Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

14 results about "Transport Layer Security" patented technology

Transport Layer Security (TLS), and its now-deprecated predecessor, Secure Sockets Layer (SSL), are cryptographic protocols designed to provide communications security over a computer network. Several versions of the protocols find widespread use in applications such as web browsing, email, instant messaging, and voice over IP (VoIP). Websites can use TLS to secure all communications between their servers and web browsers.

Application certificate provisioning process using connected vehicle

An example operation includes one or more of establishing a secure channel between a host platform and a vehicle based on a transport layer security (TLS) handshake between the host platform and the vehicle, downloading an authorization code to the vehicle through the secure channel between the host platform and the vehicle, receiving the authorization code from a mobile application installed on a mobile device, generating a mobile application certificate for the mobile device and transmitting the mobile application certificate to the mobile application on the mobile device, and establishing a secure connection between the host platform and the mobile application on the mobile device based on the mobile application certificate.
Owner:TOYOTA MOTOR NORTH AMERICA INC +1

Security enhancement methods and systems for the IEC 104 protocol on the master station side of power monitoring systems

PendingCN122339686AIEC 62351Embedded system
This invention discloses a security enhancement method and system for the IEC 104 protocol on the master station side of a power monitoring system, comprising: generating input data, dynamically selecting a security mode and issuing configuration commands, generating original ASDU messages, calling application-layer security plugins to generate enhanced ASDU messages, encapsulating them into complete APDUs, generating security messages via transport-layer security plugins, and sending them to the station. This invention adopts a plug-in embedded architecture, integrating IEC 62351-5 application-layer and IEC 62351-3 transport-layer security plugins into the protocol processing module and communication processing module respectively, achieving decoupling of security functions and business functions; establishing a policy-driven mechanism, adding a security policy management module and an operation monitoring module, and providing port differentiation to adapt to different terminals to meet the needs of gradual transformation; controlling terminal concurrent connection latency at the millisecond level to meet the needs of large-scale high-concurrency access at the master station, and establishing a layered security protection system that coordinates the transport layer and application layer, ensuring message security even if transport layer security fails.
Owner:NARI NANJING CONTROL SYSTEM CO LTD +1

Method to migrate workload between two environments and a system thereof

ActiveUS12676835B2Transport layerWorkload
A method to migrate workload between a single node environment and a multi-node environment over a Transport Layer Security (TLS) network, the method comprises running an application on a first machine in a first environment, wherein the first environment is any one of the environments. The method further comprises generating a first file for the application running on the first machine and storing the first file and the workload created from the first file in the first machine. The method further comprises accessing a second machine that runs a container cluster in a second environment, wherein the second environment is different from the first environment. The method further comprises reading a second file from the container cluster and storing the second file in the first machine. The method further comprises connecting the first machine to the container cluster of the second machine using access information stored in the second file.
Owner:RED HAT INC

Power transmission line monitoring data security protection method and device based on encrypted transmission

This invention relates to the field of data encryption technology and proposes a method and device for secure protection of transmission line monitoring data based on encrypted transmission. The method includes: performing certificate chain verification on the digital certificate of the security proxy gateway and performing a transport layer security protocol handshake to obtain a bidirectional encrypted communication tunnel; performing key derivation on the session key factor and device key of the security proxy gateway to obtain a dynamic session key; performing symmetric encryption on the data payload and digitally signing the obtained encrypted data block to obtain a secure data message; delivering the secure data message to the security proxy gateway through the bidirectional encrypted communication tunnel to obtain the message reception status; performing symmetric decryption on the encrypted data block and performing digital signature verification to obtain the data payload to be verified and the signature validity verification result; and performing protocol adaptation encapsulation on the data payload to be verified to obtain a security audit log. This invention can improve the efficiency of security protection for transmission line monitoring data.
Owner:FUJIAN SHENGYAO TECHNOLOGY GROUP CO LTD

A method and system for adaptive enhancement of a vehicle-mounted TLS configuration

ActiveCN121711190BRevolutionizing the static configuration modelimprove throughputSecuring communicationComplex mathematical operationsCommunications securityKey size
The application provides a kind of vehicle-mounted TLS configuration adaptive enhancement method and system, the method includes real-time acquisition from the multi-source heterogeneous data of different sources of vehicle;State estimation algorithm is used to fuse the multi-source heterogeneous data processing, generate the fusion state vector representing current driving scene;Based on the fusion state vector, multi-dimensional risk assessment is carried out, the comprehensive risk score is calculated and the risk level is judged;Based on the risk level, the configuration parameters of the transport layer security TLS protocol are optimized by using multi-objective optimization algorithm to generate TLS configuration strategy;The configuration parameters at least include encryption suite and key length;The TLS configuration strategy is executed, and the performance index is monitored, and the performance index obtained by monitoring is fed back to the step of generating the fusion state vector, to form a closed loop control, crack the inherent problem that communication security, real-time performance and resource constraints are difficult to be considered in vehicle dynamic environment.
Owner:NANCHANG AUTOMOTIVE INST OF INTELLIGENCE & NEW ENERGY +1

Securely synchronize cloud vault to mobile application for automotive telematics

An example operation includes one or more of establishing a secure channel between a host platform and a vehicle based on a transport layer security (TLS) handshake between the host platform and the vehicle, downloading an authorization code to the vehicle through the secure channel between the host platform and the vehicle, receiving the authorization code from a mobile application installed on a mobile device, the mobile application comprising a decryption key, encrypting secrets for the mobile application to use to communicate with the host platform using an encryption key that corresponds to the decryption key, transmitting the encrypted secrets from the host platform to the mobile application, and establishing a connection between a telematics system of the host platform and the mobile application based on the secrets.
Owner:TOYOTA MOTOR NORTH AMERICA INC +1

Safely synchronizing cloud vaults to mobile applications for automotive telematics

This application relates to securely synchronizing a cloud vault to a mobile application for automotive telematics. Example operations include one or more of: establishing a secure channel between a host platform and a vehicle based on a transport layer security (TLS) handshake between the host platform and the vehicle; downloading an authorization code to the vehicle over the secure channel between the host platform and the vehicle; receiving the authorization code from a mobile application installed on a mobile device, the mobile application including a decryption key; encrypting a secret used by the mobile application to communicate with the host platform using an encryption key corresponding to the decryption key; transmitting the encrypted secret from the host platform to the mobile application; and establishing a connection between a telematics system of the host platform and the mobile application based on the secret.
Owner:TOYOTA MOTOR NORTH AMERICA INC

Controlling communications among secure virtual machines

Controlling communications among secure virtual machines is achieved by introducing a time-expiring mutual TLS (transport layer security) certificate, also referred to as an mTLS certificate. The mTLS certificate is controlled by an mTLS certificate issuer on a secure virtual machine, which operates to attest a secure workload virtual machine. An mTLS certificate issuer is deployed on a secure virtual machine. The mTLS certificate issuer is attested to by the deploying trusted execution environment. Workloads on secure virtual machines are configured to use only mTLS certificates issued by an mTLS certificate issuer.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Application certificate provisioning process using a networked vehicle

The present application relates to application credential provisioning processes using networked vehicles. Example operations include one or more of: establishing a secure channel between a host platform and a vehicle based on a transport layer security (TLS) handshake between the host platform and the vehicle; downloading an authorization code to the vehicle over the secure channel between the host platform and the vehicle; receiving the authorization code from a mobile application installed on a mobile device; generating a mobile application credential for the mobile device and transmitting the mobile application credential to the mobile application on the mobile device; and establishing a secure connection between the host platform and the mobile application on the mobile device based on the mobile application credential.
Owner:TOYOTA MOTOR NORTH AMERICA INC

Hybrid cloud bridge system for synchronizing legacy data

UndeterminedDE202026103261U1Data synchronizationSchema mapping
A hybrid cloud bridge system (100) for synchronizing legacy data between on-premises IBM i systems and AWS cloud instances, the system comprising: an on-premises legacy interface module configured to connect to one or more IBM i (AS / 400) systems via native data access protocols, including Distributed Relational Database Architecture and Distributed Data Management, the module further comprising a journal read component for capturing change data in real time from IBM i journal subsystems; a data transformation engine operatively coupled with the on-premises legacy interface module and configured to convert data between the EBCDIC encoding native to IBM i systems and the UTF-8 encoding required by cloud-native applications, the engine comprising an EBCDIC-to-UTF-8 converter, a schema mapping processor, a data validation unit, and a format serializer;a secure communication gateway that establishes encrypted communication channels between the on-premises network and the AWS cloud environment using mutual Transport Layer Security authentication with a pure outbound connection model; a cloud integration module deployed within the AWS cloud environment that includes service adapters for connecting to AWS services; a synchronization controller configured to coordinate bidirectional data synchronization operations via data change detection mechanisms; and a conflict resolution module that implements vector-clock-based versioning to detect and resolve conflicts during concurrent changes;characterized by the fact that the system acts as an intermediary bridge, performing bidirectional real-time synchronization between IBM i legacy systems and AWS cloud instances through integrated data format transformation, secure tunneled communication, and vector clock-based conflict resolution, without requiring any changes to the legacy application code or database schemas.
Owner:VAIDYANATHAN SWAMINATHAN

A network and information security defense method and system based on multi-dimensional threat perception

PendingCN122316768ACritical information infrastructureEngineering
This invention discloses a network and information security defense method and system based on multi-dimensional threat perception, relating to the field of network and information security technology. This invention obtains mirrored traffic data from key network nodes, separates transport layer security protocol handshake messages and application data messages, extracts unencrypted handshake metadata from client and server greeting messages using a first perception channel, generates a multi-dimensional static fingerprint vector, extracts the application layer payload length sequence using a second perception channel, calculates the packet length state transition probability distribution as a dynamic behavior feature vector, and jointly encodes the static fingerprint vector and dynamic behavior feature vector, inputting it into a shallow graph convolutional network to output a malicious confidence score. When the score exceeds a threshold, session-level blocking is executed. This achieves high-precision detection of encrypted malicious traffic without decrypting the traffic, and is suitable for encrypted traffic security protection scenarios at enterprise network boundaries, cloud data centers, and critical information infrastructure.
Owner:YUANCHUN (XUZHOU) NETWORK TECHNOLOGY CO LTD

Bot detection in an edge network using the transport layer security (TLS) fingerprint

ActiveDE602018092284T2Transport layerTransport Layer Security
Owner:AKAMAI TECHNOLOGIES INC

Methods and entities for authenticating application program interface (API) callers

A 5G or near-5G communication system is disclosed to support higher data transmission rates than systems following 4G communication systems such as LTE. Embodiments herein disclose a method and system for authenticating application interface (API) callers using the Common Application Interface Framework (CAPIF). The method includes: upon receiving a connection request from at least one API caller to access at least one service API on a CAPIF-2e interface, establishing a secure transport layer security (TLS) connection with the at least one API caller. Furthermore, the method includes: determining at least one security method by the CCF, which will be used by the at least one API caller for CAPIF-2e Interface Security (C2eIS) of the at least one API caller to access the at least one service API on the CAPIF-2e interface. The method also includes enabling C2eIS for the at least one API caller by the API Exposure Function (AEF) based on the determined at least one security method.
Owner:SAMSUNG ELECTRONICS CO LTD

A communication method, device and storage medium based on a transport layer security protocol

The application provides a communication method and device based on a transport layer security protocol and a storage medium, relates to the technical field of communication, and can use a non-certificate key information to replace a traditional certificate in a communication process based on the transport layer security protocol, so that bandwidth resources occupied by a certificate transmission process are reduced in the communication process. The method comprises the following steps: in a second handshake process based on the transport layer security protocol, receiving non-certificate key information of a server sent by a server, wherein the non-certificate key information of the server comprises an identifier of a first signature public key and an identifier of a first encryption public key; in a third handshake process based on the transport layer security protocol, verifying the non-certificate key information of the server based on the identifier of the server; and after verification, sending non-certificate key information of a client to the server, wherein the non-certificate key information of the client comprises an identifier of a second signature public key and an identifier of a second encryption public key.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD +1