摘要:
Methods and systems for remote dynamic isolation of IoT devices are provided. One system includes a first IoT device and a second IoT device configured with an active communication channel with the first IoT device and a role certificate. An operator device is configured to interact with a distributed ledger to issue and revoke role certificates for a plurality of devices including the first IoT device and the second IoT device. The first IoT device periodically validates a role certificate proof received from the second IoT device with an entry of the role certificate proof recorded on the distributed ledger.
摘要:
A method of securing containers within clusters is disclosed. The method includes configuring service access points within clusters as secure endpoints; associating services within clusters with secure identities to constrain which communities-of-interest can reach which services; and wherein each cluster is cryptographically isolated such that no information will leak in or out of the cluster through an associated network.
摘要:
Methods and systems for assigning security settings to one or more nodes within an enterprise network are disclosed. One method includes receiving network concordance data at an enterprise security management configuration tool from a plurality of nodes within an enterprise network, and receiving, in a configuration user interface, a selection of an affinitization level selected from a plurality of discrete affinitization levels, each of the discrete affinitization levels corresponding to a different extent to which nodes within an enterprise are grouped into profiles. The method also includes automatically grouping each of the plurality of nodes identified in the network concordance data into a plurality of profiles based on the selected affinitization level, and applying a common security policy to each of the nodes included in one of the plurality of profiles.
摘要:
Methods and systems for defining a solution within an enterprise security management configuration server is disclosed. One method includes, based on network concordance data, grouping a plurality of nodes within an enterprise network into a plurality of profiles and identifying one or more channels among the plurality of profiles within a project of an enterprise security management configuration tool. The method also includes displaying the plurality of profiles in a configuration user interface, and automatically identifying one or more solutions among the plurality of profiles. The method further includes collapsing each of the one or more solutions into a single icon within the configuration user interface, each single icon representing a solution.
摘要:
Methods of communicatively connecting first and second endpoints are disclosed. One method includes transmitting from a first endpoint to a second endpoint a connection request, the connection request including an IP address of the second endpoint. The method further includes, based at least in part on the IP address of the second endpoint, selecting IPsec from among a plurality of available security protocols to first attempt to use in forming a tunnel between the first and second endpoints, and forming the tunnel between the first and second endpoints based on the connection request.
摘要:
Methods and systems of communicating with secure endpoints included within a secured network from a mobile device external to the secured network is disclosed. The method includes initiating a VPN-based secure connection to a VPN appliance, and initializing a stealth-based service on the mobile device. The method further includes transmitting user credential information from the mobile device to a VDR broker via the VPN appliance, and receiving status information from the VDR broker identifying a VDR associated with the mobile device and providing a connected status. The method also includes communicating with one or more secure endpoints within the secured network via a VPN connection to the VDR via the VPN appliance and through the VDR to the one or more secure endpoints within a community of interest based on the user credential information transmitted to the VDR broker.
摘要:
Provided are apparatus and systems having a lessened pulsation through the use of a pulse flow control mechanism. In performing a cyclical swing adsorption process, various streams are passed through adsorbent bed units during various steps in the swing adsorption process. The pulse flow control mechanism is utilized within a manifold of one of the streams to lessen pulsation within the manifold that results from performing the various steps.
摘要:
Provided are apparatus and systems for performing a swing adsorption process. This swing adsorption process may involve passing streams through adsorbent bed units to treat the pipeline quality natural gas to form a stream that complies with liquefied natural gas (LNG) specifications. The process may involve a combined TSA and PSA process, which is utilized to remove contaminants from the feed stream.
摘要:
Provided are apparatus and systems having a lessened pulsation through the use of a pulse flow control mechanism. In performing a cyclical swing adsorption process, various streams are passed through adsorbent bed units during various steps in the swing adsorption process. The pulse flow control mechanism is utilized within a manifold of one of the streams to lessen pulsation within the manifold that results from performing the various steps.
摘要:
A pressure swing adsorption process for removal of C02 from natural gas streams through a combination of a selective adsorbent material containing an effective amount of a non-adsorbent filler, adsorbent contactor design, and adsorption cycle design. The removal of contaminants from gas streams, preferably natural gas streams, using rapid-cycle swing adsorption processes, such as rapid-cycle pressure swing adsorption (RC-PSA). Separations at high pressure with high product recovery and/or high product purity are provided through a combination of judicious choices of adsorbent material, gas-solid contactor, system configuration, and cycle designs. For example, cycle designs that include steps of purge and staged blow-down as well as the inclusion of a mesopore filler in the adsorbent material significantly improves product (e.g., methane) recovery. An RC-PSA product with less than 10 ppm H2S can be produced from a natural gas feed stream that contains less than 1 mole percent H2S.