Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

373 results about "Security service" patented technology

Security service is a service, provided by a layer of communicating open systems, which ensures adequate security of the systems or of data transfers as defined by ITU-T X.800 Recommendation. X.800 and ISO 7498-2 (Information processing systems – Open systems interconnection – Basic Reference Model – Part 2: Security architecture) are technically aligned.

Adaptive dynamic energy coordination device for integrated renewable and conventional energy networks

A data-driven dynamic energy management system for the adaptive coordination of renewable and conventional energy sources, consisting of: a processing unit configured to perform real-time calculations to optimize the generation, storage, and distribution of electrical energy by continuously analyzing operational data, forecasting future energy demand, and generating control instructions to match available generation resources with forecasted consumption demand; a storage unit connected to the processing unit, configured to store records of historical energy production and consumption, environmental data, operating thresholds and learned model parameters, and to provide said data as input for the forecasting and optimization routines performed by the processing unit; a multitude of IoT-based monitoring units, each comprising at least one sensor configured to measure instantaneous parameters of generation, storage level, consumption rate and environmental conditions, with each monitoring unit being configured to periodically transmit measurement packets to the processing unit via a secure communication network; a forecasting unit implemented in the processing unit, configured to process historical and real-time data to create forecast curves for demand and generation using statistical and probabilistic forecasting techniques, and to dynamically update the weights of the forecasting model in response to observed deviations between forecasted and actual output; an optimization control unit implemented in the processing unit and configured to evaluate the outputs of the forecasting unit together with current operational data to determine a set of optimized control variables representing the target generation contribution of each energy source, and to pass these targets to a lower-level controller for execution; a controller that is communicatively connected to the processing unit and the multiple energy generation sources and is configured to regulate the operation of each source by adjusting the activation state, output level and operating priority based on the control signals received from the processing unit; an energy storage management unit comprising at least one battery array and a power conditioning circuit, configured to receive control instructions from the processing unit, store excess generated energy, release stored energy when forecasted demand exceeds available generation, and report charging and discharging characteristics in real time to the processing unit for continuous recalibration; an alarm and notification control unit connected to the processing unit, configured to continuously compare storage levels and generation reserves with stored operating thresholds, trigger predefined responses when critical or abnormal conditions are detected, and transmit acoustic, visual, and digital remote alerts to designated operators; a user interface terminal connected to the processing unit, configured to display real-time generation statistics, demand forecasts, energy storage status, and system alerts, and to accept operator-defined parameter inputs that are transmitted to the processing unit for recalibration of forecast or optimization parameters; and a secure server interface configured to synchronize operational logs, learning data, and performance indicators with a remote monitoring or analysis server for centralized monitoring, long-term data analysis, and distributed decision support.
Owner:CONEJERO RIQUELME NATALIA ELOISA +4

Secure identification system

The present disclosure relates to a method of enrolling an individual at a secure server and subsequently authenticating and identifying the individual at an authenticating party using an authentication token created during the enrolment and a secure server performing the method. The method comprises engaging, via a user device, in an enrolment process with the individual, registering the user device by receiving a public key, the public key being created by the user device along with a private key corresponding to the public key, acquiring a trusted identifier of the individual, associating the acquired trusted identifier of the individual with at least one database index to create an authentication token, the database index being utilized for look-up at the secure server, signing the authentication token, and sending the signed authentication token to the user device, while deleting the acquired trusted identifier at the secure server.
Owner:FINGERPRINT CARDS ANACATUM IP AB

Resource elastic scaling decision-making method, system and device and medium

The invention relates to a resource elastic scaling decision-making method, system and device and a medium. The method comprises the following steps: collecting real-time operation data of a security service node, and performing multi-dimensional security index analysis according to the real-time operation data to obtain a portrait data packet; predicting the security service weight value to obtain a prediction result, performing dynamic error compensation on the prediction result to generate a corrected weight prediction value, and generating a control instruction based on the corrected weight prediction value and the active session state; and when the instruction is a migration instruction, analyzing a session state snapshot of the instruction, calling a preset kernel state locking function to lock a memory session block of a source node, obtaining incremental state change data to generate a migration snapshot packet, and performing block verification injection operation on a target node. According to the method, by integrating multi-dimensional safety index analysis, prediction error compensation and stateful transition verification mechanisms, the accuracy and response efficiency of resource elastic scaling decision making are improved, and the continuity of stateful service transition and the consistency of safety strategies are enhanced.
Owner:STATE GRID INFORMATION & TELECOMM BRANCH +1

Internet asset vulnerability governance whole-process management method

The invention relates to a whole-process management method for internet asset vulnerability governance. The method comprises the following specific steps of task configuration, scanning task creation and execution, vulnerability list generation and work order distribution, vulnerability repair and multi-stage auditing, and data statistics and archiving. The efficiency is obviously improved; the whole process is online, so that the vulnerability management period is greatly reduced; the manpower cost is reduced: repeated docking of a third-party security team is not needed, the workload of security operation personnel is reduced, and manpower loss of offline communication is avoided at the same time; work order records, approval traces and scanning logs are archived in the whole process, a complete basis is provided for safety audit, an assessment report of a person in charge can be directly used for performance assessment, and the problem that no data exists in assessment is solved; and the rectification sheet state can be synchronized to all cadres in real time, information fault is avoided, and superior leaders can monitor the treatment progress in real time through the data statistics module and intervene in lagging links in time.
Owner:JIANGSU BAOWANGDA SOFTWARE TECH CO LTD

Network structure and service providing method for supporting multicast and broadcast service in mobile communication network

The present disclosure relates to a communication method and system for converging a 5th-Generation (5G) communication system for supporting higher data rates beyond a 4th-Generation (4G) system with a technology for Internet of Things (IoT). The present disclosure may be applied to intelligent services based on the 5G communication technology and the IoT-related technology, such as smart home, smart building, smart city, smart car, connected car, health care, digital education, smart retail, security and safety services. According to the present disclosure, MBS services for flexible and dynamic MBS service scenarios become possible in the next-generation wireless communication systems.
Owner:SAMSUNG ELECTRONICS CO LTD

Indoor robot target detection method and system based on multi-modal tracking and medium

The invention provides an indoor robot target detection method and system based on multi-modal tracking and a medium, and belongs to the field of robotics.The method comprises the steps that laser data processing is optimized through static furniture learning and filtering and dynamic region clustering, and the visual anti-illumination interference capacity is combined; a dynamic cost matrix matching strategy based on target motion characteristics is adopted to obtain a stable trajectory of a target person; kalman filtering trajectory prediction and target appearance feature matching are fused, and it is ensured that tracking can be rapidly recovered after the target is temporarily lost; a human-guided following mapping mode is adopted, a moving track of a tracked target is used as dynamic guidance, dynamic and static point clouds are separated, and a high-precision environment map with semantic tags is constructed; according to the invention, a following state monitoring and active service linkage mechanism is established, scene decision is carried out by identifying a target attitude and combining a semantic map, corresponding health monitoring and safety services are triggered, and the crossing from passive tracking to active intelligent services is realized.
Owner:EAST CHINA UNIV OF SCI & TECH

Point of presence for implementing a secure subscriber identification module security service

An intermediary system between an access network and a target may receive a communication originating from a client and directed to the target. The intermediary system may generate, based a subscriber identification module (SIM) security service, a secure communication. The intermediary system may provide the secure communication to the target.
Owner:UAB 360 IT

Intelligent security service calling method based on MCP protocol

The invention belongs to the technical field of cipher machines, and discloses an MCP protocol-based intelligent security service calling method, which comprises the following steps of: defining a standardized MCP message structure, and creating a mapping relation table of an MCP instruction and a cipher machine API (Application Program Interface); constructing an MCP server interface module, and receiving an MCP format request sent by the AI agent; analyzing the request to determine a password operation type; converting the operation type into a corresponding cipher machine API call based on the mapping relation table; aPI calling and transmitting parameters are sent to the server cipher machine; and receiving an operation result, packaging the operation result into a response message according to the MCP message structure, and returning the response message to the AI agent. Through a standardized message structure and a mapping mechanism, the calling process of the cipher machine is simplified, and the technical threshold is reduced; and meanwhile, seamless connection between the AI application and the cipher machine is realized through an interface module and a session management mechanism, so that the AI system can call the hardware-level cipher service on the premise of ensuring the safety.
Owner:GUOXIN QUANTUM (BEIJING) TECH CO LTD +2

Federal recommendation privacy protection method and system based on ring signature and selective aggregation

The invention discloses a federal recommendation privacy protection method based on ring signature and selective aggregation, which realizes anonymization privacy protection and selective aggregation in a federal learning process through an innovative double-server architecture and a hierarchical security mechanism. The method comprises the following steps: 1) deploying an aggregation server and a security server in a system initialization stage, and completing parameter initialization and key distribution; 2) the client executes local model training, and anonymization privacy protection uploading is realized by adopting a ring signature technology; 3) the security server performs selective aggregation of credibility verification, and completes grouping and parameter fusion based on user similarity; and 4) ensuring the completeness and source credibility of model updating through a hierarchical security parameter distribution mechanism. While the recommendation precision is ensured, the user identity leakage and privacy tracking are effectively prevented, the comprehensive security guarantee is provided for the federal recommendation system, and the method has the advantages of low calculation overhead and high communication efficiency.
Owner:SOUTHEAST UNIV

Large language model (LLM) powered detection reasoning solution

Various techniques for LLM powered detection reasoning solutions are disclosed. In some embodiments, a system, a process, and / or a computer program product for an LLM powered detection reasoning solution includes monitoring network traffic at a security platform, wherein the security platform generates a sample based on the monitored network traffic; sending the sample to a security service to generate a Large Language Model (LLM) powered detection and reason, wherein the LLM is prompted to automatically generate a malware or benign verdict and a reason for explaining the verdict; and reporting the LLM powered detection and reason.
Owner:PALO ALTO NETWORKS INC

Security authentication method and device of vehicle-mounted equipment, electronic equipment and storage medium

The invention relates to a safety certification method and device of vehicle-mounted equipment, electronic equipment and a storage medium, and the safety certification method of the vehicle-mounted equipment is applied to a vehicle-mounted domain controller integrated with an HSM. The SOC generates a security service request containing to-be-processed data and an operation instruction according to the digital certificate and the identity authentication operation, and sends the security service request to the MCU; and the MCU receives and analyzes the security service request to obtain to-be-processed data and an operation instruction, and calls the HSM, and the HSM executes identity authentication type cryptographic operation on the to-be-processed data according to the private key and the operation instruction, and returns an operation result to the SOC. The HSM integrated in the vehicle-mounted domain controller realizes a security authentication function without externally hanging a special security chip, and the private key is always stored in the HSM and is not exported, so that the security of the vehicle identity key is ensured.
Owner:BEIJING PHOENIX AUTO INTELLIGENCE CO LTD

Method and apparatus for PDU session transfer across different access types

The present disclosure relates to a communication method and system for converging a 5th-Generation (5G) communication system for supporting higher data rates beyond a 4th-Generation (4G) system with a technology for Internet of Things (IoT). The present disclosure may be applied to intelligent services based on the 5G communication technology and the IoT-related technology, such as smart home, smart building, smart city, smart car, connected car, health care, digital education, smart retail, security and safety services. Disclosed is a method of determining, in a User Equipment, if a PDU session between the UE and a network, can be transferred between 3GPP and non-3GPP access, when the UE is using a Cellular Internet of Things, CIoT, optimisation, wherein the determination is performed on the basis of a Control Plane, CP, only indication and if the determination is positive, then the PDU session is not transferred.
Owner:SAMSUNG ELECTRONICS CO LTD

Sidecar security pattern for agent communications

Systems and methods for securing agent communications in a multi-agent system including deploying an agent to communicate with external servers, instantiating a sidecar security service in communication with the agent and including at least one of a guardrails service, a security layer, an encryption module, and an integrity checker configured to validate resources tools using hash-based verification mechanisms. Communications including messages between the primary and the external servers are intercepted by the sidecar security service, which then performs at least one of filtering the one or more messages by the guardrails service, authenticating one or more server connections by the security layer, encrypting one or more outbound requests by the encryption module, or verifying an integrity of resources and tool definitions by the integrity checker.
Owner:MADISETTI VIJAY

System and method for secure web service access control

A computer system and method for populating electronic payment credentials is provided. The system comprises at least one processor and a memory storing instructions which when executed by the processor configure the processor to perform the method. The method comprises receiving a browser extension activation input, sending a payment details request message to a financial institution system, receiving payment details from the financial institution system following authentication at a mobile device, and populating a payment form on the browser using the payment details.
Owner:ROYAL BANK OF CANADA

Wireless network transport service security

An apparatus, method and computer-readable media are disclosed for accessing services of wireless network. For example, a process can include receiving, from a wireless device, a service session request to access a service of the wireless network; determining a user plane security anchor (UPSA) for the service and the wireless device; transmitting, to a security service of the wireless network, a request for UPSA security for the service; receiving, from the security service, a response to the request for UPSA security including information for deriving a service key; and transmitting, to the wireless device, a response to the service session request including an identifier for the UPSA and the information for deriving the service key for establishing user plane security between the UPSA and the wireless device.
Owner:QUALCOMM INC

Identity-based distributed cloud firewall for access and network segmentation

According to some embodiments, a method of controlling access to network resources includes: receiving an authentication request from a user device to a core security service; if the user is authenticated, authorizing the user device to connect to a private cloud, and connecting the user device with the private cloud and retrieving user-specific segmented firewall rules stored in the private cloud; routing, through the firewall rules, a request by the user device to access an outer resource; evaluating the request against the firewall rules; if the request meets the firewall rules, routing the request through security measures of the firewall; and if the request does not meet the firewall rules, denying the user device access to the outer resource.
Owner:720 IT UAB

Enterprise-level MCP service calling method, device, equipment, medium and product

The invention discloses an enterprise-level MCP service calling method and device, equipment, a medium and a product, and relates to the field of enterprise-level artificial intelligence security services, and the method comprises the steps that an LLM interaction module generates an MCP tool calling list according to a user service request and a user token, and signs the token and the list; the MCP module verifies the signature; the authentication module obtains a field white list according to the token and the list; the MCP module signs the token, the list and the field white list; the service module verifies the signature and sends a result to the MCP module; the MCP module filters and desensitizes the result to obtain a security result, and signs the security result; the LLM interaction module verifies the signature, and inputs a security result and a user service request into a large language model to obtain a natural language reply, the application can realize the problems of dynamic minimum permission, trusted transmission and sensitive data compliance and desensitization, and meets enterprise-level permission control requirements.
Owner:SHANGHAI OUYE FINANCIAL INFORMATION SERVICE CO LTD

Secure Document Certification and Execution System

Methods and systems for secure media processing may be used to execute and certify a digital media asset by verifying that the digital media asset is authentic and has not been altered since capture. In some cases, these secure media processing techniques may be used in the mobile certification and execution application and a corresponding server system. The mobile application and the corresponding server system may automatically generate finalized documents upon receiving certified digital media and the corresponding metadata from the users. The digital media and other information from the users may be received while the user is in communication with other users. A biometric and artificial intelligent feature recognition system may be utilized to receive biometric data and verify identity. Data transferred to a secure server are accessible by various parties involved in the certification and execution process to provide transparency.
Owner:IMAGEKEEPER LLC

Inline detect and block relayed DNS tunneling traffic

The present application discloses a method, system, and computer system for detecting DNS tunneling traffic. The method includes (i) obtaining non-DNS network traffic across an enterprise network, (ii) obtaining a hostname comprised in the non-DNS network traffic, (iii) querying a security service for a Domain Name System (DNS) tunneling attack verdict based at least in part on the hostname, (iv) determining whether the non-DNS network traffic is malicious traffic based at least in part on the DNS tunneling attack verdict, and (v) handling the non-DNS network traffic based at least in part on a determination of whether the non-DNS network traffic is malicious traffic based at least in part on the DNS tunneling attack verdict.
Owner:PALO ALTO NETWORKS INC

Signal transmission method, apparatus, electronic device and computer readable storage medium

The present disclosure relates to a communication method and system for converging a 5th-Generation (5G) communication system for supporting higher data rates beyond a 4th-Generation (4G) system with a technology for Internet of Things (IoT). The present disclosure may be applied to intelligent services based on the 5G communication technology and the IoT-related technology, such as smart home, smart building, smart city, smart car, connected car, health care, digital education, smart retail, security and safety services. The present disclosure provides a signal transmission method, apparatus, electronic device and computer readable storage medium.
Owner:SAMSUNG ELECTRONICS CO LTD

Explicit proxy inline security

A plurality of logs for a cloud security service for a plurality of tenants are captured. A network traffic pattern associated with the plurality of logs is analyzed and a security related impact analysis is determined. An action is performed based on the security related impact analysis.
Owner:PALO ALTO NETWORKS INC

Web analyzer engine for identifying security-related threats

Techniques are described for providing a threat analysis platform capable of automating actions performed to analyze security-related threats affecting IT environments. Users or applications can submit objects (e.g., URLs, files, etc.) for analysis by the threat analysis platform. Once submitted, the threat analysis platform routes the objects to dedicated engines that can perform static and dynamic analysis processes to determine a likelihood that an object is associated with malicious activity such as phishing attacks, malware, or other types of security threats. The automated actions performed by the threat analysis platform can include, for example, navigating to submitted URLs and recording activity related to accessing the corresponding resource, analyzing files and documents by extracting text and metadata, extracting and emulating execution of embedded macro source code, performing optical character recognition (OCR) and other types of image analysis, submitting objects to third-party security services for analysis, among many other possible actions.
Owner:CISCO TECHNOLOGY INC

Provider substrate extension connectivity using secure service links

ActiveUS12719842B1Substrate networkEngineering
Techniques for utilizing a cloud-side link module and a provider substrate extension (PSE) link module to secure a communications channel between a cloud provider network and a provider substrate extension are described. A PSE link module receives a request originated by a compute instance in the PSE that is destined to a destination within the cloud provider network. The request was encrypted using an encryption scheme that encrypts traffic of a virtual private cloud that the compute instance operates in. The PSE link module decrypts the first request, encrypts it using a separate encryption scheme, and transmits it via a secure tunnel to a second link module in the cloud provider network. The second link module can decrypt the encrypted traffic and cause it to be validated before it is passed on via the cloud provider's substrate network to be processed.
Owner:AMAZON TECH INC

Low-code informatization system, method and arm server

The disclosure provides a low-code informatization system and method and an ARM server, relates to the field of cloud services, and particularly relates to the field of ARM chips. A specific implementation scheme is as follows: the ARM server comprises at least one ARM board card, each ARM board card is deployed with a cloud platform, a technical component, a business middle station and an application front desk; a firewall is connected with the ARM server and is deployed with at least one security service product; and a user equipment accesses the ARM server through the firewall and is deployed with a low-code development tool. The implementation manner not only meets the demand of informatization construction for server computing power, but also greatly reduces the use cost and saves storage space compared with a server based on an X86 architecture under the condition of the same effect, and one-stop delivery of a traditional industry informatization system is realized.
Owner:BEIJING BAIDU NETCOM SCI & TECH CO LTD

User plane security anchor for wireless network service security architecture

Apparatus, methods, and computer-readable media for performing wireless communication are disclosed. For example, a method for securely accessing a service may include receiving, by a secure service from a service, a request for a service key for accessing the service, the request for the service key including an indication of using a user plane security anchor (UPSA); sending a service key response including the service key from the secure service in response to the request for the service key; receiving an indication of a UPSA key, the indication including an identifier of the UPSA for the service; generating the UPSA key based on the identifier of the UPSA; and sending the generated UPSA key to the UPSA for establishing a user plane security context between the UPSA and a wireless device.
Owner:QUALCOMM INC

Method and apparatus for handling response timer and cell reselection for small data transmission

A communication method and system for converging a 5th generation (5G) communication system for supporting higher data rates beyond a 4th generation (4G) system with a technology for Internet of things (IoT) are provided. The communication method and system includes intelligent services based on the 5G communication technology and the IoT-related technology, such as smart home, smart building, smart city, smart car, connected car, health care, digital education, smart retail, security and safety services. A method performed by a terminal for small data transmission (SDT) in a wireless communication system is provided.
Owner:SAMSUNG ELECTRONICS CO LTD

A personal application level global quantum secure encryption proxy gateway and communication system

The application discloses a personal application level global quantum security encryption proxy gateway and a communication system. Only the terminal application of a general terminal which needs to interact with a business application protected by global quantum security can establish a secure session with a security proxy module in the personal application level global quantum security encryption proxy gateway and determine a session key through negotiation, so that the personal application level global quantum security encryption proxy gateway can provide quantum security service for the general terminal based on specific applications, instead of protecting all business applications on the general terminal by quantum security, thereby avoiding affecting normal access of the general terminal to public network services. Moreover, the business data is encrypted and interacted by using a national secret / commercial secret symmetric encryption algorithm based on the established secure session and the negotiated session key, so that the security and confidentiality of the business data in the transmission process are ensured.
Owner:MATRICTIME DIGITAL TECH CO LTD

Automated attack chain following by a threat analysis platform

Techniques are described for providing a threat analysis platform capable of automating actions performed to analyze security-related threats affecting IT environments. Users or applications can submit objects (e.g., URLs, files, etc.) for analysis by the threat analysis platform. Once submitted, the threat analysis platform routes the objects to dedicated engines that can perform static and dynamic analysis processes to determine a likelihood that an object is associated with malicious activity such as phishing attacks, malware, or other types of security threats. The automated actions performed by the threat analysis platform can include, for example, navigating to submitted URLs and recording activity related to accessing the corresponding resource, analyzing files and documents by extracting text and metadata, extracting and emulating execution of embedded macro source code, performing optical character recognition (OCR) and other types of image analysis, submitting objects to third-party security services for analysis, among many other possible actions.
Owner:CISCO TECHNOLOGY INC