Patents by Inventor Rongfei WAN

Rongfei WAN has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Publication number: 20230353585
    Abstract: Embodiments of this disclosure provide a malicious traffic identification method and a related apparatus. The malicious traffic identification method may include: determining a receiving time of first alarm traffic; obtaining, according to a preset policy, a plurality of pieces of second alarm traffic corresponding to the first alarm traffic within a target time period, where the target time period is a time period determined based on the receiving time, and a similarity between each of the plurality of pieces of second alarm traffic and the first alarm traffic is greater than a preset threshold; performing feature extraction on the plurality of pieces of second alarm traffic to obtain first feature information; and determining, based on the first feature information, whether the first alarm traffic is malicious traffic. In embodiments of this disclosure, accuracy of malicious traffic identification on a live network can be improved by using a multi-flow traceback method.
    Type: Application
    Filed: June 30, 2023
    Publication date: November 2, 2023
    Inventors: Rongfei Wan, Annan Zhu, Jia Zhang, Haixin Duan
  • Patent number: 11588626
    Abstract: This application provides a key distribution method, an apparatus, and a system, includes: determining, by an identity management server based on AAA authentication information, whether AAA authentication on the terminal succeeds; if the AAA authentication succeeds, sending the ID of the terminal to a key management server; and generating, by the key management server, a private key of the terminal and returning the private key to the management server. After negotiating with the terminal to generate a first key, the identity management server encrypts the ID and the private key of the terminal, and sends an encrypted ID and an encrypted private key to the terminal. The terminal obtains the ID and the private key of the terminal. According to the key distribution method, apparatus, and system provided in this application, communication security performance of the terminal during ID-based registration authentication is improved.
    Type: Grant
    Filed: July 11, 2020
    Date of Patent: February 21, 2023
    Assignee: HUAWEI TECHNOLOGIES CO., LTD.
    Inventor: Rongfei Wan
  • Publication number: 20200351082
    Abstract: This application provides a key distribution method, an apparatus, and a system, includes: determining, by an identity management server based on AAA authentication information, whether AAA authentication on the terminal succeeds; if the AAA authentication succeeds, sending the ID of the terminal to a key management server; and generating, by the key management server, a private key of the terminal and returning the private key to the management server. After negotiating with the terminal to generate a first key, the identity management server encrypts the ID and the private key of the terminal, and sends an encrypted ID and an encrypted private key to the terminal. The terminal obtains the ID and the private key of the terminal. According to the key distribution method, apparatus, and system provided in this application, communication security performance of the terminal during ID-based registration authentication is improved.
    Type: Application
    Filed: July 11, 2020
    Publication date: November 5, 2020
    Inventor: Rongfei Wan
  • Patent number: 10754943
    Abstract: A virtual machine kernel protection method and apparatus are disclosed. The method includes: trapping a system call function initiated by an application program (S301); and pointing the system call function to a shadow kernel based on an offset value between a base address of an original kernel of a virtual machine and a base address of the shadow kernel, and determining a corresponding entry address of the system call function in the shadow kernel based on a shadow SSDT in the shadow kernel (S302), where the shadow kernel is constructed in a nonpaged pool of the original kernel of the virtual machine, and the shadow kernel is executable kernel code constructed based on an image file of the original kernel of the virtual machine.
    Type: Grant
    Filed: June 21, 2018
    Date of Patent: August 25, 2020
    Assignee: HUAWEI TECHNOLOGIES CO., LTD.
    Inventors: Rongfei Wan, Xingshu Chen
  • Publication number: 20180314822
    Abstract: A virtual machine kernel protection method and apparatus are disclosed. The method includes: trapping a system call function initiated by an application program (S301); and pointing the system call function to a shadow kernel based on an offset value between a base address of an original kernel of a virtual machine and a base address of the shadow kernel, and determining a corresponding entry address of the system call function in the shadow kernel based on a shadow SSDT in the shadow kernel (S302), where the shadow kernel is constructed in a nonpaged pool of the original kernel of the virtual machine, and the shadow kernel is executable kernel code constructed based on an image file of the original kernel of the virtual machine.
    Type: Application
    Filed: June 21, 2018
    Publication date: November 1, 2018
    Inventors: Rongfei WAN, Xingshu CHEN