Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

26 results about "Trust network" patented technology

The Trust Network is a network for all independently run, state-funded schools providing its members with an opportunity to share best practice and exchange knowledge.

Using endpoint identity for network data flow and topology orchestration

PendingUS20260189408A1Data packData stream
Embodiments relate to a computer-implemented method for managing zero-trust network communications. The method includes validating the identity of a first remote endpoint using a cryptographic credential received from the first endpoint and determining the first endpoint's authorization to communicate with a second remote endpoint. Upon successful validation and authorization, the method initiates the establishment of a network packet route between the first and second remote endpoints. Later, the method further initiates the destruction of the network packet route between the two endpoints.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Zero-trust web session caching

Devices, systems, machine-readable media, and methods for web session caching with improved security are provided. A method can include receiving, at the multi-tenant cache and from a web-based client, a first request to perform an operation on web session data in the multi-tenant cache, issuing, by the multi-tenant cache, a validation request to an authorization service, receiving, by the multi-tenant cache, a result of the validation request, responsive to determining the result of the validation request is a valid verification, performing the operation on the multi-tenant cache, and issuing, by the multi-tenant cache and to the web-based client, a response to the first request.
Owner:RAYTHEON CO

Access control method, apparatus, device, medium, and product

PendingCN122372254AEngineeringContext data
This application discloses an access control method, apparatus, device, medium, and product, relating to the field of communication technology. The access control method includes: when a terminal senses a switch from a trusted network environment to an untrusted network environment, the proxy terminal sends a long-connection request to a target business system; acquiring processing data of the target business system's response to the long-connection request, performing trustworthiness verification based on the processing data and the switching context data, and generating a restricted access credential for the terminal and enabling a one-way isolation mode for the terminal when the trustworthiness verification result is positive; with the one-way isolation mode enabled, authenticating the terminal's access behavior command to the target business system based on the restricted access credential, sending the access behavior command to the target business system after successful authentication, and filtering the response data received from the target business system before sending the filtered response data to the terminal.
Owner:CHINA MOBILE ONLINE SERVICES CO LTD +1

AI large model driven sd-wan zero trust network unknown threat accurate detection system

PendingCN122372292AAlgorithmAttack
This invention relates to the field of network security technology and discloses an AI-driven large-scale model-based system for accurately detecting unknown threats in SD-WAN zero-trust networks. The system employs a data acquisition and processing module to capture encrypted tunnel packet sequence characteristics and arrival interval timelines, and associates them with identity token hashes. A semantic threat analysis module runs a Transformer large-scale model to perform encoding inference and baseline comparison to determine session threat confidence. An unknown feature solidification module stores abnormal pattern fingerprints to support variant attack retrieval. A trust policy adjudication module generates dynamic trust credentials based on exponential decay and compiles permission revocation instructions. An encrypted tunnel control module uses a quantum key protection strategy to distribute channel traffic and redirect high-risk traffic to an isolated domain. A closed-loop evolution and maintenance module combines edge inference and model fine-tuning for continuous optimization. This system accurately identifies hidden threats without decryption, providing efficient detection and real-time blocking protection for IoT security.
Owner:BEIJING XINDA WANGAN INFORMATION TECH CO LTD

User Trust Measurement Methods and Systems in Zero-Trust Network Environments

ActiveCN116455668BSolving the trust measurement problemReduce the risk of attack spreadingSecuring communicationInternet privacyRemote control
This invention discloses a user trust measurement method and system in a zero-trust network environment. It pre-collects user information, token information, device information, and system information, and generates an access control list. When a device sends a request, a risk assessment is performed on the request, followed by authentication. Based on historical access data, the request status is determined. Based on the authentication result and request status, it is determined whether authorization is allowed. If authorization is not allowed, the request is marked as a device anomaly. Based on the device's abnormal behavior, it is determined whether the device belongs to the category of remote control anomalies. If so, the access permissions of devices connected to and interacting with this device in the access control list are updated. This reduces the risk of network attack risk propagation in a zero-trust network environment.
Owner:SOUTHEAST UNIV

An asphalt pavement maintenance evaluation method based on a Bayesian sparse trust network

The present application relates to the technical field of asphalt pavement maintenance evaluation, and particularly relates to an asphalt pavement maintenance evaluation method based on a Bayesian sparse trust network, comprising: taking a Page Rank dynamic trust relationship as a framework, constructing a trust network among indexes through initial trust, secondary trust and a decay factor, and realizing dynamic evolution of evaluation weights; introducing a Bayesian inference theory, probabilistically modeling the decay factor, secondary trust and noise variance, and using an MH algorithm for posterior sampling to quantize uncertainty of evaluation results; applying a regularization sparse constraint to suppress interference of weakly correlated indexes and focus on core indexes such as rut depth and crack rate. The three are organically coordinated to form an integrated evaluation framework of "dynamic weight evolution-uncertainty quantization-core index focusing", and finally, aiming at the engineering characteristics of multiple indexes, strong coupling and uncertain information of asphalt pavement preventive maintenance evaluation, the maintenance evaluation highly matched with the actual technical condition is realized.
Owner:NANTONG UNIV

Zero trust network infrastructure with location service for routing connections via intermediary nodes

A location service for automatic discovery of locations at which instances of an internal enterprise application are located. The service facilitates routing of connection requests directed to the internal enterprise application, which typically is hosted in distinct enterprise locations. The service works in association with connectors that each have an associated public Internet Protocol (IP) address (typically of a device to which the connector is coupled) through which a connection to an internal enterprise application instance can be proxied. Connections to the internal enterprise application are routable along a network path from a client to a given connector through a set of intermediary nodes. Using information collected from the connectors, the service performs a series of correlations (viz.., finding matching connections and their corresponding public IP addresses) to enable service provider mapping technologies to make both global and local traffic mapping decisions for these internal enterprise resources.
Owner:AKAMAI TECHNOLOGIES INC

Access control method, access credential generation method, and access control system

One or more embodiments of the present disclosure provide an access control method, an access credential generation method, and an access control system, capable of being applied to a cloud platform. Specifically, an internal trusted network range of a platform corresponding to a target account can be acquired to generate an address whitelist for the target account; and an access credential is generated for the target account on the basis of the address whitelist. A cloud platform gateway receives an access request sent by the target account, and then extracts the address whitelist of the target account from the access credential carried in the access request; and in response to a source address of the access request not matching the address whitelist, the cloud platform gateway determines that the access request does not pass address authentication, and intercepts the access request. The solution can effectively prevent an attacker from accessing a cloud platform via an unauthorized network after the leakage of an access credential, thereby improving the security of the cloud platform, and achieving platform-level access credential security management.
Owner:CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD +1

Access control method and related device

ActiveCN115603927BData packEngineering
An access control method and related device, the method comprising: a security management function receiving a first configuration request message sent by a user plane management function, the first configuration request message being used to request configuration of access rights of a first service / first service instance on a first processing link to data packets on the first processing link; the security management function determining first access rights of the first service / first service instance to the data packets on the first processing link, and sending configuration information of the first access rights to a first node, the first node being a node on which the first service / first service instance is deployed. The present application can avoid data information being obtained by an untrusted network function or being obtained by a trusted network function for illegal purposes, effectively ensuring the security of data.
Owner:CHINA MOBILE COMM LTD RES INST +1

Wireless local area network authorized traffic identification and quality of service guarantee method and device, wireless access point, terminal chip, terminal chip module and terminal equipment

This application relates to the field of network management and optimization technology, and provides a method, apparatus, wireless access point, terminal chip, terminal chip module, and terminal device for identifying authorized traffic and ensuring quality of service (QoS) in a wireless local area network (WLAN). The method includes: a wireless access point on the network side receiving authorization credentials and QoS information sent by a terminal chip; obtaining target network element information based on the authorization credentials; verifying whether the target network element is a trusted network element based on the target network element information and a first authentication public key; if the target network element is a trusted network element, obtaining a second authentication public key from the target network element and verifying whether the authorization credentials are trusted credentials; if the authorization credentials are trusted credentials, determining that the traffic corresponding to the QoS information in the dedicated traffic transmission channel is authorized traffic, and providing QoS assurance for the authorized traffic according to the QoS information. This method can ensure that the QoS assurance for authorized traffic is reliable and controllable, and can improve the transmission quality of authorized traffic.
Owner:SPREADTRUM SEMICON(CHENGDU) CO LTD

Zero-trust web session caching

Devices, systems, machine-readable media, and methods for web session caching with improved security are provided. A method can include receiving, at the multi-tenant cache and from a web-based client, a first request to perform an operation on web session data in the multi-tenant cache, issuing, by the multi-tenant cache, a validation request to an authorization service, receiving, by the multi-tenant cache, a result of the validation request, responsive to determining the result of the validation request is a valid verification, performing the operation on the multi-tenant cache, and issuing, by the multi-tenant cache and to the web-based client, a response to the first request.
Owner:RAYTHEON CO

Heterogeneous trust-driven social internet of things negative information propagation prediction method and system

PendingCN122316722AComputer networkInformation propagation
This invention proposes a heterogeneous trust-driven method and system for predicting the propagation of negative information in the social Internet of Things (IoT), relating to the field of social IoT technology. It includes: constructing user trust networks and device trust networks based on user comment text and device performance indicators in the social IoT, and building a multi-dimensional trust model describing the user-device trust relationship through embedding learning from both the trustor's and trustee's perspectives; establishing a heterogeneous trust-driven information propagation model based on the multi-dimensional trust model and the differences between intra-community and inter-community propagation of negative information; analyzing the negative information propagation process according to the information propagation model to obtain trust prediction results, which are used for trusted device recommendation and high-risk node early warning. This invention improves the accuracy of negative information propagation prediction in the social IoT, providing support for trusted device recommendation and high-risk node early warning.
Owner:SHANDONG UNIV OF POLITICAL SCI & LAW

System and method for provably secure network operations ensuring integrity and availability of distributed network resources

Systems and methods are provided for provably secure network monitoring. A significant technical problem exists in Distributed Network Resources (DNRs) due to their increased reliance on digital communication and control, which presents a substantial risk from cyberattacks. A mathematically-backed secure network monitoring framework is provided that utilizes bastion platforms in the network to ensure end-to-end protection by detecting and preventing cyber threats while isolating, attributing, and securely communicating DNR traffic. Prior to deployment, software for the bastion platform undergoes a formal verification process that models the network mathematically and then evaluates that model to determine if a trusted network security mechanism (TNSM) holds true for the network. TNSM is a security mechanism that enforces permitted patterns of operations of the network without adversarial influence. In some implementations TNSM utilizes anti-spoofing, anti-flooding, secure kill-switch, secure patch delivery, and secure network flow mechanisms to secure the network.
Owner:UBERSPARK INC

A Method for Evolutionary Analysis of Cross-Basin Pollution Liability Based on Spatiotemporal Graph Attention Network and Blockchain Dynamic Game Theory

PendingCN122088717ARealize dynamic identificationImplement strategy evolution analysisDatabase updatingBiological modelsTrust levelEngineering
This invention discloses a cross-basin pollution responsibility evolution analysis method based on spatiotemporal graph attention networks and blockchain dynamic game theory, belonging to the interdisciplinary field of environmental governance and artificial intelligence. The method includes: collecting multi-dimensional spatiotemporal data and constructing agent state vectors; constructing a spatiotemporal graph attention network, incorporating hydrodynamic features into the attention mechanism, and dynamically calculating pollution responsibility contribution weights using GRU; establishing an evolutionary game model, where the penalty coefficient in the payoff function is dynamically adjusted by a blockchain smart contract based on on-chain trust levels; executing a trust evolution function through the smart contract, automatically adjusting game parameters when the trust level triggers a threshold, forming a closed-loop feedback; and finally generating and visualizing a responsibility evolution heatmap and a trust network graph. This method achieves physical-behavioral coupled quantification of pollution responsibility, reputation-based automatic governance and control, and full-process credible evidence storage, solving the problems of ambiguous responsibility definition and lack of dynamic coordination and trust mechanisms in traditional methods.
Owner:YUNNAN ACAD OF ENVIRONMENTAL SCI

Secure web proxy and temporary passcode for SSL exempted session-based authentication

ActiveUS12683934B2Email addressInternet privacy
Approaches to providing endpoint client authentication and application access control in a zero-trust network access (ZTNA) environment are described. A secure session is generated with a secure web proxy based on a request from a browser, wherein the request corresponds to a user and requests access to a server. A secure tunnel is established between the secure web proxy and the browser. A web proxy address corresponding to the user is generated. The user is identified based on a handshake procedure with the secure web proxy. A temporary passcode is generated for the user to be used for access to the server. The temporary passcode is sent to an email address associated with the user. The server is caused to authenticate the user utilizing the temporary passcode to allow the user access to the server if the temporary passcode is approved.
Owner:FORTINET INC

Authentication methods, devices, and network equipment based on zero-trust network security architecture

This application provides an authentication method, apparatus, and network device based on a zero-trust network security architecture. The authentication method based on the zero-trust network security architecture includes: Step S1: After the client is authenticated by the control terminal, the gateway receives an SPA message sent by the client and parses it to obtain authentication information; the authentication information includes the client's first IP address and a first user identity identifier; Step S2: If it is determined that the first IP address is not recorded, based on the first user identity identifier and a recorded user information set, it is confirmed whether the user has passed authentication; wherein, the user information set represents several user information that has passed authentication by the control terminal, and the user information includes a second user identity identifier that has passed authentication by the control terminal. The above method confirms whether a user has passed authentication through the user identity identifier, thereby enabling the same user to log in to the client normally even when the IP address changes.
Owner:HANGZHOU DPTECH TECH

Network access method and device for zero trust network architecture, equipment and medium

PendingCN122247719ASecuring communicationOpen portInternet privacy
This application provides a network access method, apparatus, device, and medium for a zero-trust network architecture. The method includes: a client sending a UDP authentication request carrying authentication information to a controller; the controller verifying the authentication information, sending a first verification result to the client, and opening a TCP port; the client establishing a TCP connection with the controller and sending a first TCP request carrying security policy check information to the controller; the controller generating a credit assessment result based on the security policy check information, sending a controller authorization message to a gateway, and sending a first authorization result to the client; the gateway verifying the client's authorization message based on the controller authorization message, generating a second authorization result, and sending the second authorization result to the client; and the client establishing a communication connection with the gateway and sending an authentication result to the controller. This improves the authentication success rate and security of network access.
Owner:HANGZHOU DPTECH TECH

Real time application protection system configuration drift categorization and response

Techniques are described for improving real-time application protection (RTAP) systems (e.g., web application firewalls (WAFs), runtime application self-protection (RASP) systems). In particular, a device within a trusted network may monitor or test the configuration settings of the RTAP systems, network traffic into the RTAP systems, and / or log information from the RTAP systems. For example, the device may detect drift in a configuration for a particular RTAP system by comparing the configuration settings of the RTAP systems to baseline configuration settings and classifying any detected drift as good drift or bad drift. In some examples, the device may maintain the configuration settings or set the configuration settings as the baseline configuration settings when the configurations settings include good drift from the baseline configuration settings. In other examples, the device may set the configuration settings with the bad drift to the baseline configuration settings.
Owner:WELLS FARGO BANK NA

Distributed identity trust evaluation system based on trusted network

The invention relates to the technical field of distributed digital identity authentication, in particular to a distributed identity trust evaluation system based on a trusted network, which comprises three roles of a certificate holder, an issuer and a verifier, and a block chain storage module used for storing interaction behavior records among nodes in a non-tampering manner; the trust calculation module is used for periodically calculating trust values of the nodes through the smart contract; the real-time detection module is used for monitoring whether the nodes have malicious behaviors or not; the dynamic punishment module is used for punishing the trust value of the node generating the malicious behavior when the malicious behavior is detected; the access control module is used for monitoring whether the trust value of the node is lower than a preset security value or not, and if yes, implementing a network access isolation measure on the node to limit the node to continuously participate in network interaction; according to the invention, the problem of decentralizing malicious nodes in the trusted network is effectively solved.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Zero-trust network access with user datagram protocol message forwarding

ActiveUS12676772B2Data packEngineering
Zero-trust network access (ZTNA) with user datagram protocol (UDP) message forwarding is disclosed. A forwarding rule is determined based on a destination address associated with a received data traffic packet formatted according to a first protocol (e.g., UDP). A bi-directional tunnel is created to forward the traffic based on the determined forwarding rule. A request is generated over a stream having a corresponding stream identifier within the bi-directional tunnel to establish a connection with a proxy device. The traffic packet payload formatted according to the first protocol is wrapped with at least the stream identifier. The wrapped data traffic packet is forwarded to a client device based on the determined forwarding rule to a destination device corresponding to the stream identifier.
Owner:FORTINET INC

Zero trust network security threat early warning system and method based on key terrain analysis

PendingCN122339776AKnowledge modellingAttack
This invention discloses a zero-trust network security threat early warning system and method based on critical terrain analysis. First, network traffic is captured and preprocessed. Traffic analysis automatically discovers the network topology and identifies key devices, constructing a critical terrain map. Vulnerability information from existing vulnerability platforms is collected, and knowledge modeling is performed using entity data (including vulnerabilities, devices, ports, services, and attack chains) and relational data such as impact, dependency, association, and triggering. Node vulnerability information is acquired, and the attack costs and benefits of associated vulnerabilities are quantitatively evaluated. A dynamic network attack-defense game model is constructed based on the quantitative results. Using the constructed vulnerability knowledge graph and exploitable associated vulnerabilities in the critical terrain, a zero-trust network critical terrain attack map is generated. Targeted strategies for critical terrain are formulated. Based on the associated vulnerability analysis results and targeted countermeasures, the generated attack map is used to infer attack paths for critical terrain, achieving full automation from anomaly detection and risk assessment to threat early warning.
Owner:SOUTHEAST UNIV

A token acquisition method and device based on a double-token index, equipment and medium

PendingCN122293331AEngineeringTrust network
This application relates to a token acquisition method, apparatus, device, and medium based on a dual-token index, comprising: receiving a call request from a calling terminal; generating a first token index based on a first moment according to a preset token index generation rule; generating a second token index based on a second moment according to the preset token index generation rule; sending a token request message to a token message transmission server, the token request message including the first token index and the second token index; and receiving an identity token returned by the token message transmission server. Therefore, the technical solution of this application employs a dual-token index mechanism: by generating two token indices based on two related moments, and utilizing a parallel query method with dual indices, the negative impact of transmission delays between trusted networks is effectively eliminated, ensuring that the called terminal can successfully query the identity token uploaded by the calling terminal using either the first token index or the second token index.
Owner:WEIWEI SHANGHAI NETWORK TECH CO LTD +1

An enhanced practical byzantine fault tolerance method for service function chaining deployment

The application discloses an enhanced practical Byzantine fault tolerance method for service function chain deployment. Firstly, a three-layer trusted network system model integrating blockchain and deep reinforcement learning is constructed, and network parameters and SFC deployment constraints are defined. Then, a VRPBFT enhanced consensus mechanism integrating a verifiable random function (VRF) and a node reputation grading model is designed to quantify node credibility and realize dynamic hierarchical division. Next, a master node fair selection method based on VRF is proposed to reduce consensus delay and improve Byzantine node detection capability. Finally, an SDRL deep reinforcement learning deployment algorithm is designed to dynamically adjust VNF and link deployment strategies in combination with node credibility, thereby optimizing resource utilization and service quality. Compared with the traditional PBFT, the consensus delay is reduced by about 30%, and the proportion of Byzantine nodes is reduced by 40% after 100 rounds of consensus. Compared with existing algorithms, the long-term average income of the SDRL algorithm is increased by 17%, the SFC request acceptance rate is increased by 14.49%, the income-cost ratio is increased by 20.35%, the CPU resource utilization rate is 42% and is increased by 27.96%, the safety of SFC deployment in a heterogeneous network is ensured, and the collaborative optimization of resource utilization and service quality is realized, so that the application is suitable for SFC trusted deployment in a heterogeneous network environment such as the Internet of Things and 5G.
Owner:CHINA UNIV OF PETROLEUM (EAST CHINA)

Using endpoint identity for network data flow and topology orchestration

Embodiments relate to a computer-implemented method for managing zero-trust network communications. The method includes validating the identity of a first remote endpoint using a cryptographic credential received from the first endpoint and determining the first endpoint's authorization to communicate with a second remote endpoint. Upon successful validation and authorization, the method initiates the establishment of a network packet route between the first and second remote endpoints. Later, the method further initiates the destruction of the network packet route between the two endpoints.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

A network boundary device

PCT designated stageWO2026133183A1Securing communicationMultiple contextComputer network
The present disclosure provides a method performed by a network boundary device to enable information transfer between a trusted network and a lesser- trusted network. The method comprises receiving, from the trusted network, first electronic information for transmission to the lesser-trusted network; transmitting, to the lesser-trusted network, the first electronic information; receiving, from the lesser-trusted network, second electronic information; determining, at the network boundary device, whether the second electronic information meets one or more contextual criteria; and if the second electronic information meets the one or more contextual criteria, transmitting the second electronic information to the trusted network.
Owner:THE SECRETARY OF STATE FOR FOREIGN & COMMONWEALTH & DEV AFFAIRS