Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

243 results about "Trust network" patented technology

The Trust Network is a network for all independently run, state-funded schools providing its members with an opportunity to share best practice and exchange knowledge.

Zero-trust network dynamic access control method based on AI behavior portrait

The invention discloses a zero-trust network dynamic access control method based on an AI behavior portrait, and the method comprises the following steps: 1, collecting multi-source real-time behavior data during an access request; 2, constructing an AI behavior portrait engine based on historical data, inputting the integrated multi-source behavior data, calculating a behavior deviation degree through the AI behavior portrait engine, and outputting a risk score; 3, dynamic strategy decision making, wherein a decision making engine executes hierarchical control according to the risk score; 4, continuous session monitoring and real-time adjustment are carried out; step 5, when risk upgrading is detected in the session, degrading the session authority, limiting high-risk operation, terminating the session, and retaining evidence obtaining data; step 6, audit event generation and portrait updating; and step 7, strategy optimization closed loop. According to the method, the risk score is calculated in real time based on the AI behavior portrait, transition from static authorization to dynamic permission adjustment is realized, and internal threats such as voucher stealing and the like are effectively blocked.
Owner:JINGDEZHEN SHANJIANG TECHNOLOGY CO LTD

Zero-trust network access (ZTNA) secure traffic forwarding

Systems and methods for performing ZTNA secure traffic forwarding are provided. In one example, as part of setting up a TFAP tunnel, between a target service and an endpoint security agent of an endpoint device through which an application running on the endpoint device can interact with the target service, a secure connection is established between the endpoint security agent and a ZTNA AP. Based on an encryption status of traffic transmitted from the application to the target service: (i) protection against eavesdropping by an MITM attacker is provided by using the secure connection to encrypt one or more critical messages of the traffic between the endpoint security agent and the ZTNA AP; and (ii) the endpoint security agent abstains from switching to bypassing mode through the TFAP tunnel until after the one or more critical messages of the traffic have been exchanged.
Owner:FORTINET INC

Digital cultural product right confirmation and data sharing method and system based on block chain

The invention provides a digital culture product right confirmation and data sharing method and system based on a block chain, and relates to the technical field of digital culture, and the method comprises the steps: generating a comprehensive trust score through a self-adaptive trust evaluation model by fusing timeliness, integrity and consistency trust scores, and constructing a self-evolution data trust network and an encrypted data synchronization channel. After smart contract verification, the access authority of the data requester is determined according to the trust score, access features are extracted through a bidirectional long-short term memory network and a multi-head attention mechanism, a proof chain node is constructed, a mapping relation with an authority confirmation certificate is established by using a graph neural network, and the access contribution degree is calculated through homomorphic encryption and federated learning; and finally, performing income distribution according to a sectional income distribution curve. According to the invention, the problems of difficult right confirmation and low data sharing credibility of digital culture products are effectively solved, and safe and controllable data sharing and income distribution are realized.
Owner:HEBEI FINANCE UNIV +1

Virtual power plant full-process credible aggregation method and system based on hierarchical trust chain

The invention belongs to the technical field of novel electric power system operation control and trust management, and particularly discloses a virtual power plant full-process trusted aggregation method and system based on a hierarchical trust chain. Differentiated hierarchical trust chain models of a data acquisition link, a scheduling control link and a market transaction link are constructed respectively; through real-time credibility evaluation and adaptive weight adjustment, credibility calculation of multi-agent collaborative decision is realized. According to the invention, a trust network formed by a plurality of efficient, safe and transparent virtual power plant trust chains is constructed, solid technical support is provided for fair competition, intelligent scheduling and reliable operation of a power market, and efficient interaction and stable operation of a power system are ensured.
Owner:SHANDONG UNIV

Method and apparatus for managing a mobile embedded security platform

PendingUS20250267460A1Service provisioningSecurity arrangementEmbedded securityUser equipment
A method performed by a computer-implemented controller is provided. The method includes receiving a request for managing one or more user equipments (UEs); obtaining a user-specific security profile from a first service provider; obtaining a subscriber identity module (SIM) profile from a network node or a second service provider; obtaining a set of secure access service edge (SASE) instances from the network node; building one or more UE-specific bootstrap configurations based on the user-specific security profile, the SIM profile, and the set of SASE instances; and sending the one or more UE-specific bootstrap configurations to a third service provider. The one or more UE-specific bootstrap configurations are obtainable by the one or more UEs to establish a secured wireless communication channel through a zero-trusted network.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Human and AI collaborative large-scale group decision-making method and equipment based on trusted network

The embodiment of the invention discloses a human and AI collaborative large-scale group decision-making method and equipment based on a trusted network. The method comprises the following steps: constructing a decision-making problem; performing initial evaluation on the alternative scheme through a human decision maker set and an AI decision maker set to obtain initial evaluation information; constructing a human and AI trusted network; establishing a continuously learned human and AI consensus reaching algorithm, and dynamically updating the human and AI trust network and the initial evaluation information through the human and AI consensus reaching algorithm to obtain final evaluation information; calculating the weight of each attribute in the alternative scheme and the weight of each decision maker according to the final evaluation information; the final score of each alternative scheme is calculated, and a final decision is generated; the decision-making response speed, precision and decision-making consistency can be effectively improved, and the method is suitable for the complex decision-making field.
Owner:TAIYUAN UNIVERSITY OF TECHNOLOGY

Distributed medical equipment management platform and method based on zero-trust network

The embodiment of the invention provides a distributed medical equipment management platform and method based on a zero-trust network. In the distributed medical equipment management platform based on the zero-trust network, an edge trusted access module adopts a hardware root of trust mechanism, so that equipment accessed for the first time is connected to a temporary supply network isolated from a medical core network, and a zero-trust security normal form is followed; the distributed trust anchor point cluster constructs a distributed identity verification network based on federated learning, and the access pre-authorization authority is verified through a device distributed identity identification (DID); the dynamic permission arrangement engine injects an attribute-based access control strategy, generates a permission token in combination with network micro-segmentation, and realizes two-way encryption communication between the equipment and a target service; the intelligent isolation gateway cuts off temporary connection through a software defined network technology and sends a network access state proof through a block chain mechanism, and edge module initialization is executed by a trusted node outside the medical cloud.
Owner:GENERAL HOSPITAL OF PLA

Network data security protection method and system based on multi-dimensional right control

The invention relates to the related technical field of zero-trust networks, in particular to a network data security protection method and system based on multi-protection right control, and the method comprises the steps: connecting a terminal and a protection center, setting a primary authorization mechanism, starting hierarchical authorization of a right group, evaluating the risk in real time, interrupting the access if the risk does not accord with the threshold, and carrying out the threat sharing. The technical problems that the authority is allocated only according to a fixed role, the enterprise business scene change and the user actual demand change cannot be adapted, the access of the user to the isolated data area resource is lack of fine-grained control, the situation of excessive authority granting or insufficient authority granting is easy to occur, and the data leakage risk is increased are solved; according to the invention, dynamic hierarchical management of the authority is realized by constructing a primary authorization authentication mechanism and a hierarchical authorization authentication mechanism, the authority is minimized to a single service instance, and fine-grained partitioning is carried out on resources, so that data access control is more accurate, illegal data access and attack diffusion are effectively blocked, and data access efficiency is improved. And the safety of the isolated data area is ensured.
Owner:SHICHUAN DIGITAL TECH (SHENZHEN) CO LTD

Zero-trust network node dynamic trust degree evaluation and intelligent resource allocation method, equipment and medium

The invention relates to a zero-trust network node dynamic trust degree evaluation and intelligent resource allocation method, equipment and medium, based on the principle of never trust and continuous verification, continuous information acquisition processing is carried out on all interaction nodes in a zero-trust network environment, a node trust degree calculation model is constructed based on processed data, and the dynamic trust degree evaluation and intelligent resource allocation of the zero-trust network node is realized. Weight parameters are dynamically optimized through a credibility evaluation layer; a dynamic trust threshold is set according to the node trust degree, an access control strategy is adjusted at a decision-making layer, and hierarchical allocation of resources is implemented. In addition, a continuous authentication and anomaly detection mechanism is introduced, node behaviors are monitored in real time, a trust strategy is dynamically adjusted, and abnormal access is limited; based on behaviors, contexts and real-time trust evaluation, refined access control and resource management are realized, internal threats, permission abuse and potential attacks can be effectively prevented, security requirements in a complex dynamic environment are met, and trust management efficiency and resource scheduling rationality are further improved.
Owner:ANHUI UNIV +5

Alias domains for accessing ZTNA applications

A cloud computing platform provides zero trust network access as a service to customers that maintain applications on-premises. In this context, the cloud computing platform may associate customers and / or applications with specific service proxies, and add an abstraction layer for network access that maps an alias domain for each customer and / or application to a network load balancer associated with the specific service proxies associated with the corresponding application(s). This approach advantageously simplifies the configuration of service proxies at the cloud computing platform by permitting dedicated relationships among network load balancers, specific service proxies, and specific applications, while concurrently reducing or avoiding the administrative burden on customers of updating network pointers when the clusters of service proxies are periodically reconfigured to adjust to varying user traffic.
Owner:SOPHOS LTD

Cloud-based zero trust network access service

A cloud-based platform for zero trust network access (ZTNA) services provides zero trust network access as a service for multiple customers in a multi-tenant architecture. In this context, the configuration for a new ZTNA application is validated with a service proxy in a sandbox or similar environment before release by the cloud-based platform for access through a public network. As a significant advantage, this approach mitigates inadvertent conflicts or instability in a service proxy that supports other applications and customers.
Owner:SOPHOS LTD

Intelligent decision-making method and system based on deep learning

The invention discloses an intelligent decision-making method and system based on deep learning, and relates to the field of data processing. The method comprises the steps of obtaining place data and corresponding attribute data of a to-be-decided project; establishing a fuzzy relation matrix between the places and the attributes; generating a network model reflecting trust relationship strength among users through trust propagation operation of the graph neural network; identifying a community structure containing a community overlapping degree through a community discovery algorithm; and according to the trust relationship strength between the users and the community overlapping degree, calculating an influence weight of a decision maker, forming a group consensus through a robust optimization method, and generating a decision result of the project to be decided. Aiming at low network relation modeling precision caused by multi-source heterogeneous data in bus station layout decision making in the prior art, the method and the device have the advantages that the network relation modeling precision is low through accurate modeling of an information propagation path in a complex trusted network, effective dimension reduction representation of a high-dimensional feature space and robust optimization solution in an uncertain environment; therefore, the calculation precision and robustness of the bus station layout intelligent decision-making system are improved.
Owner:北京长河数智科技有限责任公司 +2

Conditional SSH Tunneling as a Policy Enforcement Point for Seamless Zero Trust Integration

Enhanced security for Zero Trust networks is provided by SSH-customized tunnel clients / tunnel servers, a catalog service, and loopback address DNS mechanisms. Systems and methods provide Policy Enforcement Point (PEP) layer enhancements, strategically positioning the PEP between the user and the network resource. It manages network traffic flows and provides moderate control granularity, near-real-time enforcement decisions, low overheads, and broad applicability to TCP / IP traffic through modified tunneling implementations of Secure Shell (SSH). Unique use of SSH tunneling is utilized and adapted to selectively filter tunnel requests based on user entitlements, ensuring secure and authorized access to network resources. This method entails detailed assessment of tunneling requests, DNS manipulation, and the use of loopback address space for traffic redirection, all without requiring modifications to client-side applications. The approach significantly enhances network security by controlling access based on continuous verification of user entitlements, addressing the shortcomings of traditional network security models.
Owner:BANK OF AMERICA CORP

Active Directory Security Enforcement and Threat Insights on Zero Trust Networks

Systems and methods for active directory security enforcement and threat insights on zero trust networks include performing inline monitoring of traffic associated with a plurality of tenants of the cloud-based system; classifying the traffic as being associated with any of one or more active directory protocols; inspecting the traffic associated with the one or more detected active directory protocols; and performing one or more actions on the traffic based on the inspecting.
Owner:ZSCALER INC

Next gen zero trust network access (ZTNA) and virtual private network (VPN) including cloud secure access service edge (SASE)

Techniques for leveraging the MASQUE protocol to provide remote clients with full application access to private enterprise resources are described herein. One or more network nodes may be configured to execute a MASQUE proxy service to provide a remote client device with full access to an enterprise / private application resource executing on an application node and hosted in an enterprise / application network, behind the MASQUE proxy service. In some examples, the MASQUE proxy service may execute on a single proxy node hosted at an edge of a cloud network or at an edge of an enterprise network. Additionally, or alternatively, a first instance of the MASQUE proxy service may execute on a first proxy node hosted at an edge of a cloud network (e.g., an ingress proxy node) and a second instance of the MASQUE proxy service may execute on a second proxy node hosted at an edge of the enterprise network.
Owner:CISCO TECHNOLOGY INC

Zero-trust cybersecurity access control system using continuous identity verification

A system for zero-trust cybersecurity access control using continuous identity verification (100), comprising: a Policy Decision and Enforcement Orchestrator (1) configured to receive an access request from a user device and enforce a session with minimal privileges; an engine for continuous identity verification (2) configured to generate a time-dependent identity trust score by continuously verifying the user identity during an active session; a device state and telemetry collector (3) configured to acquire device state parameters, runtime signals and network telemetry and to generate a state value; a module for detecting behavioral risks and anomalies (4) that is configured to create behavioral profiles and detect anomalies based on user activity patterns, contextual signals and the history of resource access; a cryptographic authentication and secure token module (5) configured to issue and update a short-lived, bound access token associated with at least the identity trust value and the state value; and an adaptive response and microsegmentation module (6) configured to dynamically adjust access permissions, network segmentation and session privileges in real time, based on an aggregated risk assessment derived from modules (2) to (4), where the system (100) continuously reassesses trustworthiness during the session and selectively allows, restricts, requires enhanced authentication or terminates the session based on the aggregated risk assessment.
Owner:SIVASHANMUGAM SATHESH PADMANABAN GLENDALE

Zero-trust security access system based on random forest positioning method

The invention discloses a zero-trust security access system based on a random forest positioning method, and the system comprises the following modules: a behavior characteristic collection module which is used for collecting original behavior data generated by network interaction between a user and equipment; the structure time sequence modeling module is used for converting the behavior characteristic data set into structured time sequence diagram data; the graph neural network analysis module is used for generating a security risk feature representation vector; the adversarial disturbance enhancement module is used for actively generating random disturbance data to form a disturbance enhancement risk feature representation vector; the random forest positioning module is used for positioning safety risk positions of the user and the equipment through an improved random forest algorithm; the dynamic risk assessment module is used for calculating a security risk level in real time; and the access decision module is used for dynamically adjusting zero-trust network access permission configuration. According to the invention, the security risk positioning precision and the dynamic risk response capability are effectively improved.
Owner:JIANGSU ENLINK NETWORK TECH CO LTD

Zero-trust cybersecurity enforcement in operational technology systems

In one embodiment, a method may implement a multi-layer cybersecurity model for a multi-layer distributed computer system which comprises a sensitive data resource, such as a computing environment with an operational technology (OT) layer with multiple zones, an information technology (IT) layer, a DMZ, and a cloud layer. The method can assess a policy based on a zero-trust model for the sensitive data resource. The method can receive one or more requests, at any layer of a multi-layer distributed computing system, to access the sensitive data resource and acquire identity information for a user account specified in the first request. The method can perform a multi-layer multi-factor authentication of the user account using the identity information and the multi-layer cybersecurity model. In response to authenticating the identity information, the method can acquire sensitive access data corresponding to the identity information. The method can determine a sensitive resource access value using the sensitive access data and the zero trust model. In response to determining the sensitive resource access value is above a predetermined threshold, the method can authenticate the user account.
Owner:XAGE SECURITY INC

Systems and methods for active directory protection in zero trust networks

Systems and methods for active directory protection in zero trust networks. In an embodiment, steps include performing inline monitoring of traffic associated with a cloud-based system; detecting one or more active directory protocols based on the inline monitoring; classifying the traffic as being associated with any of the one or more active directory protocols; inspecting the traffic associated with the one or more detected active directory protocols; and generating one or more active directory logs based on the inspecting and classifying.
Owner:ZSCALER INC

Validation of ZTNA configuration for a multi-tenant proxy environment

A cloud-based platform for zero trust network access (ZTNA) services provides zero trust network access as a service for multiple customers in a multi-tenant architecture. In this context, the configuration for a new ZTNA application is validated with a service proxy in a sandbox or similar environment before release by the cloud-based platform for access through a public network. As a significant advantage, this approach mitigates inadvertent conflicts or instability in a service proxy that supports other applications and customers.
Owner:SOPHOS LTD

Cloud-based zero trust network access service

Infrastructure for zero trust network access (ZTNA) is deployed as a cloud-based service remotely from a customer premises where user applications are hosted. By connecting an appliance on the customer premises to the cloud-based service through a secure tunnel or the like, an application hosted on the customer premises can then be accessed externally as a ZTNA application without the customer premises opening a firewall to public networks or otherwise exposing potential attack surfaces to the customer premises.
Owner:SOPHOS LTD

Quantum state mapping and language phase difference fused transnational trust modeling method

The invention discloses a transnational trust modeling method fusing quantum state mapping and language phase difference, comprising the following steps: 1) estimating the site of each country based on the voting data of the united countries, and calculating the trust weight between countries through a weighting function in combination with the political ideal point distance and voting consistency of each country to obtain the initial quantized value of transnational trust; 2) mapping the initial trust value to a quantum state on a Bloch ball, applying phase perturbation according to semantic difference reported by a core country media, and simulating trust interaction between countries under discourse difference in combination with a quantum game mechanism so as to obtain a trust value mapped back to a classical space; and 3) carrying out iterative updating on the trust value by adopting a social influence model, dynamically describing an evolution process of the trust relationship between the countries, and outputting a time sequence change result of the trust network between the countries. According to the method, by fusing the international voting behavior and the transnational utterance difference, dynamic and quantifiable modeling of the inter-country trust relationship is realized, and an innovative methodological support is provided for international relationship research, transnational strategic game analysis and global risk early warning.
Owner:SOUTHEAST UNIV

Zero-trust network access processing method, device, electronic device and storage medium

The present application provides an access processing method, device, electronic device and computer-readable storage medium for a zero-trust network; it relates to the security field of cloud technology, and the method includes: receiving an access request sent by an application; obtaining the address of the business site that the application needs to access from the access request; based on the identification of the application and the address of the business site, querying the access control policy of the zero-trust network to obtain the access mode of the application accessing the business site; establishing a communication connection between the application and the business site based on the access mode and the zero-trust network; sending the access request to the business site through the communication connection, and sending the access request response of the business site to the application through the communication connection. Through this application, a flexible, stable and efficient access mode can be provided to applications through a zero-trust network.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD

Block chain-based trusted network connection identity authentication and secure communication method

The invention relates to the technical field of network security, and particularly discloses a block chain-based trusted network connection identity authentication and secure communication method, which comprises the following steps of: firstly, generating a public and private key pair in a user registration stage, uploading a public key to a block chain smart contract for storage through an encryption channel, and when a user requests a service, sending the public key to the block chain smart contract; the method comprises the following steps of: signing a message containing identity verification information by using a private key, verifying the validity of the signature by using a public key on a block chain by a service provider so as to confirm the identity of a user, generating a temporary session key by both parties by adopting a Diffie-Hellman algorithm after the identity verification is successful, and performing encrypted transmission through the public key of the user, thereby establishing a secure communication channel. In order to further evaluate the stability and consistency of the communication link, a timestamp deviation characteristic value and a consistency deviation characteristic value are calculated, a gradient boosting tree model is utilized to comprehensively analyze the characteristic values to output a communication security score, and once an unsafe condition is found, the system automatically triggers to regenerate and exchange a new session key mechanism.
Owner:HEFEI TANOVO INFORMATION SECURITY TECH CO LTD

Domain ownership verification for a ZTNA service platform

A cloud computing platform provides zero trust network access as a service to a customer that maintains an application on-premises. In this context, the customer may be required to demonstrate ownership of a domain before the cloud computing platform will provide access to the on-premises application via the domain.
Owner:SOPHOS LTD

Robust encoding of machine readable information in host objects and biometrics, and associated decoding and authentication

This disclosure details image and audio signal processing methods and associated equipment to robustly encode transaction parameters in rendered displays, printed objects and audio. It also details corresponding decoding methods and equipment to recover these parameters. Further, it details object authentication processing and equipment to validate a transaction for an object, employing a trust network protocol for maintaining a trusted transaction history of the object. Various alternative forms of this technology are described.
Owner:DIGIMARC LLC

Universal privileged access for web applications through remote browser isolation

Methods and systems of providing a universal privileged access management solution to enable users to securely share web applications through remote browser isolation (RBI). The web applications may be hosted in a SAAS (Software As A Services) cloud or in a private network. For privileged access of web applications that do not support SSO, the universal privileged access management solution implements cloud-based software services including Remote Browser Isolation (RBI), Zero Trust Network Access (ZTNA) and password vault. For privileged access of web applications that support SSO, the universal privileged access management solution implements cloud-based software services including Remote Browser Isolation (RBI) and ID brokers. In the access authentication process, by leveraging the data loss prevention (DLP) feature of RBI, the actual access credentials for accessing web applications are not disclosed to the user for mitigating security risks.
Owner:SPLASHTOP INC

Using endpoint identity for network data flow and topology orchestration

PendingUS20260189408A1Data packData stream
Embodiments relate to a computer-implemented method for managing zero-trust network communications. The method includes validating the identity of a first remote endpoint using a cryptographic credential received from the first endpoint and determining the first endpoint's authorization to communicate with a second remote endpoint. Upon successful validation and authorization, the method initiates the establishment of a network packet route between the first and second remote endpoints. Later, the method further initiates the destruction of the network packet route between the two endpoints.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Security communication platform and method constructed based on security control and trusted network connection

The invention relates to the technical field of network security and communication, in particular to a security communication platform and method constructed based on security control and trusted network connection. The security communication platform comprises a security management and control center platform, a trusted password service platform, a trusted network connection optimization architecture, a distributed network architecture, a security shared memory mechanism, an application cluster system and a trusted VPN function module, the security management and control center platform is deployed in a core network, and a trusted platform module is arranged in the security management and control center platform as a global trusted root. By constructing an integrated platform of the trusted security management and control system and the secure and trusted intelligent VPN, triple security assurance of trusted access terminal, trusted network connection and trusted data transmission can be realized, and the requirements of a key information system on high security, high reliability and high adaptation of network communication are met; the defects of the traditional VPN in the aspects of attack surface control, encryption capability, identity authentication, systematic defense and the like are overcome.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD