FIREWALL DRIFT MONITORING AND DETECTION
    2.
    发明申请

    公开(公告)号:WO2023091359A1

    公开(公告)日:2023-05-25

    申请号:PCT/US2022/049674

    申请日:2022-11-11

    Abstract: The present application relates to embodiments for detecting firewall drift. In some embodiments, a first set of firewall rules of a first firewall for a first instance of a distributed application, a second set of firewall rules of a second firewall for a second instance of the distributed application, and a mapping of IP addresses to identifiers of services from amongst a first set of services of the first instance and a second set of services of the second instance may be obtained. First connectivity data and second connectivity data may be generated indicating, for each of IP address associated with the first and second set of firewall rules, a respective port number over which communications between a respective IP address are transmitted, and generating comparison data indicating whether firewall drift is detected based on a comparison of the first connectivity data and the second connectivity data.

    METHOD AND APPARATUS FOR UE AUTHENTICATION FOR REMOTE PROVISIONING

    公开(公告)号:WO2023090820A1

    公开(公告)日:2023-05-25

    申请号:PCT/KR2022/018006

    申请日:2022-11-15

    Inventor: KWEON, Kisuk

    Abstract: The disclosure relates to a communication method and system for converging a 5th-Generation (5G) communication system for supporting higher data rates beyond a 4th-Generation (4G) system with a technology for Internet of Things (IoT). A method is provided for operating a terminal in a wireless network, including configuring a restricted packet data unit session with a provisioning server (PVS); transmitting a remote provisioning request message including a subscription permanent identifier to the PVS; and receiving a remote provisioning response message in response to the remote provisioning request message. The remote provisioning response message includes standalone non-public network credentials and subscription data of a terminal in case that a remote provisioning for the terminal is approved.

    METHOD AND SYSTEM FOR CARRYING OUT MEASUREMENT CAMPAIGNS BY MEANS OF MOTOR VEHICLES USING A CENTRALLY-CONTROLLED CAMPAIGN-SPECIFIC END-TO-END ENCRYPTION OF THE MEASUREMENT DATA

    公开(公告)号:WO2023088548A1

    公开(公告)日:2023-05-25

    申请号:PCT/EP2021/081966

    申请日:2021-11-17

    Applicant: CARIAD SE

    Inventor: SCHIMMEL, Oliver

    Abstract: The invention relates to a method for carrying out measurement campaigns by means of motor vehicles (12). A key derivation module (43) is operated by a central computer system (11), which key derivation module generates a campaign-specific cryptographic key (44) for the respective measurement campaign, and control software (15) is provided in the motor vehicles (12), which control software is executed in a respective local computer system (14) in the respective motor vehicle (12) and is set up a) for carrying out measurements (16) of measurement data (17) in accordance with campaign configuration data (26) of the respective measurement campaign and b) for encrypting the measured measurement data (17) in the local computer system (14) by means of the campaign-specific cryptographic key (44) using a predetermined symmetrical encryption method (45) and c) for transmitting the encrypted measurement data (17) to the central computer system (11).

    外设认证方法、装置、电子设备及存储介质

    公开(公告)号:WO2023087628A1

    公开(公告)日:2023-05-25

    申请号:PCT/CN2022/090698

    申请日:2022-04-29

    Abstract: 本公开涉及一种外设认证方法、装置、电子设备及存储介质,该方法包括响应于外设发送的质询请求,根据质询请求生成质询结果,并将质询结果发送至外设,质询结果用于外设根据质询结果返回密钥查询请求;响应于密钥查询请求进行密钥查询,并将查询结果发送至外设,查询结果用于外设基于查询结果和质询结果生成待验证令牌,并返回待验证令牌以及查询结果对应的密钥索引信息;根据接收到的密钥索引信息确定目标密钥,并基于目标密钥和质询结果生成目标令牌;如果接收到的待验证令牌与目标令牌一致,则确定外设认证成功。本公开能够有效降低终端对外设的认证成本。

    一种云平台权限设置方法、装置、终端设备及存储介质

    公开(公告)号:WO2023087278A1

    公开(公告)日:2023-05-25

    申请号:PCT/CN2021/131905

    申请日:2021-11-19

    Abstract: 一种云平台权限设置方法、装置、终端设备及存储介质,方法包括:获取云平台页面上的功能模块的模块数据,根据模块数据配置页面功能表,获取云平台上所有接口的接口数据,根据接口数据配置系统功能接口表,根据页面功能表中的功能信息以及系统功能接口表中的接口信息,配置包括有每个功能和每个接口之间的对应关系的页面功能依赖接口表;根据每个角色的权限以及页面功能表,配置包括有每个角色所能够使用的功能的角色功能授权表;当第一角色登录云平台并调用第一接口时,根据页面功能依赖接口表、角色功能授权表以及系统功能接口表,确定第一角色是否有权限调用第一接口。该方法解决了现有技术中权限设置效率低下的技术问题。

    SYSTEMS AND METHODS FOR SECURE COMMUNICATION BETWEEN COMPUTING DEVICES OVER AN UNSECURED NETWORK

    公开(公告)号:WO2023086452A1

    公开(公告)日:2023-05-19

    申请号:PCT/US2022/049514

    申请日:2022-11-10

    Applicant: CUCULAN LLC

    Abstract: Techniques for securing communication between a plurality of network computing devices over an unsecured network can include providing a plurality of communication security devices in secure communication with the network computing devices. A list of authorized communication devices can be established that specifies one or more computing devices with which each of the plurality of network computing devices are authorized to communicate. A communication packet from a source network computing device will specify a destination network computing device. A communication security device that receives the packet will transmit the packet to another communication security device associated with the intended destination network computing device when the network computing devices are authorized to communicate. The other communication security device will transmit the packet to the intended destination network when the network computing devices are authorized to communicate. When the source and destination are not authorized to communicate, the packet will be discarded.

    CACHING OF BIOMETRIC DATA
    9.
    发明申请

    公开(公告)号:WO2023086168A1

    公开(公告)日:2023-05-19

    申请号:PCT/US2022/045497

    申请日:2022-10-03

    Applicant: ALCLEAR, LLC

    Inventor: WISNIEWSKI, Rob

    Abstract: An identification station is operable to obtain digital representations of biometrics for people and communicate these digital representations of biometrics over one or more networks to an identification system device in order to identify the people for a variety of different purposes. The identification station also stores data related to previous biometric identifications in a local cache for one or more time windows. Upon obtaining a digital representation of a biometric, the identification station may first check if the digital representation of the biometric corresponds to data in the local cache. If so, the identification station may omit communicating with the identification system device. Otherwise, the identification station may communicate with the identification system device to identify the person, as well as store the digital representation of the biometric in the local cache for the one or more time windows.

    一种区块链中恶意节点的检测方法及区块链

    公开(公告)号:WO2023082903A1

    公开(公告)日:2023-05-19

    申请号:PCT/CN2022/124217

    申请日:2022-10-09

    Abstract: 本发明公开了一种区块链中恶意节点的检测方法及区块链,其中方法为:公证节点获取已认证验证消息、来自第一发送节点的第一验证消息、来自第二发送节点的第二验证消息和来自接收节点的第三验证消息,所述公证节点根据所述已认证验证消息、所述第一验证消息、所述第二验证消息和所述第三验证消息,确定出所述接收节点、所述第一发送节点和所述第二发送节点中的恶意节点。上述方法应用于金融科技(Fintech)时,可以通过验证各节点声明的密文消息与已认证密文消息之间的一致性关系,从而可以确定出所述接收节点、所述第一发送节点和所述第二发送节点中的恶意节点。

Patent Agency Ranking