Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

139 results about "Trust level" patented technology

Trust Level. The Trust Level determines the actions that a program is allowed to perform. The Trust Levels are Super, Trusted, Restricted, Ask, Kill, and No Enforcement. A program’s Trust Level setting is determined by its policy. ZoneAlarm security software assigns policies to known programs automatically.

System and method for communication validation and multi-attribute trust scoring through cross-network intelligence correlation

A system and method for privacy-preserving communication validation and multi-attribute trust scoring is disclosed. The system analyzes communication metadata to determine pattern legitimacy by comparing current communication patterns against relationship fingerprints without accessing communication content. The system validates relationship context between communicating parties using interaction graph analysis and historical communication data. Cross-network intelligence correlation compares current patterns against aggregated patterns across voice, email, and messaging services, creating a self-strengthening security framework that recognizes emerging threat patterns while validating legitimate communication behaviors. The system generates comprehensive multi-attribute trust assessments comprising individual trust attribute scores including engagement rate, reliability index, channel preference, temporal pattern, and behavioral pattern, combined into overall trust levels. Trust context is displayed through a user interface presenting simplified, intuitive, and actionable information with progressive disclosure capabilities, enabling informed user decisions while preserving privacy. Communication processing actions provide users with appropriate engagement options tailored to specific trust assessment results.
Owner:ICA AI INC

Multi-level Internet of Things equipment security management and access control method

The invention belongs to the technical field of Internet of Things security, and particularly relates to a multi-level Internet of Things equipment security management and access control method, which comprises the following steps of: performing bidirectional verification on a digital certificate and a hardware fingerprint through an edge node when equipment is accessed; calculating credibility in real time and dynamically dividing security levels by using a hybrid evaluation algorithm based on equipment operation context data; a fine-grained access strategy is generated in combination with equipment attributes and environmental risks, and cross-level collaboration is realized through a lightweight protocol; abnormal behaviors are detected in real time in the access process, and high-risk operation is blocked within milliseconds; and strategy conflict resolution and adaptive optimization are realized through formalized verification and deep reinforcement learning. According to the technical scheme, the identity authentication reliability, the authority dynamic adaptability, the strategy consistency and the threat response speed of the Internet of Things equipment are remarkably improved, and a systematic security guarantee is provided for large-scale Internet of Things applications with high security requirements.
Owner:XIANNING YUCHUANG TECHNOLOGY CO LTD

Safety guarantee method for credible interaction of inland ship shore-based driving control data under zero-trust architecture

The invention relates to the technical field of ship navigation and data safety, solves the technical problem that an existing ship data safety guarantee system has defects in the aspects of data trust evaluation and data correction, and particularly relates to a safety guarantee method for credible interaction of inland ship shore-based driving control data under a zero-trust architecture. Comprising the following steps: standardizing operation data to obtain ship sensing data and shore-based data with the same dimension; based on an evidence theory, taking the ship sensing data and the shore-based data as independent evidence sources to perform fusion processing so as to obtain a trust evaluation result for quantitatively representing data credibility; and performing consistency correction on the ship sensing data and the shore-based data based on a least square method. According to the method, scientific and rigorous trust evaluation is realized, mathematical optimality of data fusion is guaranteed, and long-term reliability is ensured. Meanwhile, the credibility and the weight are directly associated with the equipment precision and historical data, so that an operator can flexibly adjust the system to adapt to different equipment.
Owner:ANHUI UNIV +3

Internet of Things data security system based on trust

The invention belongs to the technical field of data security, and particularly relates to a trust-based Internet of Things data security system, which comprises a hierarchical trust evaluation module used for converting equipment identity legality, data integrity and behavior compliance into quantifiable trust values through an identity-data-behavior three-dimensional model; and the dynamic trust updating module is used for realizing periodic updating of trust values, linkage authority control of trust levels, and abnormity repair and access blocking of low-trusted equipment according to trust data acquired in real time, and ensuring synchronization of a trust state and an actual safety condition of the equipment. According to the invention, a multi-factor identity authentication mechanism of equipment hardware fingerprint + dynamic token + cloud identity verification is constructed through the hierarchical trust evaluation module, so that equipment identity credible verification is realized, and the risks of identity counterfeiting and certificate leakage are resisted.
Owner:BEIJING CHUANGLIAN YUNRUI TECH CO LTD

Total-factor integrated large Token data management system and management method

The invention discloses a total-factor integrated large Token data management system, and the system comprises an identity credential collection unit which is used for obtaining an identity label and associated business data from a plurality of social subjects; the identifier abstraction unit is used for mapping the identity identifier into a standardized Token primary key according to a main body type and structuring the associated business data into a corresponding digital asset package; the total element aggregation unit is used for aggregating and packaging the digital asset package into a single verifiable large Token data structure, and the large Token comprises a Token primary key and a dynamic trust level; the dynamic trust engine is used for calculating and updating the trust level of each main body in real time and binding the trust level to the corresponding large Token; and the intelligent service execution unit is used for responding to an external business instruction and calling the large Token to realize intelligent service.
Owner:胡金钱 +2

Yellow storm terrorism content identification and filtering method and system

The invention discloses a yellow storm terrorism content identification and filtering method and system, and relates to the technical field of digital content auditing, and the method comprises the steps: carrying out the modal decomposition and preprocessing of a to-be-detected content, including the calculation of a single-modal sensitive probability and confidence, and recording the coordinates and confidence of a local image region; calculating a dynamic weight and performing normalization processing based on the confidence and the prior credibility of each mode; calculating a final fusion score by combining the sensitive probability and the weight of each mode, and performing content auditing decision according to a preset threshold value; and the modal priori credibility is updated through manual feedback data. According to the method, the detection rate of cross-modal violation contents is remarkably improved through a multi-modal collaborative analysis and confidence-driven dynamic fusion technology; and the system adopts a three-level decision-making mechanism to automatically allocate auditing resources, so that the manual rechecking cost is greatly reduced, meanwhile, an online learning function is introduced to continuously optimize the model, the sensitivity to novel violation contents is kept, and the processing efficiency and detail identification are both considered.
Owner:NANJING XINWANG VIDEO NETWORK TECH

Safety management and control method, system and equipment combined with biological characteristics and medium

The invention discloses a safety management and control method, system and equipment combined with biological characteristics and a medium, and the method comprises the steps: verifying the identity of a user in a manner of combining living body detection and behavior characteristic detection, and obtaining an identity verification result; calculating a trust score of the user in combination with a preset trust scoring model according to the identity verification result; dividing the users into N trust levels according to the trust scores, and configuring corresponding access permissions and security measures for each trust level; continuously monitoring physiological state change and operation behavior abnormity of the user in a user access process, and updating the trust score according to a monitoring result; and adjusting the trust level of the user through the updated trust score and a risk assessment algorithm. By constructing a zero-trust architecture based on multi-modal biological verification, the technical problems that a traditional power grid access control system is single in identity authentication and rigid in authority management are effectively solved.
Owner:GUIZHOU POWER GRID CO LTD

Equipment credibility judgment and data security guarantee method

The invention belongs to the technical field of information security, industrial internet of things and data credible transmission, and particularly relates to a device credibility judgment and data security guarantee method, which comprises the following steps: acquiring protocol interaction data and running state data of a third-party device in an industrial scene; based on the protocol interaction data and the operation state data, static features, dynamic features and associated features of equipment are extracted, and a dynamic adaptive behavior fingerprint model is constructed; presetting an evaluation index and a dynamic weight adjustment mechanism, and quantitatively evaluating the credibility of the equipment; carrying out importance layering according to the credibility of the equipment, and carrying out layered traceability data integrity verification by adopting a hierarchical hash abstract and encryption signature technology to obtain a verification result; and dividing trust levels based on the equipment credibility and a verification result, executing data access, interactive control and associated trust conduction, and performing equipment full-life-cycle dynamic trust management. Therefore, the problems of equipment identity authentication deficiency, equipment trust management staticization and the like in the prior art are solved.
Owner:ZHONGBO INFORMATION TECH RES INST CO LTD

Privacy protection AI decision system and method based on digital signature

The invention discloses a privacy protection AI decision making system based on digital signature, comprising a security chip which is internally provided with a cryptographic hash function H and is used for generating an irreversible large Token digital asset package through operation Token = H (ID + Datahash + TrustLevel) according to a user unique identity ID, an original data hash value Datahash and a dynamic trust level TrustLevel; the digital signature management module is used for generating a multi-level digital signature system, binding a digital signature with the multi-dimensional organization information and carrying out digital signature on the large Token digital asset package; the privacy protection module is used for calling the digital signature management module to carry out signature verification and triggering a desensitization program; and the AI large model interaction module is used for receiving the signed and desensitized large Token digital asset package and generating a decision result by utilizing AI analysis capability.
Owner:玺链科技有限公司 +4

Systems and methods for communications over near field communication channels

An improved approach is proposed for adapting available NFC channels to establish a bi-directional NFC channel where no such channel would otherwise be available. The approach is adapted for usage between a mobile device and a target receiver, such as a point of sale (POS) device, both having NFC capabilities. Specific approaches are proposed to orchestrate communications to prevent collisions. The NFC channels can be operated alongside secure elements to establish a dynamic cryptographic handshake that is used for enhancing trust levels for sensitive communications or transactions.
Owner:ROYAL BANK OF CANADA

Power terminal access attack behavior detection method and system based on multi-modal data fusion

The invention discloses a multi-modal data fusion-based power terminal access attack behavior detection method and system, and the method comprises the steps: collecting data through a specific collection tool, and carrying out the collection of four key indexes, namely, a traffic mode, a system log, signal strength and network topology; and an access security assessment detection model is constructed based on a Transform model of multi-modal feature fusion, and abnormal behaviors of the access terminal of the power Internet of Things platform are accurately identified. A system constructed according to the method comprises a collection unit, a processing unit, a behavior detection unit, a trust evaluation unit and a blocking unit, a deep learning algorithm is utilized to analyze multi-modal features, terminal behaviors are evaluated in combination with a trust evaluation mechanism, and trust levels are divided. According to the invention, an intelligent blocking rule strategy is provided for different abnormal behaviors, and the access safety and reliability of the electric power Internet of Things terminal are improved.
Owner:GUANGDONG POWER GRID CO LTD +1

Trust verification for consent-free out-of-band management of endpoint devices

A user may register with a fleet system responsible for remote management of a fleet of endpoint devices. The fleet system can determine a level of trust for the user based on information associated with an email address of the user and other information and register the user if the determined level of trust is sufficient. The registered user can request an activation token to be used for provisioning an endpoint device for consent-free out-of-band management. An endpoint device can be provisioned by the user submitting the activation token to the fleet service, the fleet service sending the activation token to the endpoint device, the endpoint device generating an ownership voucher request that includes the activation token, the fleet service verifying and validating the ownership voucher request, the fleet service returning a signed ownership voucher to the endpoint device, and the endpoint device verifying the signed ownership voucher.
Owner:INTEL CORP

Method, system and equipment for evaluating credibility of auxiliary driving system and medium

PendingCN121469604ADriver/operatorSimulation
The invention discloses an auxiliary driving system credibility evaluation method, system and device and a medium, and relates to the technical field of intelligent driving, and the auxiliary driving system credibility evaluation method comprises the following steps: obtaining the actual confidence of an auxiliary driving system in multiple dimensions; calculating a credibility index of the auxiliary driving system according to the actual confidence of the multiple dimensions; and determining the trust level of the auxiliary driving system according to the trust index of the auxiliary driving system. According to the invention, the operation state of the auxiliary driving system is quantified through the credibility index, so that a driver can accurately know the operation state of the auxiliary driving system in the use process.
Owner:DONGFENG AUTOMOBILE COMPANY

Host security alert methods, devices, equipment, and readable media in data centers

This disclosure provides embodiments of a host security early warning method, apparatus, device, and readable medium in a data center. One specific implementation of the method includes: collecting process information corresponding to processes running on a host to be monitored, and simultaneously collecting network port information corresponding to those processes; constructing a dynamic process feature library and a dynamic process baseline information set; and performing the following monitoring steps: collecting process information and corresponding network port information of processes on the host to be monitored; determining the collected process information and network port information as the behavior information of the process to be detected; performing dynamic risk detection processing based on the process liveness trust level of the behavior information of the process to be detected; performing dynamic baseline security detection processing on the behavior information of the process to be detected; and performing host security early warning processing on the host to be monitored. This implementation reduces the waste of early warning resources.
Owner:GUANGZHOU CLOUDSINO INFORMATION TECH CO LTD

Simple airborne collision avoidance system

PendingCN122337051ASimulationTrust level
This invention relates to the fields of unmanned aerial vehicle (UAV) technology and air traffic safety management, and discloses a simplified airborne collision avoidance system. The system includes a processor, a memory, and a communication interface. When the processor executes a computer program, it implements a multi-source perception and fusion unit, a trust assessment unit, a cooperative mode management unit, and a graded avoidance decision-making unit. It achieves compatibility with existing unsigned broadcasts through graded verification, marking targets with different trust levels and adjusting risk assessment weights accordingly. It identifies authorized targets through authorized cooperative modes, dynamically lowering safety distances or alarm thresholds within the authorized range, and distinguishing between non-contact and contact cooperation. It generates cooperative or non-cooperative avoidance commands through multi-level progressive risk assessment. It supports parsing dynamic sweep area description information from rotating obstacle broadcasts and reconstructing time-varying collision envelopes. This invention is flexible in deployment and can be installed on various aircraft and ground obstacles, improving low-altitude airspace collision avoidance safety.
Owner:CHONGQING YI XUNFEI EDUCATION CONSULTING CO LTD

An unmanned aerial vehicle data collection optimization method based on matrix completion and trust evaluation

PendingCN122373092AData packSimulation
This invention proposes an optimized method for drone data acquisition based on matrix completion and trust assessment, applicable to drone forensics in IoT network defense. First, in matrix completion, the sampling point locations and data packet acquisition times are constructed into a matrix, and matrix completion technology is used to recover all information and select sampling points. Second, in the drone flight trajectory, the selected sampling points and the Elite Ant Trail Optimization (EATO) algorithm are combined to optimize the drone's flight trajectory. Third, in the trust evolution mechanism, the comprehensive trust level of sensor nodes is obtained through dual evaluation by neighboring nodes and the drone. The proposed method can solve the security risks and resource consumption problems of data acquisition from IoT smart devices, effectively identify malicious nodes, optimize the accuracy of trust assessment, improve network security, and reduce drone energy consumption.
Owner:GUANGXI UNIV +1

Power grid terminal zero-trust access control method based on double-domain graph learning

The invention discloses a power grid terminal zero-trust access control method and system based on double-domain graph learning. The method comprises the steps that multi-dimensional data of a power grid are collected and preprocessed; constructing a variational auto-encoder model to perform fusion processing on the preprocessed data features to obtain a fusion feature vector; constructing a double-domain neural network model, constructing a topological domain graph according to a communication relationship between devices, constructing a feature domain graph by aggregating dynamic weights generated by real-time monitoring indexes, inputting a fusion feature vector into the double-domain neural network model, and generating a fusion embedded vector through double-domain message cross transmission and aggregation; and performing trust level division on the fusion embedding vector of the terminal, determining the risk level of the fusion embedding vector in combination with a preset threshold value, and automatically executing a corresponding permission allocation strategy according to the risk level to realize dynamic access control. The method provided by the invention can comprehensively describe the security state of the terminal and effectively identify the cooperative attack, and is suitable for intelligent security protection of the distributed terminal in a complex power grid environment.
Owner:STATE GRID HENAN ELECTRIC POWER ELECTRIC POWER SCI RES INST +4

Software supply chain security risk transmission assessment methods, devices, media and equipment

PendingCN122310545ATrust levelCumulative risk
This invention discloses a method, apparatus, medium, and equipment for assessing the transmission of security risks in the software supply chain, belonging to the field of computer software technology. This invention introduces dynamic risk transmission weights and time-series decay coefficients into the assessment of software supply chain security risks. It integrates factors such as component trust level, component dependency depth, and security control measures into dynamic risk transmission weights, accurately simulating the transmission and accumulation process of risks in complex supply chains. Furthermore, the introduction of a time-series decay coefficient precisely calculates the dynamic changes of risks over time. This invention achieves dynamic prediction and time-series modeling of software supply chain security risk transmission, simulating the natural decay of risks over time and providing an assessment synchronized with the actual security situation. The final output cumulative risk value accurately reflects the actual impact on target components, enabling precise location of high-risk indirect dependencies.
Owner:BEIJING TIMES XINWEI INFORMATION TECH CO LTD

A fresh agricultural product transport truck intelligent rapid detection method based on multi-source data fusion

The present application relates to the field of expressway green channel violation monitoring, and particularly relates to a kind of fresh agricultural products transport truck intelligent rapid detection method based on multi-source data fusion. Including the following steps: step one, build goods packaging loading proportion benchmark database and empty car mass benchmark database;Step two, collect total weight of loaded vehicle, actual vehicle information and transport goods information, obtain goods packaging loading proportion;Step three, obtain difference absolute value according to actual goods loading quality and theoretical maximum goods loading quality;Step four, determine trust level according to the ratio of difference absolute value and theoretical load;The trust level includes mild suspicion and severe suspicion;For the vehicle determined as severe suspicion, it is suggested to carry out artificial strict inspection, and the vehicle determined as mild suspicion is normally inspected. The present application can automatically identify insufficient loading, mixed loading goods and other various violations, significantly improve the accuracy and efficiency of green channel vehicle detection.
Owner:XIAN CHANGYUNKE TRANSPORTATION TECHNOLOGY CO LTD +3

Establishing and maintaining secure device communication

Techniques for dynamically generating a trust level for IoT devices are described. A plurality of characteristics of a first device of a first device type are analyzed against a set of expected characteristics for the first device type. Embodiments monitor runtime behavior of the first device for a time window to collect runtime behavior data and analyze the runtime behavior data of the first device to determine whether the device is operating in a manner consistent with the first device type. Upon determining that the analyzed plurality of characteristics are consistent with the set of expected characteristics and that the first device is operating in a manner consistent with the first device type, embodiments generate a security profile for the first device that designates the first device as a trusted device.
Owner:SCHNEIDER ELECTRIC USA INC

Authorization management method and system for SDN (Software Defined Network) software

The invention provides an authorization management method and system for SDN (Software Defined Network) software. Comprising the following steps: acquiring a user authorization request of SDN software, and verifying the legality of a user identity; collecting multi-dimensional parameters, wherein the multi-dimensional parameters comprise a real-time load of an SDN controller, a slice service priority, an edge node credibility level, an edge node computing power and a slice service time delay demand; dynamically calculating an authorization resource quota, an authorization credible threshold value and authorization timeliness based on the multi-dimensional parameters; judging whether the current credible value of the edge node is not lower than the authorization credible threshold, if so, executing authorization and allocating the authorization resource quota, and setting the authorization time efficiency; and the authorization execution state is monitored in real time, and if the variable quantity of any parameter in the multi-dimensional parameters exceeds a preset threshold value, safe and stable operation of the SDN network in the key field can be guaranteed.
Owner:HUANENG HULUNBEIER ENERGY DEV CO LTD

Power business scene-oriented operator scheduling method and device, medium and equipment

ActiveCN122044901AResource allocationHardware monitoringOperator schedulingTrust level
The invention discloses an operator scheduling method and device for a power business scene, a medium and equipment, and belongs to the field of scheduling. According to the method, power business data, data security level labels, computing power node resource states and trust level information are acquired, input and output protocols and resource demand fingerprints are analyzed and determined based on preset operator metadata portraits, a candidate node set is determined through preliminary screening, idle nodes are subjected to silent detection to acquire actual reasoning time consumption, and reasoning efficiency is improved. A multi-dimensional adaptation degree scoring model is input, a security mask value is determined according to comparison of a data security level and a trust level, after an adaptation degree score is comprehensively calculated, a target execution node, a distribution operator and data are output to complete local scheduling, and efficient self-adaptive scheduling of the heterogeneous operator at a cloud edge end is achieved. The problem that the AI operator cannot be accurately and efficiently scheduled in the prior art is effectively solved.
Owner:STATE GRID ZHEJIANG ELECTRIC POWER CO LTD +1

Power network boundary dynamic trust evaluation system and method based on multi-model parallel analysis

The invention discloses a power network boundary dynamic trust evaluation system and method based on multi-model parallel analysis. The system comprises a data acquisition and preprocessing subsystem, a multi-model parallel analysis subsystem, a model collaborative fusion subsystem and a trust level output subsystem. According to the method, the technical problems that short-time exceptions are difficult to capture, medium risks are difficult to recognize, complex threats are difficult to perceive and model collaboration is poor in novel power system boundary trust evaluation are solved, real-time, precise and graying evaluation of the trust state of a boundary entity (equipment / session / user) is achieved, and a reliable basis is provided for gray risk control.
Owner:CHINA SOUTHERN POWER GRID COMPANY

A smart grid information system access control method and device and storage medium

PendingCN122293432APathPingAttack
This invention provides an access control method, device, and storage medium for a smart grid information system, belonging to the field of smart grid information systems. The method includes: obtaining a time series of current performance indicators; calculating the trust level of intermediate nodes in data transmission using a trust assessment model; allocating transmission paths for each instruction based on its importance and the trust level of the intermediate nodes, thus obtaining a set of instruction paths; determining the access control level of the intermediate nodes based on the path set; and continuously evaluating the trust level of the uploading data source nodes during instruction issuance, and obtaining the transmission path for the uploaded data based on the access control level of the intermediate nodes, and then uploading the data. This invention can capture temporal dependencies, accurately reflect the real-time trust level of nodes, and adapt to changes in the dynamic network environment, effectively responding to sudden failures or attacks.
Owner:NANJING UNIV OF POSTS & TELECOMM

A safety control method and system for smart cockpits

PendingCN122310494ARealize refined management and controlImprove reliabilityAttackTrust level
This application discloses a security control method and system for smart cockpits. The solution acquires user authentication information, historical behavior baselines, and authentication features. It continuously collects current environmental and user behavior information, dynamically determines user trust levels based on the aforementioned information, and adjusts user operation permissions in real time according to the trust level. Upon detecting a user interaction command, it acquires multimodal signals within the corresponding time window of the command and performs multi-dimensional consistency verification on the command based on authentication features. Based on the verification results and the user's current operation permissions, it determines the command execution strategy. This application's technical solution achieves precise matching of permissions and real-time risks through dynamic trust level assessment. Relying on multimodal signal verification, it accurately identifies abnormal interactions and deception attacks, achieving refined security control of interaction commands. Through the coordinated decision-making of trust level, operation permissions, and interaction verification results, it improves the reliability and adaptability of smart cockpit security control.
Owner:NEUSOFT REACH AUTOMOBILE TECH (SHENYANG) CO LTD

A man-machine fusion scheduling method and system applied to a DCS operator station of a thermal power plant

The application relates to a man-machine fusion method and system applied to a DCS operator station of a thermal power plant, and aims to solve the technical problems of missing man-machine trust and low collaborative efficiency caused by the fact that the existing DCS system simply enhances machine intelligence and ignores man-machine deep fusion. The application builds a system architecture integrating operator physiological and behavioral monitoring, realizes real-time sensing of the states such as fatigue, stress and attention of the operator, and establishes a quantitative model to scientifically measure the dynamic trust level between man and machine. On this basis, the application proposes an adaptive man-machine interaction interface and a collaborative regulation mechanism based on game theory, dynamically allocates control authority according to the operator state and man-machine trust degree, realizes flexible switching of man-machine roles and intelligent resolution of decision conflicts. The application adaptively deeply fuses the experience wisdom of man and the intelligence of machine, and significantly improves the safety and decision efficiency of system operation under complex working conditions.
Owner:HUADIAN ELECTRIC POWER SCI INST CO LTD

Data security protection system applied to data display terminal

The invention relates to the technical field of data security protection, in particular to a data security protection system applied to a data display terminal, which comprises a security protection center, a data acquisition and processing module, a bidirectional trust verification module, a dynamic trust degree calculation module, a risk root positioning module and a back-end execution module, through a two-way verification mechanism, the defect that traditional one-way verification is prone to being hijacked and counterfeited is overcome, meanwhile, a dynamic trust degree scoring system is constructed based on three core dimensions of hardware health, network security and operation behaviors, quantitative evaluation and grading of the terminal security state are achieved, different trust levels are matched with differentiated protection strategies, and the safety of the terminal is improved. And for a low-trust-level terminal, a full-link data link is constructed, a preset risk feature library and a root identification model are combined, a single root and a composite root are accurately distinguished, the problem that in traditional protection, only warning is conducted, and positioning is difficult is solved, and blind rectification is avoided.
Owner:GUANGZHOU ZHONGLIPIN INTELLIGENT TECH CO LTD

Method of determining trust in computer network, computing system and storage medium

The invention relates to a method for determining trust in a computer network, a computing system and a storage medium. This disclosure describes techniques including evaluating trust in a computer network. In one example, the disclosure describes a method comprising: determining a trust level that a first network entity has for a second network entity; determining a trust level of the second network entity to the third network entity; determining that the first network entity is separated from the third network entity by the second network entity; determining a trust level of the first network entity to the third network entity based on the trust level of the first network entity to the second network entity and further based on the trust level of the second network entity to the third network entity; and enabling the first network entity to perform an operation with the third network entity based on the trust level of the first network entity to the third network entity.
Owner:JUNIPER NETWORKS INC

Security defense method and device for core network of industrial Internet of Things, and electronic equipment

The invention discloses a security defense method and device for an industrial internet of things core network and electronic equipment. The method comprises the following steps: acquiring protocol message data and a sensor time sequence signal; carrying out preprocessing, feature extraction and time sequence alignment processing to obtain standardized network feature data and sensor feature data; fusing the data to generate a joint feature vector; on the basis of the joint feature vector, calculating to obtain a dynamic association index for representing the collaborative abnormity of the physical state and the network behavior; comparing the dynamic association index with a preset threshold value, and generating an anomaly judgment result; determining a trust level corresponding to the network equipment based on a verification result of the equipment digital signature and a historical behavior; generating a defense strategy according to an abnormal judgment result and the trust level; and according to the defense strategy, cooperatively scheduling an industrial firewall to execute network isolation, a programmable logic controller to execute interface freezing, and a block chain system to execute security event evidence storage. According to the method, false alarm and missing alarm can be effectively avoided.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD

Transport layer security management using a management controller

Methods and systems for managing an endpoint device are disclosed. To do so, a key pair may be generated by a management controller of the endpoint device and a private key of the key pair may be kept secret by the management controller. A public key of the public private key pair may be provided to a first entity for use in generating a certificate for the endpoint device. The certificate may be provided to a second entity desiring a level of trust with the endpoint device. As a portion of establishing a secure connection between the second entity and the endpoint device, a TLS handshake may be performed. Performing the TLS handshake may include obtaining a TLS packet, signing the TLS packet using the private key, and providing the signed TLS packet to the second entity to demonstrate that the endpoint device is trustworthy for the level of trust.
Owner:DELL PROD LP