Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

180 results about "Trust network" patented technology

The Trust Network is a network for all independently run, state-funded schools providing its members with an opportunity to share best practice and exchange knowledge.

Zero-trust network dynamic access control method based on AI behavior portrait

The invention discloses a zero-trust network dynamic access control method based on an AI behavior portrait, and the method comprises the following steps: 1, collecting multi-source real-time behavior data during an access request; 2, constructing an AI behavior portrait engine based on historical data, inputting the integrated multi-source behavior data, calculating a behavior deviation degree through the AI behavior portrait engine, and outputting a risk score; 3, dynamic strategy decision making, wherein a decision making engine executes hierarchical control according to the risk score; 4, continuous session monitoring and real-time adjustment are carried out; step 5, when risk upgrading is detected in the session, degrading the session authority, limiting high-risk operation, terminating the session, and retaining evidence obtaining data; step 6, audit event generation and portrait updating; and step 7, strategy optimization closed loop. According to the method, the risk score is calculated in real time based on the AI behavior portrait, transition from static authorization to dynamic permission adjustment is realized, and internal threats such as voucher stealing and the like are effectively blocked.
Owner:JINGDEZHEN SHANJIANG TECHNOLOGY CO LTD

Virtual power plant full-process credible aggregation method and system based on hierarchical trust chain

The invention belongs to the technical field of novel electric power system operation control and trust management, and particularly discloses a virtual power plant full-process trusted aggregation method and system based on a hierarchical trust chain. Differentiated hierarchical trust chain models of a data acquisition link, a scheduling control link and a market transaction link are constructed respectively; through real-time credibility evaluation and adaptive weight adjustment, credibility calculation of multi-agent collaborative decision is realized. According to the invention, a trust network formed by a plurality of efficient, safe and transparent virtual power plant trust chains is constructed, solid technical support is provided for fair competition, intelligent scheduling and reliable operation of a power market, and efficient interaction and stable operation of a power system are ensured.
Owner:SHANDONG UNIV

Intelligent decision-making method and system based on deep learning

The invention discloses an intelligent decision-making method and system based on deep learning, and relates to the field of data processing. The method comprises the steps of obtaining place data and corresponding attribute data of a to-be-decided project; establishing a fuzzy relation matrix between the places and the attributes; generating a network model reflecting trust relationship strength among users through trust propagation operation of the graph neural network; identifying a community structure containing a community overlapping degree through a community discovery algorithm; and according to the trust relationship strength between the users and the community overlapping degree, calculating an influence weight of a decision maker, forming a group consensus through a robust optimization method, and generating a decision result of the project to be decided. Aiming at low network relation modeling precision caused by multi-source heterogeneous data in bus station layout decision making in the prior art, the method and the device have the advantages that the network relation modeling precision is low through accurate modeling of an information propagation path in a complex trusted network, effective dimension reduction representation of a high-dimensional feature space and robust optimization solution in an uncertain environment; therefore, the calculation precision and robustness of the bus station layout intelligent decision-making system are improved.
Owner:北京长河数智科技有限责任公司 +2

Next gen zero trust network access (ZTNA) and virtual private network (VPN) including cloud secure access service edge (SASE)

Techniques for leveraging the MASQUE protocol to provide remote clients with full application access to private enterprise resources are described herein. One or more network nodes may be configured to execute a MASQUE proxy service to provide a remote client device with full access to an enterprise / private application resource executing on an application node and hosted in an enterprise / application network, behind the MASQUE proxy service. In some examples, the MASQUE proxy service may execute on a single proxy node hosted at an edge of a cloud network or at an edge of an enterprise network. Additionally, or alternatively, a first instance of the MASQUE proxy service may execute on a first proxy node hosted at an edge of a cloud network (e.g., an ingress proxy node) and a second instance of the MASQUE proxy service may execute on a second proxy node hosted at an edge of the enterprise network.
Owner:CISCO TECHNOLOGY INC

Zero-trust cybersecurity access control system using continuous identity verification

A system for zero-trust cybersecurity access control using continuous identity verification (100), comprising: a Policy Decision and Enforcement Orchestrator (1) configured to receive an access request from a user device and enforce a session with minimal privileges; an engine for continuous identity verification (2) configured to generate a time-dependent identity trust score by continuously verifying the user identity during an active session; a device state and telemetry collector (3) configured to acquire device state parameters, runtime signals and network telemetry and to generate a state value; a module for detecting behavioral risks and anomalies (4) that is configured to create behavioral profiles and detect anomalies based on user activity patterns, contextual signals and the history of resource access; a cryptographic authentication and secure token module (5) configured to issue and update a short-lived, bound access token associated with at least the identity trust value and the state value; and an adaptive response and microsegmentation module (6) configured to dynamically adjust access permissions, network segmentation and session privileges in real time, based on an aggregated risk assessment derived from modules (2) to (4), where the system (100) continuously reassesses trustworthiness during the session and selectively allows, restricts, requires enhanced authentication or terminates the session based on the aggregated risk assessment.
Owner:SIVASHANMUGAM SATHESH PADMANABAN GLENDALE

Quantum state mapping and language phase difference fused transnational trust modeling method

The invention discloses a transnational trust modeling method fusing quantum state mapping and language phase difference, comprising the following steps: 1) estimating the site of each country based on the voting data of the united countries, and calculating the trust weight between countries through a weighting function in combination with the political ideal point distance and voting consistency of each country to obtain the initial quantized value of transnational trust; 2) mapping the initial trust value to a quantum state on a Bloch ball, applying phase perturbation according to semantic difference reported by a core country media, and simulating trust interaction between countries under discourse difference in combination with a quantum game mechanism so as to obtain a trust value mapped back to a classical space; and 3) carrying out iterative updating on the trust value by adopting a social influence model, dynamically describing an evolution process of the trust relationship between the countries, and outputting a time sequence change result of the trust network between the countries. According to the method, by fusing the international voting behavior and the transnational utterance difference, dynamic and quantifiable modeling of the inter-country trust relationship is realized, and an innovative methodological support is provided for international relationship research, transnational strategic game analysis and global risk early warning.
Owner:SOUTHEAST UNIV

Domain ownership verification for a ZTNA service platform

A cloud computing platform provides zero trust network access as a service to a customer that maintains an application on-premises. In this context, the customer may be required to demonstrate ownership of a domain before the cloud computing platform will provide access to the on-premises application via the domain.
Owner:SOPHOS LTD

Robust encoding of machine readable information in host objects and biometrics, and associated decoding and authentication

This disclosure details image and audio signal processing methods and associated equipment to robustly encode transaction parameters in rendered displays, printed objects and audio. It also details corresponding decoding methods and equipment to recover these parameters. Further, it details object authentication processing and equipment to validate a transaction for an object, employing a trust network protocol for maintaining a trusted transaction history of the object. Various alternative forms of this technology are described.
Owner:DIGIMARC LLC

Using endpoint identity for network data flow and topology orchestration

PendingUS20260189408A1Data packData stream
Embodiments relate to a computer-implemented method for managing zero-trust network communications. The method includes validating the identity of a first remote endpoint using a cryptographic credential received from the first endpoint and determining the first endpoint's authorization to communicate with a second remote endpoint. Upon successful validation and authorization, the method initiates the establishment of a network packet route between the first and second remote endpoints. Later, the method further initiates the destruction of the network packet route between the two endpoints.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Security communication platform and method constructed based on security control and trusted network connection

The invention relates to the technical field of network security and communication, in particular to a security communication platform and method constructed based on security control and trusted network connection. The security communication platform comprises a security management and control center platform, a trusted password service platform, a trusted network connection optimization architecture, a distributed network architecture, a security shared memory mechanism, an application cluster system and a trusted VPN function module, the security management and control center platform is deployed in a core network, and a trusted platform module is arranged in the security management and control center platform as a global trusted root. By constructing an integrated platform of the trusted security management and control system and the secure and trusted intelligent VPN, triple security assurance of trusted access terminal, trusted network connection and trusted data transmission can be realized, and the requirements of a key information system on high security, high reliability and high adaptation of network communication are met; the defects of the traditional VPN in the aspects of attack surface control, encryption capability, identity authentication, systematic defense and the like are overcome.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Techniques for providing long uniform resource locators through a secure environment

A method and system for providing web resources having long identifiers through a zero trust network environment. The method comprises receiving a request from a client device to access a web resource through a zero trust network environment, wherein the web resource is external to the zero trust network environment, the request including a first uniform resource locator (URL), and the resource further including a second URL having a first length; fetching the web resource based on the first URL; generating a shortened alternate URL based on at least a portion of the second URL, in response to determining that the first length exceeds a predetermined threshold; generating an alternate resource, the alternate resource including the shortened alternate URL replacing the second URL; and providing the alternate resource to the client device.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Managing traffic in networks that use zero trust network access

Systems and methods for managing traffic in a network that uses Zero Trust Network Access (ZTNA). The method includes providing a ZTNA gateway in connectivity with a first network, providing a ZTNA agent on a first user device in connectivity with the first network, and analyzing, using at least one of the ZTNA gateway or the first user device, a communication between the ZTNA gateway and the first user device to determine whether the first user device is on the first network. The method further includes enabling the first device to access a first resource on the first network without tunneling traffic from the first user device to the ZTNA gateway upon determining the user device is on the first network.
Owner:SOPHOS LTD

Network authentication toxicity assessment

A system and method for scoring and enforcing authentication standards that actually enable zero trust network security principles when combined with stateful authentication object tracking, authentication object manipulation and forgery detection, and assessment of authentication and identity attack surface. The methodology involves gathering all authentication objects issued by a network, storing the authentication objects in a centralized location for use in stateful deterministic authentication object tracking, scoring the completeness of the authentication observations, assessing the quality of the authentication observations, and assigning organization-specific penalty functions.
Owner:QOMPLX INC

Robust encoding of machine readable information in host objects and biometrics, and associated decoding and authentication

This disclosure details image and audio signal processing methods and associated equipment to robustly encode transaction parameters in rendered displays, printed objects and audio. It also details corresponding decoding methods and equipment to recover these parameters. Further, it details object authentication processing and equipment to validate a transaction for an object, employing a trust network protocol for maintaining a trusted transaction history of the object. Various alternative forms of this technology are described.
Owner:DIGIMARC LLC

Zero-trust web session caching

Devices, systems, machine-readable media, and methods for web session caching with improved security are provided. A method can include receiving, at the multi-tenant cache and from a web-based client, a first request to perform an operation on web session data in the multi-tenant cache, issuing, by the multi-tenant cache, a validation request to an authorization service, receiving, by the multi-tenant cache, a result of the validation request, responsive to determining the result of the validation request is a valid verification, performing the operation on the multi-tenant cache, and issuing, by the multi-tenant cache and to the web-based client, a response to the first request.
Owner:RAYTHEON CO

Distributed energy storage equipment cooperative scheduling method and system based on trusted network

The invention provides a distributed energy storage equipment cooperative scheduling method and system based on a trusted network, and relates to the technical field of power systems, and the method comprises the steps: obtaining operation data, calculating a reputation score, building a network topology, receiving a scheduling instruction, screening target equipment, and calculating a cooperative scheduling strategy based on reinforcement learning. And writing the power distribution scheme and the scheduling execution time sequence into the smart contract. The method can effectively improve the reliability of cooperative scheduling of the energy storage equipment, reduces the scheduling cost, optimizes the electric energy quality, and reduces the response delay and scheduling deviation.
Owner:STATE GRID GANSU ELECTRIC POWER CORP

Methods and Systems for In-Band Sign Up to a Wireless Network

An example method includes determining, by a client computing device, that a wireless access point (WAP) supports an in-band secure access protocol to connect to a wireless network hosted by a server, where the protocol involves establishing an initial network connection to exchange subscription data. The method includes receiving, from the WAP, a temporary login credential and an authentication protocol for the server. The method includes utilizing the temporary login credential and the authentication protocol to establish the initial network connection. The method includes exchanging the subscription data with the server over the initial network connection. The method includes completing the protocol by downloading, from the WAP and over the initial network connection, a subscription file. The subscription file enables the client computing device to establish an encrypted and trusted network connection over the wireless network.
Owner:GOOGLE LLC

Enhanced internet of things sensor analysis and real-time trust provenance determination

Systems and methods are disclosed for enhanced internet-of-things sensor analysis and real-time trust provenance determination. An example method includes determining a subset of a plurality of IoT sensors from which data is to be aggregated, the subset of the plurality of IoT sensors being responsive to one or more constraints, wherein individual IoT sensors are configured to generate data provenance information which, at least, cryptographically identifies data as originating from the individual IoT sensors; instructing the subset of the IoT sensors to generate data, wherein a first IoT sensor of the subset is instructed to execute a custom workload, and wherein the data provenance information generated via the first IoT sensor is to be cryptographically signed; and aggregating output data associated with the subset of the IoT sensors, wherein data provenance information associated with the IoT sensors is validated to form a trusted network chain.
Owner:ANALOG DEVICES INT UNLTD CO

Method for application access in zero trust campus network

Disclosed herein are system, method, and computer program product aspects for providing an agent-based zero trust network access (ZTNA) remote device access to a campus network. Some aspects of this disclosure relate to a universal network access application including a memory and a processor. The processor is configured to receive an authentication request from a client device and in response to receiving the authentication request, retrieve a set of network policies indicating an Internet protocol (IP) address and a port number based on the authentication request. The processor is further configured to transmit the set of network policies to a policy enforcement application in a campus network.
Owner:EXTREME NETWORKS INC

Method for determining trusted terminal and related apparatus

A method for determining a trusted terminal and a related apparatus, which are applied to a zero trust network security architecture, improves security of the zero trust architecture. The method includes: a terminal sends an access request when the terminal accesses an application server. A policy control apparatus sends an HTTPS connection request to the terminal based on the access request from the terminal. The terminal sends verification information to the policy control apparatus based on the HTTPS connection request. The policy control apparatus performs verification on the verification information. After the verification on the verification information succeeds, the terminal successfully establishes an HTTPS connection to the policy control apparatus. The HTTPS connection indicates that the terminal is a trusted terminal.
Owner:HUAWEI TECH CO LTD

Techniques for managing cookies through a secure web gateway

A system and method for facilitating communication between a user device and a web application through a zero trust network providing a secure web gateway using authentication cookies. The method includes receiving network traffic from a user device including an altered authentication cookie, the network traffic directed at a web application; retrieving an original authentication cookie based on the altered authentication cookie; generating a new network traffic based on: the received network traffic, and the original authentication cookie; and sending the new network traffic from the zero trust network environment to the web application.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

System and method for providing multi factor authorization to RDP services through a zero trust cloud environment

Remote desktop protocol (RDP) is a proprietary protocol for controlling machines over a network. In order to overcome certain deficiencies of the protocol a method is disclosed utilized in a zero trust cloud environment, to provide access to a RDP servers utilizing multifactor authorization services which are not natively supported by RDP. This is performed utilizing an RDP client while simultaneously providing an authenticated and secure policy based experience through a zero trust network.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Conditional ssh tunneling as a policy enforcement point for seamless zero trust integration

Enhanced security for Zero Trust networks is provided by SSH-customized tunnel clients / tunnel servers, a catalog service, and loopback address DNS mechanisms. Systems and methods provide Policy Enforcement Point (PEP) layer enhancements, strategically positioning the PEP between the user and the network resource. It manages network traffic flows and provides moderate control granularity, near-real-time enforcement decisions, low overheads, and broad applicability to TCP / IP traffic through modified tunneling implementations of Secure Shell (SSH). Unique use of SSH tunneling is utilized and adapted to selectively filter tunnel requests based on user entitlements, ensuring secure and authorized access to network resources. This method entails detailed assessment of tunneling requests, DNS manipulation, and the use of loopback address space for traffic redirection, all without requiring modifications to client-side applications. The approach significantly enhances network security by controlling access based on continuous verification of user entitlements, addressing the shortcomings of traditional network security models.
Owner:BANK OF AMERICA CORP

System and method for securing data in software applications and networks utilizing quantum computing

A system includes a memory configured to store instances of a software application executable on a computing device and a set of public data. The system includes a processor operably coupled to the memory and configured to detect an interaction to initiate execution of user interactions with the set of public data. The processor is further configured to execute one or more generative machine-learning models trained to extract, based on the set of public data, a set of data to be inputted into a trusted network for obfuscating from public view sets of private data, and identify, based on the extracted set of data, the sets of private data. The processor is further configured to input the extracted set of data into the trusted network, and initiate execution of user interactions with the sets of private data based on the extracted set of data as inputted into the trusted network.
Owner:BANK OF AMERICA CORP

Access control method, apparatus, device, medium, and product

PendingCN122372254AEngineeringContext data
This application discloses an access control method, apparatus, device, medium, and product, relating to the field of communication technology. The access control method includes: when a terminal senses a switch from a trusted network environment to an untrusted network environment, the proxy terminal sends a long-connection request to a target business system; acquiring processing data of the target business system's response to the long-connection request, performing trustworthiness verification based on the processing data and the switching context data, and generating a restricted access credential for the terminal and enabling a one-way isolation mode for the terminal when the trustworthiness verification result is positive; with the one-way isolation mode enabled, authenticating the terminal's access behavior command to the target business system based on the restricted access credential, sending the access behavior command to the target business system after successful authentication, and filtering the response data received from the target business system before sending the filtered response data to the terminal.
Owner:CHINA MOBILE ONLINE SERVICES CO LTD +1

Zero-trust network dynamic access control method based on AI behavior portrait

The application discloses a zero-trust network dynamic access control method based on AI behavior portrait, which comprises the following steps: step 1: when an access request is made, collect multi-source real-time behavior data; step 2: based on historical data, build an AI behavior portrait engine, input the integrated multi-source behavior data, calculate the behavior deviation degree through the AI behavior portrait engine, and output a risk score; step 3: dynamic strategy decision, the decision engine executes hierarchical control according to the risk score; step 4: continuous session monitoring and real-time adjustment; step 5: when a risk escalation is detected in the session, the session permission is downgraded, high-risk operations are limited, and the session is terminated, and evidence data is retained; step 6: audit event generation and portrait updating; step 7: strategy optimization closed loop. The application calculates a risk score in real time based on an AI behavior portrait, realizes the transition from'static authorization' to 'dynamic permission adjustment', and effectively blocks internal threats such as credential theft.
Owner:JINGDEZHEN SHANJIANG TECHNOLOGY CO LTD

A method for constructing a decentralized public key infrastructure based on a blockchain and a trust network

The application discloses a kind of decentralized public key infrastructure based on blockchain and trust network construction method, belong to information security PKI public key infrastructure field, including the following steps: step one, build decentralized CA agency;Step two, user submits certificate application / update / revocation request.Certificate request of user is submitted to decentralized CA agency, and the service of decentralized CA agency will call blockchain to generate / update / revocation digital certificate;Step three, certificate request of user is verified using blockchain technology.Certificate request is verified using smart contract technology.The decentralized public key infrastructure based on blockchain and trust network construction method aims to solve the single point of failure, certificate opacity, certificate revocation time-consuming and other problems existing in traditional PKI system, focuses on realizing that CA agency will not cause PKI trust system to collapse due to CA agency failure in the process of certificate life cycle management, while realizing certificate transparency and improving certificate revocation efficiency.
Owner:KOAL SOFTWARE CO LTD

Controlling network access using risk levels determined by user activity and program versioning

A component controlling network access between a client and a server using application software versions to determine a risk level of the client. The component uses a first set of programs for negotiation with the client if the risk level is high, wherein the first set of programs includes programs with high security level, and it uses a second set of programs for negotiation with the client if the risk level is not high, wherein the second set of programs includes programs with high security level and programs with low security level. The component may utilize secure network protocols for communication between the client and server, and may be included as a gateway in a zero trust network access (ZTNA) system.
Owner:CALIX INC

Remote commands using network of trust

A device may include a processor, a wireless transceiver in communication with the processor, and a non-transitory memory. The memory may store instructions that, when executed by the processor, cause the processor to perform processing. The processing may include receiving a command configured to be executed by an external user device. The external user device and the user device may be members of a network of trust. The processing may include detecting, by the wireless transceiver, a plurality of member devices of the network of trust in communication range of the device. The processing may include sending, by the wireless transceiver, the command to each of the plurality of member devices.
Owner:CAPITAL ONE SERVICES LLC