Patents Examined by Brandon Hoffman
  • Patent number: 12688306
    Abstract: Embodiments herein include generating a safe copy of a first control block for an operating system, recording the safe copy in memory, initiating a test of an authorized service associated with the operating system, identifying a vulnerability for the authorized service that includes comparing a state of the first control block after the test of the authorized service with the safe copy recorded in memory, and initiating an action to alleviate the identified vulnerability.
    Type: Grant
    Filed: September 11, 2024
    Date of Patent: July 21, 2026
    Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
    Inventors: Michael Page Kasper, Bryan Childs, Andrew C. M. Hicks, Diane Marie Stamboni, Joshua David Steen
  • Patent number: 12688321
    Abstract: Provided is a technology for performing secure computation of a k-means method with high accuracy while keeping data secure. The technology includes: centroid table initialization means that sets a table including a set of a share of a cluster ID j and a share of a centroid of a cluster ID j as a j-th record as an initial value of a centroid table; distance table computation means that computes a distance table including a set of a share of a data ID i, the share of the cluster ID j, a share of a distance dij between data of the data ID i and the centroid of the cluster ID j as an M(j?1)+i-th record; cluster ID table computation means that computes a cluster ID table including a set of the share of the data ID i and a share of a cluster ID k(i) of the cluster to which the data of the data ID i belongs as an i-th record; and centroid table computation means that computes the centroid table.
    Type: Grant
    Filed: January 11, 2022
    Date of Patent: July 21, 2026
    Assignee: NTT, Inc.
    Inventors: Ibuki Mishina, Dai Ikarashi, Koki Hamada, Ryo Kikuchi
  • Patent number: 12682097
    Abstract: A platform we call an R-Cloud Data Protection Platform supports the ability to recover anything “as-a-Service” at a specified level of granularity. The approach splits data catalog information between the R-Cloud platform and R-Cloud Modules. It provides the ability to describe every as-a-Service related configuration and data hierarchy, their attributes, associations, relevance to data resilience and the associated methods required to protect and recover the different parts of the service and data. This enables the unique approach to cover all as-a-Service, from the simple ones like Google CloudSQL to the most complex ones having millions of dynamic and unstructured objects within.
    Type: Grant
    Filed: January 30, 2024
    Date of Patent: July 14, 2026
    Assignee: HYCU, INC.
    Inventors: Mladen Brajković, Antal Nemeš, Subbiah Sundaram
  • Patent number: 12683989
    Abstract: A method for scalable vulnerability detection is provided. The method includes selecting at least a workload of a plurality of workloads deployed in a first cloud environment for inspection, wherein the workload includes a first volume; generating in a remote cluster an inspection node, the inspection node including at least a first disk, wherein the remote cluster provisions inspection nodes in response to demand for inspection nodes; generating a persistent volume (PV) on which the at least a first disk is mounted, wherein the at least a first disk is generated from a snapshot of the first volume; and generating a persistent volume claim (PVC) of the PV for an inspector workload, wherein the inspector workload is configured to inspect the PV for an object, and wherein inspector workloads are provisioned in response to demand for inspector workloads.
    Type: Grant
    Filed: May 23, 2024
    Date of Patent: July 14, 2026
    Assignee: Wiz, Inc.
    Inventors: Yarin Miran, Ami Luttwak, Roy Reznik, Avihai Berkovitz, Moran Cohen, Yaniv Shaked, Yaniv Joseph Oliver
  • Patent number: 12682094
    Abstract: A computer-implemented method, according to one approach, includes using a determined classification of a predetermined file to determine a data compliance ruleset that applies to data of the predetermined file. In response to a determination that the data of the predetermined file is scheduled to be moved and/or replicated from a source node to a target node of an edge computing environment, the determined data compliance ruleset is applied to the data of the predetermined file. The method further includes preventing the scheduled movement and/or replication of the data of the predetermined file from occurring, in response to a determination that the scheduled movement and/or replication of the data of the predetermined file violates at least one rule of the determined data compliance ruleset.
    Type: Grant
    Filed: June 9, 2023
    Date of Patent: July 14, 2026
    Assignee: International Business Machines Corporation
    Inventors: Christopher J. Vollmar, Joseph W. Dain, Frank N. Lee, Sandeep Ramesh Patil
  • Patent number: 12676837
    Abstract: Decrypting synthetic transactions with beacon packets is provided. A probe receives, from a client device, a start beacon packet that identifies a test of a service provided by one or more servers. The probe establishes, responsive to receipt of the start beacon packet, a log for the test. The probe stores, in the log established responsive to the start beacon packet, data packets transmitted between the client device and the one or more servers subsequent to the start beacon packet and encrypted with a key using a security protocol. The probe receives, from the client device, key information used to decrypt the data packets of the test encrypted with the key using the security protocol. The probe provides at least one of the data packets for evaluation or decryption using the key information to determine a performance of the service.
    Type: Grant
    Filed: August 26, 2024
    Date of Patent: July 7, 2026
    Assignee: NetScout Systems, Inc.
    Inventors: Bruce Kosbab, Bob Vogt, Paul Alexander Barrett, Anil K. Singhal, Ashwani Singhal, Narendra Byrapuram, Colm Toomey, Connor Monk
  • Patent number: 12676840
    Abstract: Systems and methods for uses and/or improvements to blockchain and blockchain technology, particularly to provide a scalable solution to the aforementioned security and privacy concerns. As one example, systems and methods are described herein for a double-layer restriction subnet architecture that overcomes the technical limitations of conventional blockchains, whether public or permissioned, and subnets thereof. The double-layer restriction subnet architecture comprises a series of permissioned subnets, which provides both the security/privacy benefits of permissioned blockchains but also the scalability of subnet efficiency.
    Type: Grant
    Filed: July 25, 2024
    Date of Patent: July 7, 2026
    Assignee: Citigroup Technology, Inc.
    Inventors: Aharon Baruch Haber, Shobhit Maini, Haiping Choo
  • Patent number: 12670283
    Abstract: Systems and methods for generating location-based application segments include obtaining transactional data for a plurality of users of an enterprise, wherein the transactional data relates to usage of a plurality of applications by the plurality of users; obtaining location data associated with the plurality of applications; and generating one or more application segments based on the transactional data and the location data. In various embodiments, the location data can be leveraged to alter various application segmentation factor thresholds for adapting the likelihood of applications to be grouped together.
    Type: Grant
    Filed: May 6, 2024
    Date of Patent: June 30, 2026
    Assignee: Zscaler, Inc.
    Inventors: Chenhui Hu, Kabir Nagpal
  • Patent number: 12670282
    Abstract: The Abstract of the Disclosure is provided to allow the reader to quickly identify the nature of the technical disclosure. It is submitted with the understanding that it will not be used to interpret or limit the scope or meaning of the claims. In addition, in the foregoing Detailed Description, it can be seen that various features are grouped together in various examples for the purpose of streamlining the disclosure. This method of disclosure is not to be interpreted as reflecting an intention that any claim requires more features than the claim expressly recites. Rather, as the following claims reflect, inventive subject matter lies in less than all features of a single disclosed example. Thus, the following claims are hereby incorporated into the Detailed Description, with each claim standing on its own as a separately claimed subject matter.
    Type: Grant
    Filed: April 29, 2024
    Date of Patent: June 30, 2026
    Assignee: Microsoft Technology Licensing, LLC
    Inventors: Mohamed Azmil Macksood, Pedro Miguel Lima De Jesus Vieira, Gjorgji Rankovski
  • Patent number: 12665747
    Abstract: Training an artificial intelligence model to categorize data by sensitivity and for applying the model to selectively protect sensitive portions of multimodal datasets. Sensitive training data can be obfuscated with synthetic noise or randomized errors to preserve confidentiality while enabling the model to learn patterns correlated with sensitivity. The trained model is validated on labeled data and can be refined as classification standards evolve. In operation, the classifier assigns sensitivity levels to data elements and directs tiered protection. Elements assigned to a higher relative sensitivity classification level are protected using post-quantum key establishment, for example a key encapsulation mechanism, combined with symmetric authenticated encryption of payloads, and associated metadata is authenticated using a post-quantum digital signature scheme. Less sensitive elements can be protected using conventional symmetric encryption for efficiency.
    Type: Grant
    Filed: October 22, 2025
    Date of Patent: June 23, 2026
    Assignee: University of Central Florida Research Foundation, Inc.
    Inventor: David Metcalf
  • Patent number: 12664237
    Abstract: Systems and methods of executing secure write operations within combined supervisory control and data acquisition (SCADA) and programmable logic controller (PLC) systems including receiving an operator interaction at a user interface of a SCADA system, generating an encoded secure write instruction based on the operator interaction in a tamper-resistant secure format at the SCADA system, transmitting the encoded secure write instruction from the SCADA system to a PLC, extracting an operation instruction comprising an operation and a plurality of operation parameters by decoding the encoded secure write instruction at the PLC, and one of executing the operation instruction and rejecting the operating instruction at the PLC.
    Type: Grant
    Filed: September 22, 2025
    Date of Patent: June 23, 2026
    Inventor: Vijay Madisetti
  • Patent number: 12659164
    Abstract: A computer-implemented method, system, and program product is disclosed for anonymized user authentication that dissociates a user's identify from a report submission after successful authentication. The method authenticates field personnel using organization-specific credentials and one-time passcodes, then establishes mathematically anonymous sessions that permanently dissociate user identity from report submissions. Field compliance data including geolocation, equipment status, environmental conditions, and photographic evidence is captured with complete offline capability. The system generates timestamped cryptographic hashes representing each report and records them immutably on distributed ledger networks, while maintaining full report data in encrypted off-chain storage. The system enables regulatory compliance documentation and litigation defense evidence generation, while maintaining complete reporter anonymity through cryptographic guarantees.
    Type: Grant
    Filed: September 5, 2025
    Date of Patent: June 16, 2026
    Assignee: Fenris LLC
    Inventor: David G. Mangold
  • Patent number: 12657281
    Abstract: Examples described herein provide a method that includes providing a joint test action group interface of an engine control, the joint test action group interface being in a disabled state to prevent a device connected to the joint test action group interface from communicating with the engine control. The method further includes detecting whether a control access card is inserted into a port of the engine control. The method further includes, responsive to detecting that the control access card is inserted into the port of the engine control, performing an authentication using a credential stored on the control access card. The method further includes, responsive to successfully completing the authentication, enabling the joint test action group interface of the engine control to enable the device connected to the joint test action group interface to communicate with the engine control.
    Type: Grant
    Filed: August 19, 2022
    Date of Patent: June 16, 2026
    Assignee: RTX CORPORATION
    Inventors: Paul A. Adamski, Jayashree Rajagopalan
  • Patent number: 12657297
    Abstract: An analysis engine receives data characterizing a prompt for ingestion by a generative artificial intelligence (GenAI) model. The analysis engine, using a prompt injection classifier determines whether the prompt comprises or is indicative of malicious content or otherwise elicits malicious actions. The prompt injection classifier can be trained using a dataset generated by populating benign content and malicious content into a plurality of different prompt attack structures at pre-defined locations. Data characterizing the determination is provided to a consuming application or process. Related apparatus, systems, techniques and articles are also described.
    Type: Grant
    Filed: September 17, 2024
    Date of Patent: June 16, 2026
    Assignee: HiddenLayer, Inc.
    Inventors: Kenneth Yeung, Tanner Burns, Kwesi Cappel
  • Patent number: 12659359
    Abstract: Embodiments of the present invention provide a method and apparatus for remotely accessing a computer system or network to identify storage devices and to retrieve metadata from the storage devices that are respectively unique to files stored in the storage devices. An agent is executed by the computer system and receives scanning instructions from a server. A scanning tool compares the metadata retrieved from the computer system or network to a database or list of known metadata of known restricted content. Metadata retrieved from the computer system or network that matches metadata from the database or list of known restricted content is flagged and the file associated with the matching metadata is flagged and reported as potentially storing restricted content. During the scanning, restricted content itself is not scanned, not copied, not transferred and not stored.
    Type: Grant
    Filed: April 16, 2024
    Date of Patent: June 16, 2026
    Inventor: Steve Hummel
  • Patent number: 12657323
    Abstract: An electronic device (e.g., smartphone) identifies digital content and classifies the digital content as confidential digital content via one or more machine learning models. The electronic device automatically stores the confidential digital content in a secure digital storage. The secure digital storage maintains the confidential digital content separately from digital content that is not classified as confidential digital content. Access to the secure digital storage is controlled by the electronic device such that the confidential digital content within the secure digital storage is not exposed outside of the secure digital storage.
    Type: Grant
    Filed: March 29, 2024
    Date of Patent: June 16, 2026
    Assignee: Motorola Mobility LLC
    Inventors: Amit Kumar Agrawal, Panduranga Reddy Pailla, Vijayprakash Idlur
  • Patent number: 12647401
    Abstract: A healthcare data system. The system comprises a data protection entity configured to: sign at least a portion of a routing header of a data packet with a private key held by the data protection entity, the data packet including a payload and a routing header, the payload including healthcare data and the routing header indicating an intended consumer of the data packet; and transmit the data packet on towards the intended consumer. The healthcare data system further comprises one or more data receivers, each configured to: receive the data packet; and verify the signed routing header.
    Type: Grant
    Filed: January 24, 2024
    Date of Patent: June 2, 2026
    Assignee: Roche Diagnostics Operations, Inc.
    Inventor: Domenico de Luca
  • Patent number: 12647455
    Abstract: A method and system for defending AI agents against prompt injection attacks is provided. The method and system include: monitoring, in real-time, a plurality of prompts and a plurality of action sequences for a plurality of AI agents, wherein an action sequence is a series of actions intended to be performed by the AI agent based on at least a corresponding prompt; and for each AI agent, computing a semantic distance metric between each prompt and each action sequence, comparing the computed semantic distance metric to a learned baseline semantic distance computed for the AI agent; and causing an execution of a mitigation action when the computed semantic distance metric deviates from the baseline semantic distance.
    Type: Grant
    Filed: July 30, 2025
    Date of Patent: June 2, 2026
    Assignee: Radware, Ltd.
    Inventors: Gabi Nakibly, David Aviv, Zvika Babo
  • Patent number: 12639701
    Abstract: The present invention concerns the verification and authentication of independent digital wallets and, particularly, the linking of regulated and unregulated digital wallets on a public blockchain. An unregulated trading system has a public certificate module arranged selectively to write NFTs into specific unregulated accounts. A public ledger database of the blockchain system stores unregulated accounts which each contain: (i) a document type identifier having a related minted unique non-transferable NFT linked to an externally generated certificate hash and where each non-transferable NFT is obtained via writing of a smart contract and each non-transferable NFT is a permanent record for a description of the document type; and (ii) a link to a private wallet of a regulated account of a regulated trading platform. The link relates directly to the minted non-transferable NFT issued from the certificate module.
    Type: Grant
    Filed: May 10, 2023
    Date of Patent: May 26, 2026
    Assignee: Tintra 3.0 Limited
    Inventors: David Peter Smith, Joseph Michael William Lyske
  • Patent number: 12641142
    Abstract: Systems and methods for quick start-up of playback in accordance with embodiments of the invention are disclosed. Media content may be encoded in a plurality of alternative streams and a quick start-up stream. The quick start-up stream may include media content that is encoded at a lower quality that the alternative streams and may be encrypted with a different, less secure encryption process than that of the alternative streams. During a start-up of playback, the playback device streams the media content from a quick start-up stream until a metric, such as a decryption key for the alternative streams is met. The device then streams the media content from the alternative streams in response to the metric being met.
    Type: Grant
    Filed: June 14, 2024
    Date of Patent: May 26, 2026
    Assignee: DIVX, LLC
    Inventors: William David Amidei, Jason Braness, Cristina Dobrin