Patents Examined by Brandon Hoffman
-
Patent number: 12732487Abstract: A method for securing data access by containerized applications includes intercepting, by a first container executing on a first computing device and associated with a containerized application in a second container executing on the first computing device, a first Internet Protocol (IP) request from the containerized application. The first container determines that the IP request is addressed to a second computing device executing a resource that the containerized application is authorized to access. The first container encrypts a payload portion of the IP request and transmits, to the resource, a second IP request with the encrypted payload portion. The first container receives, from the resource, a response. The first container requests, from a third computing device, a cryptographic key for decrypting the response. The first container decrypts, with the cryptographic key, a payload portion of the response and transmits, to the containerized application, the decrypted payload portion of the response.Type: GrantFiled: April 7, 2024Date of Patent: September 8, 2026Inventors: William Rodgers Ackerly, Julian Embry Herwitz, Timothy Robert Tschampel
-
Patent number: 12730918Abstract: An apparatus and method for autonomously operating a service environment. The apparatus includes a processor configured to receive a service request from a user interface, process the service request by indexing data extracted from the service request using a rule-based algorithm to classify the extracted data to a plurality of data structures, generate a digital access token as a function of the service request using a token generation module, and initiate a service protocol as a function of the digital access token, wherein initiating the service protocol includes transmitting the digital access token to a access control system, and authenticating the digital access token using the access control system.Type: GrantFiled: April 30, 2024Date of Patent: September 8, 2026Assignee: Quick Quack Car Wash Holdings, LLCInventors: Josh David Schumacher, Joseph Allen Steele, III, Jonathan Kevin Cheng
-
Patent number: 12726468Abstract: Techniques are described for providing session management functionalities using an access token (e.g., an Open Authorization (OAuth) access token). Upon successful user authentication, a session (e.g., a single sign-on session) is created for the user along with a user identity token that includes information identifying the session. The user identity token is presentable in an access token request sent to an access token issuer authority (e.g., an OAuth server). Upon receiving the access token request, the user identity token is parsed to identify and validate the session against information stored for the session. The validation can include various session management-related checks. If the validation is successful, the token issuer authority generates the access token. In this manner, the access token that is generated is linked to the session. The access token can then be used by an application to gain access to a protected resource.Type: GrantFiled: October 1, 2024Date of Patent: September 1, 2026Assignee: ORACLE INTERNATIONAL CORPORATIONInventors: Mayank Maria, Aarathi Balakrishnan, Dharmvir Singh, Madhu Martin, Vikas Pooven Chathoth, Vamsi Motukuru
-
Patent number: 12719912Abstract: Various embodiments include systems and methods of implementing automated assessment scheduling. A particular automated assessment may be automatically performed based at least in part on an assessment configuration and scan engine resource(s) of an organization. Based at least in part on performance of the particular automated assessment, a scan engine utilization assessment may be performed to determine a scan engine utilization value that represents utilization of the scan engine resource(s) with respect to resource requirements that are based at least in part on the set of attributes of the assessment configuration. Based at least in part on the scan engine utilization assessment, a particular resource utilization recommendation may be generated. The particular resource utilization recommendation may correspond to a first resource utilization recommendation to allocate additional scan engine resources or a second resource utilization recommendation to allocate fewer scan engine resources.Type: GrantFiled: July 16, 2024Date of Patent: August 25, 2026Assignee: Rapid7, Inc.Inventors: Paul Miseiko, James Cancilla
-
Patent number: 12719849Abstract: A method for protecting data transmission in an ad hoc network including nodes, each node including a private key, a public key and a certificate of the public key signed by a certification authority, the method including transmitting by the first node to the second node: a first message signed with the private key of the first node; a third message containing a first set of initialization data including: a first certificate including the public key of the first node, signed by the certification authority; a second data set including the IP address of the first node; and the first certificate associated with the IP address of the first node, wherein the second data set is signed with the private key of the first node.Type: GrantFiled: November 18, 2013Date of Patent: August 25, 2026Assignee: AIRBUS DS SASInventors: Thierry Deniaud, Romain Carnus
-
Patent number: 12717951Abstract: Systems and techniques for database threat detection are described. First login data for a first database that includes a first aggregation key may be received. A first counter that tracks first events associated with the first database may be determined. A first value of the first counter associated with at least the first aggregation key may be determined. A first feature value associated with the first aggregation key may be determined using the first value. An aggregated anomaly detection score may be determined by combining the first anomaly detection score and a plurality of other anomaly detection scores. A determination may be made that the first login data represents anomalous database activity for the first database by comparing the aggregated anomaly detection score to a threshold anomaly detection score. First output data indicating that the first login data represents anomalous database activity for the first database may be generated.Type: GrantFiled: June 21, 2024Date of Patent: August 25, 2026Assignee: AMAZON TECHNOLOGIES, INC.Inventors: Abishek Sankararaman, Sriram Manohar, Joseph Skinner, Saumya Gaurang Shah, Balakrishnan Narayanaswamy, Farnam Mohasseb
-
Patent number: 12719700Abstract: A method may include receiving configuration data associated with an application used for secure data transfers. The method may include accessing certificate data indicating a certificate chain from a certificate service. The method may include generating a configuration script based at least in part on the configuration data and including at least a portion of the certificate data in the certificate data. The method may include generating a script hash based on at least a portion of the configuration script. The method may include receiving a validation signature for the configuration script from the certificate service. The method may include providing the configuration script, the script hash, and the validation signature to a user device may include the application used for secure data transfers such that the application is modified using the configuration script.Type: GrantFiled: July 12, 2024Date of Patent: August 25, 2026Assignee: Apple Inc.Inventors: Rahul Narayan Singh, Robin Burel, Vincent Pozzuoli, Catalin Giurca, Mamta Devi, Marawan Ragab
-
Patent number: 12717956Abstract: Methods and system implement solutions for integrating encryption and emulation into native database formats and/or architectures. “Native” database is used to describe a database that has not been designed for end to end encryption, an off the shelf database deployment, and/or a commercially available database. According to some embodiments, various encryption systems and methods employ emulation operations to enable a native database and native database functions to leverage full encryption primitives. Various aspects integrate emulation operations into standard database implementations, where the emulation enables native database functions to operate on entirely encrypted data.Type: GrantFiled: April 26, 2024Date of Patent: August 25, 2026Assignee: MongoDB, Inc.Inventor: Tarik Moataz
-
Patent number: 12711107Abstract: The present technology provides a versatile content management system that can also support bi-directional synchronization of an organization account. The organization account is maintained as a plurality of root directories that can be mounted under an organization directory top-level folder. The organization directory top-level folder can appear in a user account's view of the organization account, by does not actually exist as a directory in the content management system. The organization directory top-level folder can be a folder created on a client device in which root directories of an organization account are mounted, but the organization directory top-level folder is not a synchronized directory. The organization directory top-level folder gives the appearance of a single directory structure for an organization even though the organization content is actually organized into the plurality of root directories.Type: GrantFiled: July 5, 2024Date of Patent: August 18, 2026Assignee: Dropbox, Inc.Inventors: Pratik Nadagouda, Austin Willis, Frank Wang, Yufei Zou, Jessica Miao, Kashif Nadeem, Owen Collins, Bozhen Lyu, Ken Park, Jay Paroline, Akos Albert
-
Patent number: 12712879Abstract: A method includes receiving, by a first device that is included in a first network and a second network, a request from a second device to join the first network. The method also includes making, by the first device, determinations of whether to transmit the second device a first credential corresponding to the first network and whether to transmit the second device a second credential corresponding to the second network. The method also includes using the determinations as a basis to select, as content for a message, the first credential, the second credential, or an indication that the second device is not allowed on the first network and not allowed on the second network. The method also includes transmitting the message that includes the content to the second device.Type: GrantFiled: October 18, 2023Date of Patent: August 18, 2026Assignee: Roku, Inc.Inventors: David Stern, Greg Garner, Robert Caston Curtis, Carl Sassenrath
-
Patent number: 12705382Abstract: A system for protecting source code from unauthorized access is disclosed. The system is configured to scan the source code and identify code segments, including function code. The system may perform code obfuscation, code separation, and code encryption. The system may extract a first set of code features from the function code. The first set of code features indicates a first task associated with the function code. The system accesses a training dataset comprising a sample code that is associated with a second task and a template code. The system compares the first task with the second task. In response to determining that the first task corresponds to the second task, the system obfuscates the function code with the template code. In response, the system updates the source code to include the obfuscated function code.Type: GrantFiled: April 26, 2024Date of Patent: August 11, 2026Assignee: Bank of America CorporationInventors: Pushkar Taneja, Suryanarayana Adivi, Shailendra Singh, Sunilkumar Sriperambudur
-
Patent number: 12696095Abstract: The present disclosure generally relates to predicting and remediating fraudulent activity associated with a roaming SIM card. Systems described herein involve detecting potential fraud signals associated with a roaming SIM card and applying one or more machine learning models to those signals to generate a fraud prediction. In one or more examples, the potential fraud signals are detected in connection with one or more core network components of a 5G telecommunication network and provide unique insight into the network activities of a user equipment where the roaming SIM card is installed. As such, the systems described herein generate fraud predictions that take into account signals that are not necessarily indicative of fraud by themselves. Once fraud is predicted, the systems described herein execute various remediation actions to correct the fraudulent activities.Type: GrantFiled: June 14, 2024Date of Patent: July 28, 2026Assignee: Microsoft Technology Licensing, LLCInventors: Andrew John Robinson Hodges, Edmund Richard James Pringle, Keith Stuart Wansbrough, Martin George Davidson
-
Patent number: 12694130Abstract: A method, computer program product, and computer system for receiving, by a computing device, an indication that a software component is to be released for delivery to a customer. A predefined and non-modifiable industry-standard security profile may be selected defining one or more security scans to be executed in accordance with at least one of an application-security framework and a secure-development standard. The one or more security scans may be executed against the software component using the predefined and non-modifiable industry-standard security profile to identify one or more vulnerabilities. It may be determined that the one or more vulnerabilities that exceeds a remediation threshold has been remediated.Type: GrantFiled: November 7, 2025Date of Patent: July 28, 2026Assignee: Truist BankInventor: Brian Matthew White
-
Patent number: 12688306Abstract: Embodiments herein include generating a safe copy of a first control block for an operating system, recording the safe copy in memory, initiating a test of an authorized service associated with the operating system, identifying a vulnerability for the authorized service that includes comparing a state of the first control block after the test of the authorized service with the safe copy recorded in memory, and initiating an action to alleviate the identified vulnerability.Type: GrantFiled: September 11, 2024Date of Patent: July 21, 2026Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATIONInventors: Michael Page Kasper, Bryan Childs, Andrew C. M. Hicks, Diane Marie Stamboni, Joshua David Steen
-
Patent number: 12688321Abstract: Provided is a technology for performing secure computation of a k-means method with high accuracy while keeping data secure. The technology includes: centroid table initialization means that sets a table including a set of a share of a cluster ID j and a share of a centroid of a cluster ID j as a j-th record as an initial value of a centroid table; distance table computation means that computes a distance table including a set of a share of a data ID i, the share of the cluster ID j, a share of a distance dij between data of the data ID i and the centroid of the cluster ID j as an M(j?1)+i-th record; cluster ID table computation means that computes a cluster ID table including a set of the share of the data ID i and a share of a cluster ID k(i) of the cluster to which the data of the data ID i belongs as an i-th record; and centroid table computation means that computes the centroid table.Type: GrantFiled: January 11, 2022Date of Patent: July 21, 2026Assignee: NTT, Inc.Inventors: Ibuki Mishina, Dai Ikarashi, Koki Hamada, Ryo Kikuchi
-
Patent number: 12682097Abstract: A platform we call an R-Cloud Data Protection Platform supports the ability to recover anything “as-a-Service” at a specified level of granularity. The approach splits data catalog information between the R-Cloud platform and R-Cloud Modules. It provides the ability to describe every as-a-Service related configuration and data hierarchy, their attributes, associations, relevance to data resilience and the associated methods required to protect and recover the different parts of the service and data. This enables the unique approach to cover all as-a-Service, from the simple ones like Google CloudSQL to the most complex ones having millions of dynamic and unstructured objects within.Type: GrantFiled: January 30, 2024Date of Patent: July 14, 2026Assignee: HYCU, INC.Inventors: Mladen Brajković, Antal Nemeš, Subbiah Sundaram
-
Patent number: 12683989Abstract: A method for scalable vulnerability detection is provided. The method includes selecting at least a workload of a plurality of workloads deployed in a first cloud environment for inspection, wherein the workload includes a first volume; generating in a remote cluster an inspection node, the inspection node including at least a first disk, wherein the remote cluster provisions inspection nodes in response to demand for inspection nodes; generating a persistent volume (PV) on which the at least a first disk is mounted, wherein the at least a first disk is generated from a snapshot of the first volume; and generating a persistent volume claim (PVC) of the PV for an inspector workload, wherein the inspector workload is configured to inspect the PV for an object, and wherein inspector workloads are provisioned in response to demand for inspector workloads.Type: GrantFiled: May 23, 2024Date of Patent: July 14, 2026Assignee: Wiz, Inc.Inventors: Yarin Miran, Ami Luttwak, Roy Reznik, Avihai Berkovitz, Moran Cohen, Yaniv Shaked, Yaniv Joseph Oliver
-
Patent number: 12682094Abstract: A computer-implemented method, according to one approach, includes using a determined classification of a predetermined file to determine a data compliance ruleset that applies to data of the predetermined file. In response to a determination that the data of the predetermined file is scheduled to be moved and/or replicated from a source node to a target node of an edge computing environment, the determined data compliance ruleset is applied to the data of the predetermined file. The method further includes preventing the scheduled movement and/or replication of the data of the predetermined file from occurring, in response to a determination that the scheduled movement and/or replication of the data of the predetermined file violates at least one rule of the determined data compliance ruleset.Type: GrantFiled: June 9, 2023Date of Patent: July 14, 2026Assignee: International Business Machines CorporationInventors: Christopher J. Vollmar, Joseph W. Dain, Frank N. Lee, Sandeep Ramesh Patil
-
Patent number: 12676837Abstract: Decrypting synthetic transactions with beacon packets is provided. A probe receives, from a client device, a start beacon packet that identifies a test of a service provided by one or more servers. The probe establishes, responsive to receipt of the start beacon packet, a log for the test. The probe stores, in the log established responsive to the start beacon packet, data packets transmitted between the client device and the one or more servers subsequent to the start beacon packet and encrypted with a key using a security protocol. The probe receives, from the client device, key information used to decrypt the data packets of the test encrypted with the key using the security protocol. The probe provides at least one of the data packets for evaluation or decryption using the key information to determine a performance of the service.Type: GrantFiled: August 26, 2024Date of Patent: July 7, 2026Assignee: NetScout Systems, Inc.Inventors: Bruce Kosbab, Bob Vogt, Paul Alexander Barrett, Anil K. Singhal, Ashwani Singhal, Narendra Byrapuram, Colm Toomey, Connor Monk
-
Patent number: 12676840Abstract: Systems and methods for uses and/or improvements to blockchain and blockchain technology, particularly to provide a scalable solution to the aforementioned security and privacy concerns. As one example, systems and methods are described herein for a double-layer restriction subnet architecture that overcomes the technical limitations of conventional blockchains, whether public or permissioned, and subnets thereof. The double-layer restriction subnet architecture comprises a series of permissioned subnets, which provides both the security/privacy benefits of permissioned blockchains but also the scalability of subnet efficiency.Type: GrantFiled: July 25, 2024Date of Patent: July 7, 2026Assignee: Citigroup Technology, Inc.Inventors: Aharon Baruch Haber, Shobhit Maini, Haiping Choo