Patents Examined by Harris C Wang
-
Patent number: 11799855Abstract: Systems, methods, and related technologies for device identification are described. In certain aspects, packet data associated with a device can be analyzed and a score determined. The score and the threshold can be compared to determine a device identification for the device.Type: GrantFiled: November 5, 2020Date of Patent: October 24, 2023Assignee: FORESCOUT TECHNOLOGIES, INC.Inventors: Yang Zhang, Siying Yang
-
Patent number: 11799860Abstract: Systems and methods include providing a user interface to an administrator associated with a tenant of a cloud-based system, wherein the tenant has a plurality of users each having an associated user device; receiving a plurality of client forwarding policies for the plurality of users, wherein each client forwarding policy of the client forwarding policies define rules related to how application requests from the plurality of users are forwarded for zero trust access; and providing the rules to corresponding user devices of the plurality of users.Type: GrantFiled: November 24, 2020Date of Patent: October 24, 2023Assignee: Zscaler, Inc.Inventors: Kunal Shah, John A. Chanak, David Creedy
-
Patent number: 11799663Abstract: Systems and methods are described that relate to authentication and/or binding of multiple devices with varying security profiles. In one aspect, a first device with a higher security profile may vouch for the authenticity of a second device with a lower security profile when the second device requests access for content from a content provider. The vouching process may be implemented by allowing the first device to overlay its digital signature on a registration request that has been signed and transmitted by the second device. The second device with the lower security profile may access content from the content provider or source for a predetermined time period, even when the second device does not access content through the first device.Type: GrantFiled: August 28, 2020Date of Patent: October 24, 2023Assignee: Comcast Cable Communications, LLCInventors: James W. Fahrny, Kyong Park
-
Patent number: 11777939Abstract: A method and device for processing information, and a storage medium is provided. The method is applied to an authorization proxy server, and includes receiving a first account information of a first vehicle-mounted terminal, determining, based on an associating record of a user account service, that a first account corresponding to the first account information is an authorized account that has been associated with the user account service, and authorizing the first account with a control right for controlling a device to be controlled.Type: GrantFiled: July 27, 2020Date of Patent: October 3, 2023Assignee: Beijing Xiaomi Pinecone Electronics Co., Ltd.Inventors: Zhiming Li, Li Zhao, Yanning Wang, Feng Han
-
Patent number: 11770392Abstract: Methods, systems, and computing platforms for data communication are disclosed. A computer-data communication based network, including receiving a set of virtual nodes each with a data payload may include an originating node attribute, an infosec data attribute, an behavioral data attribute, a biometric enterprise attribute and at least one data element associated with the originating node attribute. A machine learning module may learn from across multiple of collection points to determine control triggers and control durations. A user anomaly collector/module may be configured to identify an unusual or anomalous usage of an application.Type: GrantFiled: January 8, 2020Date of Patent: September 26, 2023Assignee: Bank of America CorporationInventors: George Albero, Elijah Clark
-
Patent number: 11765182Abstract: A system for location-aware authentication is configured to receive an authentication request associated with an identifier of a user for accessing an application and retrieves user information associated with the identifier and the application. The system then determines that the user information includes a geofence and information associated with a device of the user. Based on the geofence and the device information, the system sends a geolocation data request to the device, causing the device to gather and send the device's current geolocation data to the computing system. A data structure is generated to store data related to the device's current geolocation and sent to the application, which in turn causes the application to grant or deny the authentication request.Type: GrantFiled: October 23, 2020Date of Patent: September 19, 2023Assignee: Microsoft Technology Licensing, LLCInventors: Olena Lanxin Huang, Jia Le He, Samir Vasantbhai Shah, Andrew Pickering
-
Patent number: 11750595Abstract: Systems for credential evaluation and control are provided. In some examples, a request to access data via a website may be received. The request may include a username. A browser extension embedded in the web browser used to request the data via the website may be triggered and one or more credential evaluation functions may be executed. An event record associated with the request to access data may be generated. The event record may be analyzed to determine a designation associated with the website and a designation associated with user credentials provided with the request to access the data. The designation of the website and the designation of the credentials may be compared to determine whether the designations match. If so, access to the requested data may be provided. If not, one or more mitigating actions may be identified and executed.Type: GrantFiled: February 9, 2021Date of Patent: September 5, 2023Assignee: Bank of America CorporationInventors: Stuart David Ford, Ricardo Varanda, Andrew Paul Montgomery, Sanjay Bhanu
-
Patent number: 11743054Abstract: To easily identify an invalid device certificate by means of a validity check when signing keys that are used to create device certificates are compromised, a piece of status information is provided for device certificates that comprises positive evidence of the existence and validity of the device certificate, and alternatively or additionally to apply a special validity model for device certificates, wherein the time of issue of the device certificate is documented by means of a signed electronic timestamp, and wherein a different signing key is used for signing the timestamp than for signing the device certificate. Additionally, all information that is required for the validity check of a device certificate is stored in a memory of the device or in a memory associated with the device, so that an identity check on the device can be performed at any time without fetching additional data.Type: GrantFiled: October 22, 2020Date of Patent: August 29, 2023Assignee: Phoenix Contact GmbH & Co. KGInventor: Torsten Nitschke
-
Patent number: 11743253Abstract: A system for bidirectional device authentication between two computing devices is disclosed. A first processor generates a first random number sequence, performs a first operation on the first random number sequence to determine a first table address, and retrieves a first entry in the first table based on the first table address. The processor also executes a first transformation function on the first entry to generate a first transformed entry, transmits the first random number sequence to the second computing device, receives an encoded entry from a second computing device in response to transmission of the first random number sequence, and decodes the encoded entry to determine a second transformed entry. The first transformed entry matches the second transformed entry, and the first processor performs an update to a dynamic table by replacing each entry of the dynamic table with an associated transformed entry.Type: GrantFiled: May 8, 2018Date of Patent: August 29, 2023Assignee: Roche Diabetes Care, Inc.Inventors: Nagaraj Hegde, Craig L. Carlson, Phillip E. Pash, Robert P. Sabo
-
Patent number: 11729177Abstract: A computer-implemented method includes receiving an authentication request from an external device for authenticating an application on the external device, and receiving a plurality of information items in connection with the authentication request from a plurality of different externally residing information sources. The authentication request is then evaluated, which includes evaluating each of the plurality of information items, to determine an authentication status of the application. Based on the authentication status, the device is then selectively permitted access to private information through the application. A computer system and/or machine-readable media may be provided to perform some or all steps of the method.Type: GrantFiled: April 30, 2020Date of Patent: August 15, 2023Assignee: Capital One Services, LLCInventors: Daniel Jarvis, Andrew Beck, Manuel Vicente Vivo
-
Patent number: 11689530Abstract: A system for managing custom code within a data computing platform determines that a request for one or more uniform resource identifiers external to the platform is being made by custom code executing in the platform. In response to the determination, the system checks a whitelist of allowable external URIs against the requested one or more URIs and allows access to the requested one or more URIs if a match is detected with the whitelist, otherwise access by the custom code to the requested one or more URIs is denied. In addition, or alternatively, the system checks a blacklist of disallowed external URIs against the requested one or more URIs and denies access to the requested one or more URIs if a match is detected with the blacklist, otherwise access by the custom code to the requested one or more URIs is allowed. The blacklist can override the whitelist.Type: GrantFiled: December 2, 2019Date of Patent: June 27, 2023Assignee: Palantir Technologies Inc.Inventor: James Ding
-
Patent number: 11677723Abstract: Systems and methods directed to a third-party gateway that controls egress traffic from Internet Data Centers (IDC) and/or Virtual Private Clouds (VPC) are described. When egress traffic reaches the third-party gateway, a forward proxy may obtain a service identified or otherwise associated with the source IP address and port. Once, the service is identified, the third-party gateway may obtain a configuration rule specified by a rule manager to determine if the service is allowed to access the destination host(s). If the destination host is approved for the service, the forward proxy may send the traffic to the internet. If the destination host is not approved for the service, the forward proxy may block or otherwise drop the respective communication. In some examples, one or more auditors or auditing agencies may access essential information from the third-party gateway to view egress traffic logs and verify egress traffic approved destinations.Type: GrantFiled: February 25, 2022Date of Patent: June 13, 2023Assignee: BEIJING BYTEDANCE NETWORK TECHNOLOGY CO., LTD.Inventors: Jialin Wang, Fangfei Chen, Kaitong Guo, Yi Cao, Pangyang Chu
-
Patent number: 11627148Abstract: Systems and methods include obtaining data from a log system storing historical transactions monitored by a security system; creating one or more mock transactions based on the data; and analyzing the one or more mock transactions with a signature pattern matching engine having updates provided therein subsequent to a time of the historical transactions. The one or more mock transactions can have a header based on the data from corresponding historical transactions. The systems and methods can include performing a content scan in the one or more mock transactions based on the signature pattern matching engine having the updates, or determining malicious activity in the one or more mock transactions based on the signature pattern matching engine having the updates to determine missed matches in the corresponding historical transactions.Type: GrantFiled: June 26, 2019Date of Patent: April 11, 2023Assignee: Zscaler, Inc.Inventor: Deepen Desai
-
Patent number: 11616854Abstract: Systems and methods of securing interface to a blockchain based network, including generating, by a server, a proxy communication layer for communication between the server and a computerized device, wherein the proxy communication layer replaces an IP address of the computerized device with another IP address, intercepting, by the server, data communicated through the proxy communication layer, and blocking, by the server, unauthorized communication data intercepted by the server, wherein communication requests associated with unauthorized IP addresses are blocked, where the server is in communication with the blockchain based network, and wherein the server provides a web interface to decentralized applications of the blockchain based network.Type: GrantFiled: July 14, 2022Date of Patent: March 28, 2023Assignee: ZENGO LTD.Inventors: Tal Arieh Be'Ery, Menahem Cherbakovsky
-
Patent number: 11611547Abstract: Devices, systems and methods for authenticating a user to access electronic content include use of a processor configured to identify a technical condition for the content, access distributor logic providing a first release of the technical condition, receive a request from a subscriber to transfer the first release to an identified user, determine whether to approve or deny the request, and when approved, provide a device associated with the identified user with an authentication that permits the identified user to activate the first release and access the electronic content, and a database that stores the technical condition.Type: GrantFiled: October 19, 2017Date of Patent: March 21, 2023Assignee: DISH Network L.L.C.Inventor: Benjamin Gerard Husser
-
Patent number: 11604894Abstract: Embodiments of the present specification disclose data processing methods, apparatuses, devices, and media. One method includes the following: receiving a data use request; determining data to be used based on the data use request; determining one or more approvers of the data to be used; sending an approval instruction to the one or more approvers, wherein the approval instruction instructs the one or more approvers to approve the data use request; receiving feedback data from the one or more approvers; and determining that the data use request is approved if the feedback data satisfies a predetermined condition.Type: GrantFiled: June 29, 2021Date of Patent: March 14, 2023Assignee: Alipay (Hangzhou) Information Technology Co., Ltd.Inventors: Qin Liu, Shubo Li, Yuan Chen, Renhui Yang, Wenyu Yang
-
Patent number: 11582212Abstract: A tamper resistant device can be used for an integrated circuit card. The device includes memory storing a first security domain that includes a telecommunication profile and a second security domain that includes an application profile. A first physical interface is configured to be coupled to a baseband processor configured to operate with a mobile telecommunications network. A second physical interface configured to be coupled to an application processor. The first physical interface configured to allow the baseband processor to access the telecommunication profile and the second physical interface is configured to allow the application processor to access the application profile. The tamper resistant device is configured to enable accessibility to the application profile if corresponding commands are received at the first interface and to enable accessibility to the telecommunication profile if corresponding commands are received at the second interface.Type: GrantFiled: October 17, 2019Date of Patent: February 14, 2023Assignee: STMicroelectronics S.r.l.Inventors: Luca Di Cosmo, Amedeo Veneroso
-
Patent number: 11575709Abstract: Disclosed herein are methods, systems, and processes for monitoring scan attempts in a network. A virtual security appliance with multiple ports is deployed in a network. One or more ports are obfuscated via the virtual security appliance to make the various ports appear to be closed. An address of the virtual security appliance within the network is modified, the several ports are adjusted to assume a predetermined profile, a network neighbor's profile is discovered and emulated, and a received connection attempt intended for the virtual security appliance is monitored.Type: GrantFiled: March 15, 2021Date of Patent: February 7, 2023Assignee: Rapid7, Inc.Inventors: Roy Hodgman, Jeffrey D. Myers
-
Patent number: 11533318Abstract: Various embodiments described herein relate to a call management system that aims to provide a more efficient, secure, and dynamic technique for authenticating a user based on a location of the user. A server of the call management system receives a phone call from a user device. The server transfers the phone call to an analyst device. When the analyst device accepts the phone call, the server starts an electronic communication session between the user device and the analyst device. The server then determines a current location of the user. The server further determines a question for authentication of the user based on the current location. The server transmits the question to the analyst device. The analyst device transmits the question to the user device via the server. In response to an answer received from the user device, the server authenticates the user.Type: GrantFiled: September 30, 2020Date of Patent: December 20, 2022Assignee: United Services Automobile Association (USAA)Inventors: Bryan J. Osterkamp, Ryan Thomas Russell, Jon D. McEachron, Gregory B. Yarbrough, Janelle Denice Dziuk
-
Patent number: 11533307Abstract: Systems and methods include intercepting traffic on a mobile device based on a set of rules; determining whether a connection associated with the traffic is allowed based on a local map associated with an application; responsive to the connection being allowed or blocked based on the local map, one of forwarding the traffic associated with the connection when allowed and generating a block of the connection at the mobile device when blocked; and, responsive to the connection not having an entry in the local map, forwarding a request for the connection to a cloud-based system for processing therein. The cloud-based system is configured to allow or block the connection based on the connection not having an entry in the local map.Type: GrantFiled: July 7, 2020Date of Patent: December 20, 2022Assignee: Zscaler, Inc.Inventors: Vikas Mahajan, Rohit Goyal