating data traffic to be sent via a network to a destination. The device can provide the data traffic to the network. A network node can receive the data traffic and can allow or deny the data traffic access to the destination based upon a command received from the master security server.
Owner:AT&T INTELLECTUAL PROPERTY I L P

Internet asset vulnerability governance whole-process management method

The invention relates to a whole-process management method for internet asset vulnerability governance. The method comprises the following specific steps of task configuration, scanning task creation and execution, vulnerability list generation and work order distribution, vulnerability repair and multi-stage auditing, and data statistics and archiving. The efficiency is obviously improved; the whole process is online, so that the vulnerability management period is greatly reduced; the manpower cost is reduced: repeated docking of a third-party security team is not needed, the workload of security operation personnel is reduced, and manpower loss of offline communication is avoided at the same time; work order records, approval traces and scanning logs are archived in the whole process, a complete basis is provided for safety audit, an assessment report of a person in charge can be directly used for performance assessment, and the problem that no data exists in assessment is solved; and the rectification sheet state can be synchronized to all cadres in real time, information fault is avoided, and superior leaders can monitor the treatment progress in real time through the data statistics module and intervene in lagging links in time.
Owner:JIANGSU BAOWANGDA SOFTWARE TECH CO LTD

Network structure and service providing method for supporting multicast and broadcast service in mobile communication network

The present disclosure relates to a communication method and system for converging a 5th-Generation (5G) communication system for supporting higher data rates beyond a 4th-Generation (4G) system with a technology for Internet of Things (IoT). The present disclosure may be applied to intelligent services based on the 5G communication technology and the IoT-related technology, such as smart home, smart building, smart city, smart car, connected car, health care, digital education, smart retail, security and safety services. According to the present disclosure, MBS services for flexible and dynamic MBS service scenarios become possible in the next-generation wireless communication systems.
Owner:SAMSUNG ELECTRONICS CO LTD

Security resource pool dynamic capacity expansion method for multi-tenant sharing

The invention relates to the technical field of security resource pool dynamic capacity expansion, and discloses a security resource pool dynamic capacity expansion method for multi-tenant sharing, which comprises the following steps: acquiring the security service use condition of each tenant in a current security resource pool to generate tenant state data; constructing a tenant state prediction model based on the historical tenant state data; generating tenant state prediction data in combination with the tenant state prediction model and the current tenant state data; and dynamically optimizing resource pool configuration based on the tenant state prediction data. According to the method, accurate prediction, intelligent scheduling and efficient utilization of resources are realized, the dynamic response capability and resource allocation rationality of the multi-tenant security resource pool are effectively improved, the operation cost is reduced, and the service quality of the tenants is guaranteed.
Owner:HUANENG INFORMATION TECH CO LTD

Indoor robot target detection method and system based on multi-modal tracking and medium

The invention provides an indoor robot target detection method and system based on multi-modal tracking and a medium, and belongs to the field of robotics.The method comprises the steps that laser data processing is optimized through static furniture learning and filtering and dynamic region clustering, and the visual anti-illumination interference capacity is combined; a dynamic cost matrix matching strategy based on target motion characteristics is adopted to obtain a stable trajectory of a target person; kalman filtering trajectory prediction and target appearance feature matching are fused, and it is ensured that tracking can be rapidly recovered after the target is temporarily lost; a human-guided following mapping mode is adopted, a moving track of a tracked target is used as dynamic guidance, dynamic and static point clouds are separated, and a high-precision environment map with semantic tags is constructed; according to the invention, a following state monitoring and active service linkage mechanism is established, scene decision is carried out by identifying a target attitude and combining a semantic map, corresponding health monitoring and safety services are triggered, and the crossing from passive tracking to active intelligent services is realized.
Owner:EAST CHINA UNIV OF SCI & TECH

Point of presence for implementing a secure subscriber identification module security service

An intermediary system between an access network and a target may receive a communication originating from a client and directed to the target. The intermediary system may generate, based a subscriber identification module (SIM) security service, a secure communication. The intermediary system may provide the secure communication to the target.
Owner:UAB 360 IT

Intelligent security service calling method based on MCP protocol

The invention belongs to the technical field of cipher machines, and discloses an MCP protocol-based intelligent security service calling method, which comprises the following steps of: defining a standardized MCP message structure, and creating a mapping relation table of an MCP instruction and a cipher machine API (Application Program Interface); constructing an MCP server interface module, and receiving an MCP format request sent by the AI agent; analyzing the request to determine a password operation type; converting the operation type into a corresponding cipher machine API call based on the mapping relation table; aPI calling and transmitting parameters are sent to the server cipher machine; and receiving an operation result, packaging the operation result into a response message according to the MCP message structure, and returning the response message to the AI agent. Through a standardized message structure and a mapping mechanism, the calling process of the cipher machine is simplified, and the technical threshold is reduced; and meanwhile, seamless connection between the AI application and the cipher machine is realized through an interface module and a session management mechanism, so that the AI system can call the hardware-level cipher service on the premise of ensuring the safety.
Owner:GUOXIN QUANTUM (BEIJING) TECH CO LTD +2

Federal recommendation privacy protection method and system based on ring signature and selective aggregation

The invention discloses a federal recommendation privacy protection method based on ring signature and selective aggregation, which realizes anonymization privacy protection and selective aggregation in a federal learning process through an innovative double-server architecture and a hierarchical security mechanism. The method comprises the following steps: 1) deploying an aggregation server and a security server in a system initialization stage, and completing parameter initialization and key distribution; 2) the client executes local model training, and anonymization privacy protection uploading is realized by adopting a ring signature technology; 3) the security server performs selective aggregation of credibility verification, and completes grouping and parameter fusion based on user similarity; and 4) ensuring the completeness and source credibility of model updating through a hierarchical security parameter distribution mechanism. While the recommendation precision is ensured, the user identity leakage and privacy tracking are effectively prevented, the comprehensive security guarantee is provided for the federal recommendation system, and the method has the advantages of low calculation overhead and high communication efficiency.
Owner:SOUTHEAST UNIV

Large language model (LLM) powered detection reasoning solution

Various techniques for LLM powered detection reasoning solutions are disclosed. In some embodiments, a system, a process, and / or a computer program product for an LLM powered detection reasoning solution includes monitoring network traffic at a security platform, wherein the security platform generates a sample based on the monitored network traffic; sending the sample to a security service to generate a Large Language Model (LLM) powered detection and reason, wherein the LLM is prompted to automatically generate a malware or benign verdict and a reason for explaining the verdict; and reporting the LLM powered detection and reason.
Owner:PALO ALTO NETWORKS INC

A medical image transmission method based on a 5G network

The application discloses a medical image transmission method based on a 5G network, and specifically comprises the following steps: step one, hardware architecture; step two, image acquisition and encapsulation; step three, decapsulation and restoration; and step four, fault-tolerant processing, and relates to the technical field of medical communication. The medical image transmission method based on the 5G network constructs a 5G network hardware framework system, utilizes the low-latency and high-speed characteristics of the 5G network for information transmission, and cooperates with a client, a slice information unit, a state information monitoring unit, a fault-tolerant information unit and an identification unit to form a client message system, utilizes a server, a transmission data record module, a slice image information module, a data information module and a data integration module to form a server end heat preservation system, and after encapsulation and decapsulation, the medical image with a large amount of data can be completely and quickly transmitted and saved to a remote secure server while ensuring the high-speed stability of the transmission environment.
Owner:NAT INST OF ADVANCED MEDICAL DEVICES SHENZHEN

Self-service business handling terminal based on social security and intelligent management method

The invention discloses a business self-service handling terminal based on social security and an intelligent management method, and relates to the technical field of data processing and analysis, and the method comprises the steps: building an integrated business processing platform, and integrating various social security business rules and processes; real-time connection with a social security policy issuing system is established, and the platform automatically acquires latest policy information based on changes of social security policies; through a preset rule engine, automatically adjusting the business process and the handling requirement according to the latest policy; a standardized communication interface and a data format are adopted, so that real-time sharing and interaction of data are realized by self-service handling terminals of all regions and departments; a central management server is established, and all terminal devices are managed and monitored in a unified mode. Through multi-service integration, real-time connection, the rule engine, the standardized interface and the central management server, the efficiency, convenience and safety of social security service self-service handling are improved, and the adaptability and the cross-regional cooperation capability of the system are enhanced.
Owner:JIANGSU SANSSAN INFORMATION TECH CO LTD

Security authentication method and device of vehicle-mounted equipment, electronic equipment and storage medium

The invention relates to a safety certification method and device of vehicle-mounted equipment, electronic equipment and a storage medium, and the safety certification method of the vehicle-mounted equipment is applied to a vehicle-mounted domain controller integrated with an HSM. The SOC generates a security service request containing to-be-processed data and an operation instruction according to the digital certificate and the identity authentication operation, and sends the security service request to the MCU; and the MCU receives and analyzes the security service request to obtain to-be-processed data and an operation instruction, and calls the HSM, and the HSM executes identity authentication type cryptographic operation on the to-be-processed data according to the private key and the operation instruction, and returns an operation result to the SOC. The HSM integrated in the vehicle-mounted domain controller realizes a security authentication function without externally hanging a special security chip, and the private key is always stored in the HSM and is not exported, so that the security of the vehicle identity key is ensured.
Owner:BEIJING PHOENIX AUTO INTELLIGENCE CO LTD

Method and apparatus for PDU session transfer across different access types

The present disclosure relates to a communication method and system for converging a 5th-Generation (5G) communication system for supporting higher data rates beyond a 4th-Generation (4G) system with a technology for Internet of Things (IoT). The present disclosure may be applied to intelligent services based on the 5G communication technology and the IoT-related technology, such as smart home, smart building, smart city, smart car, connected car, health care, digital education, smart retail, security and safety services. Disclosed is a method of determining, in a User Equipment, if a PDU session between the UE and a network, can be transferred between 3GPP and non-3GPP access, when the UE is using a Cellular Internet of Things, CIoT, optimisation, wherein the determination is performed on the basis of a Control Plane, CP, only indication and if the determination is positive, then the PDU session is not transferred.
Owner:SAMSUNG ELECTRONICS CO LTD

Method and apparatus for performing paging in a communication system

A communication method and system for converging a 5th-Generation (5G) communication system for supporting higher data rates beyond a 4th-Generation (4G) system with a technology for Internet of Things (IoT). The disclosure may be applied to intelligent services based on the 5G communication technology and the IoT-related technology, such as smart home, smart building, smart city, smart car, connected car, health care, digital education, smart retail, security and safety services. A method performed by a terminal comprises: receiving, from a base station, information indicating whether at least one paging message is to be transmitted in at least one paging occasion (PO) among a plurality of POs configured with the UE; identifying that the at least one paging message is to be transmitted in the at least one PO based on the information; and monitoring the at least one PO for receiving the at least one paging message.
Owner:SAMSUNG ELECTRONICS CO LTD