Patents Examined by Harris C Wang
  • Patent number: 11799855
    Abstract: Systems, methods, and related technologies for device identification are described. In certain aspects, packet data associated with a device can be analyzed and a score determined. The score and the threshold can be compared to determine a device identification for the device.
    Type: Grant
    Filed: November 5, 2020
    Date of Patent: October 24, 2023
    Assignee: FORESCOUT TECHNOLOGIES, INC.
    Inventors: Yang Zhang, Siying Yang
  • Patent number: 11799860
    Abstract: Systems and methods include providing a user interface to an administrator associated with a tenant of a cloud-based system, wherein the tenant has a plurality of users each having an associated user device; receiving a plurality of client forwarding policies for the plurality of users, wherein each client forwarding policy of the client forwarding policies define rules related to how application requests from the plurality of users are forwarded for zero trust access; and providing the rules to corresponding user devices of the plurality of users.
    Type: Grant
    Filed: November 24, 2020
    Date of Patent: October 24, 2023
    Assignee: Zscaler, Inc.
    Inventors: Kunal Shah, John A. Chanak, David Creedy
  • Patent number: 11799663
    Abstract: Systems and methods are described that relate to authentication and/or binding of multiple devices with varying security profiles. In one aspect, a first device with a higher security profile may vouch for the authenticity of a second device with a lower security profile when the second device requests access for content from a content provider. The vouching process may be implemented by allowing the first device to overlay its digital signature on a registration request that has been signed and transmitted by the second device. The second device with the lower security profile may access content from the content provider or source for a predetermined time period, even when the second device does not access content through the first device.
    Type: Grant
    Filed: August 28, 2020
    Date of Patent: October 24, 2023
    Assignee: Comcast Cable Communications, LLC
    Inventors: James W. Fahrny, Kyong Park
  • Patent number: 11777939
    Abstract: A method and device for processing information, and a storage medium is provided. The method is applied to an authorization proxy server, and includes receiving a first account information of a first vehicle-mounted terminal, determining, based on an associating record of a user account service, that a first account corresponding to the first account information is an authorized account that has been associated with the user account service, and authorizing the first account with a control right for controlling a device to be controlled.
    Type: Grant
    Filed: July 27, 2020
    Date of Patent: October 3, 2023
    Assignee: Beijing Xiaomi Pinecone Electronics Co., Ltd.
    Inventors: Zhiming Li, Li Zhao, Yanning Wang, Feng Han
  • Patent number: 11770392
    Abstract: Methods, systems, and computing platforms for data communication are disclosed. A computer-data communication based network, including receiving a set of virtual nodes each with a data payload may include an originating node attribute, an infosec data attribute, an behavioral data attribute, a biometric enterprise attribute and at least one data element associated with the originating node attribute. A machine learning module may learn from across multiple of collection points to determine control triggers and control durations. A user anomaly collector/module may be configured to identify an unusual or anomalous usage of an application.
    Type: Grant
    Filed: January 8, 2020
    Date of Patent: September 26, 2023
    Assignee: Bank of America Corporation
    Inventors: George Albero, Elijah Clark
  • Patent number: 11765182
    Abstract: A system for location-aware authentication is configured to receive an authentication request associated with an identifier of a user for accessing an application and retrieves user information associated with the identifier and the application. The system then determines that the user information includes a geofence and information associated with a device of the user. Based on the geofence and the device information, the system sends a geolocation data request to the device, causing the device to gather and send the device's current geolocation data to the computing system. A data structure is generated to store data related to the device's current geolocation and sent to the application, which in turn causes the application to grant or deny the authentication request.
    Type: Grant
    Filed: October 23, 2020
    Date of Patent: September 19, 2023
    Assignee: Microsoft Technology Licensing, LLC
    Inventors: Olena Lanxin Huang, Jia Le He, Samir Vasantbhai Shah, Andrew Pickering
  • Patent number: 11750595
    Abstract: Systems for credential evaluation and control are provided. In some examples, a request to access data via a website may be received. The request may include a username. A browser extension embedded in the web browser used to request the data via the website may be triggered and one or more credential evaluation functions may be executed. An event record associated with the request to access data may be generated. The event record may be analyzed to determine a designation associated with the website and a designation associated with user credentials provided with the request to access the data. The designation of the website and the designation of the credentials may be compared to determine whether the designations match. If so, access to the requested data may be provided. If not, one or more mitigating actions may be identified and executed.
    Type: Grant
    Filed: February 9, 2021
    Date of Patent: September 5, 2023
    Assignee: Bank of America Corporation
    Inventors: Stuart David Ford, Ricardo Varanda, Andrew Paul Montgomery, Sanjay Bhanu
  • Patent number: 11743054
    Abstract: To easily identify an invalid device certificate by means of a validity check when signing keys that are used to create device certificates are compromised, a piece of status information is provided for device certificates that comprises positive evidence of the existence and validity of the device certificate, and alternatively or additionally to apply a special validity model for device certificates, wherein the time of issue of the device certificate is documented by means of a signed electronic timestamp, and wherein a different signing key is used for signing the timestamp than for signing the device certificate. Additionally, all information that is required for the validity check of a device certificate is stored in a memory of the device or in a memory associated with the device, so that an identity check on the device can be performed at any time without fetching additional data.
    Type: Grant
    Filed: October 22, 2020
    Date of Patent: August 29, 2023
    Assignee: Phoenix Contact GmbH & Co. KG
    Inventor: Torsten Nitschke
  • Patent number: 11743253
    Abstract: A system for bidirectional device authentication between two computing devices is disclosed. A first processor generates a first random number sequence, performs a first operation on the first random number sequence to determine a first table address, and retrieves a first entry in the first table based on the first table address. The processor also executes a first transformation function on the first entry to generate a first transformed entry, transmits the first random number sequence to the second computing device, receives an encoded entry from a second computing device in response to transmission of the first random number sequence, and decodes the encoded entry to determine a second transformed entry. The first transformed entry matches the second transformed entry, and the first processor performs an update to a dynamic table by replacing each entry of the dynamic table with an associated transformed entry.
    Type: Grant
    Filed: May 8, 2018
    Date of Patent: August 29, 2023
    Assignee: Roche Diabetes Care, Inc.
    Inventors: Nagaraj Hegde, Craig L. Carlson, Phillip E. Pash, Robert P. Sabo
  • Patent number: 11729177
    Abstract: A computer-implemented method includes receiving an authentication request from an external device for authenticating an application on the external device, and receiving a plurality of information items in connection with the authentication request from a plurality of different externally residing information sources. The authentication request is then evaluated, which includes evaluating each of the plurality of information items, to determine an authentication status of the application. Based on the authentication status, the device is then selectively permitted access to private information through the application. A computer system and/or machine-readable media may be provided to perform some or all steps of the method.
    Type: Grant
    Filed: April 30, 2020
    Date of Patent: August 15, 2023
    Assignee: Capital One Services, LLC
    Inventors: Daniel Jarvis, Andrew Beck, Manuel Vicente Vivo
  • Patent number: 11689530
    Abstract: A system for managing custom code within a data computing platform determines that a request for one or more uniform resource identifiers external to the platform is being made by custom code executing in the platform. In response to the determination, the system checks a whitelist of allowable external URIs against the requested one or more URIs and allows access to the requested one or more URIs if a match is detected with the whitelist, otherwise access by the custom code to the requested one or more URIs is denied. In addition, or alternatively, the system checks a blacklist of disallowed external URIs against the requested one or more URIs and denies access to the requested one or more URIs if a match is detected with the blacklist, otherwise access by the custom code to the requested one or more URIs is allowed. The blacklist can override the whitelist.
    Type: Grant
    Filed: December 2, 2019
    Date of Patent: June 27, 2023
    Assignee: Palantir Technologies Inc.
    Inventor: James Ding
  • Patent number: 11677723
    Abstract: Systems and methods directed to a third-party gateway that controls egress traffic from Internet Data Centers (IDC) and/or Virtual Private Clouds (VPC) are described. When egress traffic reaches the third-party gateway, a forward proxy may obtain a service identified or otherwise associated with the source IP address and port. Once, the service is identified, the third-party gateway may obtain a configuration rule specified by a rule manager to determine if the service is allowed to access the destination host(s). If the destination host is approved for the service, the forward proxy may send the traffic to the internet. If the destination host is not approved for the service, the forward proxy may block or otherwise drop the respective communication. In some examples, one or more auditors or auditing agencies may access essential information from the third-party gateway to view egress traffic logs and verify egress traffic approved destinations.
    Type: Grant
    Filed: February 25, 2022
    Date of Patent: June 13, 2023
    Assignee: BEIJING BYTEDANCE NETWORK TECHNOLOGY CO., LTD.
    Inventors: Jialin Wang, Fangfei Chen, Kaitong Guo, Yi Cao, Pangyang Chu
  • Patent number: 11627148
    Abstract: Systems and methods include obtaining data from a log system storing historical transactions monitored by a security system; creating one or more mock transactions based on the data; and analyzing the one or more mock transactions with a signature pattern matching engine having updates provided therein subsequent to a time of the historical transactions. The one or more mock transactions can have a header based on the data from corresponding historical transactions. The systems and methods can include performing a content scan in the one or more mock transactions based on the signature pattern matching engine having the updates, or determining malicious activity in the one or more mock transactions based on the signature pattern matching engine having the updates to determine missed matches in the corresponding historical transactions.
    Type: Grant
    Filed: June 26, 2019
    Date of Patent: April 11, 2023
    Assignee: Zscaler, Inc.
    Inventor: Deepen Desai
  • Patent number: 11616854
    Abstract: Systems and methods of securing interface to a blockchain based network, including generating, by a server, a proxy communication layer for communication between the server and a computerized device, wherein the proxy communication layer replaces an IP address of the computerized device with another IP address, intercepting, by the server, data communicated through the proxy communication layer, and blocking, by the server, unauthorized communication data intercepted by the server, wherein communication requests associated with unauthorized IP addresses are blocked, where the server is in communication with the blockchain based network, and wherein the server provides a web interface to decentralized applications of the blockchain based network.
    Type: Grant
    Filed: July 14, 2022
    Date of Patent: March 28, 2023
    Assignee: ZENGO LTD.
    Inventors: Tal Arieh Be'Ery, Menahem Cherbakovsky
  • Patent number: 11611547
    Abstract: Devices, systems and methods for authenticating a user to access electronic content include use of a processor configured to identify a technical condition for the content, access distributor logic providing a first release of the technical condition, receive a request from a subscriber to transfer the first release to an identified user, determine whether to approve or deny the request, and when approved, provide a device associated with the identified user with an authentication that permits the identified user to activate the first release and access the electronic content, and a database that stores the technical condition.
    Type: Grant
    Filed: October 19, 2017
    Date of Patent: March 21, 2023
    Assignee: DISH Network L.L.C.
    Inventor: Benjamin Gerard Husser
  • Patent number: 11604894
    Abstract: Embodiments of the present specification disclose data processing methods, apparatuses, devices, and media. One method includes the following: receiving a data use request; determining data to be used based on the data use request; determining one or more approvers of the data to be used; sending an approval instruction to the one or more approvers, wherein the approval instruction instructs the one or more approvers to approve the data use request; receiving feedback data from the one or more approvers; and determining that the data use request is approved if the feedback data satisfies a predetermined condition.
    Type: Grant
    Filed: June 29, 2021
    Date of Patent: March 14, 2023
    Assignee: Alipay (Hangzhou) Information Technology Co., Ltd.
    Inventors: Qin Liu, Shubo Li, Yuan Chen, Renhui Yang, Wenyu Yang
  • Patent number: 11582212
    Abstract: A tamper resistant device can be used for an integrated circuit card. The device includes memory storing a first security domain that includes a telecommunication profile and a second security domain that includes an application profile. A first physical interface is configured to be coupled to a baseband processor configured to operate with a mobile telecommunications network. A second physical interface configured to be coupled to an application processor. The first physical interface configured to allow the baseband processor to access the telecommunication profile and the second physical interface is configured to allow the application processor to access the application profile. The tamper resistant device is configured to enable accessibility to the application profile if corresponding commands are received at the first interface and to enable accessibility to the telecommunication profile if corresponding commands are received at the second interface.
    Type: Grant
    Filed: October 17, 2019
    Date of Patent: February 14, 2023
    Assignee: STMicroelectronics S.r.l.
    Inventors: Luca Di Cosmo, Amedeo Veneroso
  • Patent number: 11575709
    Abstract: Disclosed herein are methods, systems, and processes for monitoring scan attempts in a network. A virtual security appliance with multiple ports is deployed in a network. One or more ports are obfuscated via the virtual security appliance to make the various ports appear to be closed. An address of the virtual security appliance within the network is modified, the several ports are adjusted to assume a predetermined profile, a network neighbor's profile is discovered and emulated, and a received connection attempt intended for the virtual security appliance is monitored.
    Type: Grant
    Filed: March 15, 2021
    Date of Patent: February 7, 2023
    Assignee: Rapid7, Inc.
    Inventors: Roy Hodgman, Jeffrey D. Myers
  • Patent number: 11533318
    Abstract: Various embodiments described herein relate to a call management system that aims to provide a more efficient, secure, and dynamic technique for authenticating a user based on a location of the user. A server of the call management system receives a phone call from a user device. The server transfers the phone call to an analyst device. When the analyst device accepts the phone call, the server starts an electronic communication session between the user device and the analyst device. The server then determines a current location of the user. The server further determines a question for authentication of the user based on the current location. The server transmits the question to the analyst device. The analyst device transmits the question to the user device via the server. In response to an answer received from the user device, the server authenticates the user.
    Type: Grant
    Filed: September 30, 2020
    Date of Patent: December 20, 2022
    Assignee: United Services Automobile Association (USAA)
    Inventors: Bryan J. Osterkamp, Ryan Thomas Russell, Jon D. McEachron, Gregory B. Yarbrough, Janelle Denice Dziuk
  • Patent number: 11533307
    Abstract: Systems and methods include intercepting traffic on a mobile device based on a set of rules; determining whether a connection associated with the traffic is allowed based on a local map associated with an application; responsive to the connection being allowed or blocked based on the local map, one of forwarding the traffic associated with the connection when allowed and generating a block of the connection at the mobile device when blocked; and, responsive to the connection not having an entry in the local map, forwarding a request for the connection to a cloud-based system for processing therein. The cloud-based system is configured to allow or block the connection based on the connection not having an entry in the local map.
    Type: Grant
    Filed: July 7, 2020
    Date of Patent: December 20, 2022
    Assignee: Zscaler, Inc.
    Inventors: Vikas Mahajan, Rohit Goyal