Patents Examined by Bryan F Wright
  • Patent number: 12730879
    Abstract: A system and method for enforcing a no-harm directive in artificial intelligence systems using a unified training-and-runtime control framework. A harm functional assigns quantitative harm scores to candidate actions in a given state or context, and a policy model is trained via constrained optimization to maximize a primary utility subject to harm constraints, including probability-of-harm limits, tail-risk limits, and optionally cumulative harm budgets. A runtime safety enforcement module mediates deployment by evaluating proposed actions using a harm predictor and constraint policy, and by performing interception, substitution with safe alternatives, or abstention when constraints are predicted to be violated or confidence is insufficient. A monitoring and audit pipeline records decisions and outcomes and may generate triggers for recalibration, rollback, or retraining.
    Type: Grant
    Filed: January 15, 2026
    Date of Patent: September 8, 2026
    Inventor: Anthony LaPine
  • Patent number: 12732823
    Abstract: One or more capabilities of the client device are determined at the client device. A request for a security profile is transmitted from a client device to a remote server. The request includes information related to the one or more capabilities of the client device. The security profile, defining a set of communication parameters based on at least some of the one or more capabilities, is received at the client device from the remote server. The received security profile is interpreted by the client device to obtain instructions for establishing the secure communication channel. The secure communication channel with a second server is then established by the client device based on the instructions from the security profile.
    Type: Grant
    Filed: November 5, 2025
    Date of Patent: September 8, 2026
    Assignee: UAB 360 IT
    Inventors: Mantas Jonytis, Mindaugas Valkaitis
  • Patent number: 12719909
    Abstract: An open-source intelligence (OSINT) monitoring engine operating as an AI-driven system for monitoring incoming content received from an OSINT source to detect emerging cyber threats is described. The OSINT monitoring engine features a source evaluation module, a content processing engine, and a content classification engine. The source evaluation module determines a confidence level associated with a source of the incoming content and refrains from providing textual information associated with the incoming content unless the confidence level associated with the source is equal to or exceeds a prescribed threshold. The content processing engine identifies salient information from the textual information for use in identifying an emerging cyber threat.
    Type: Grant
    Filed: March 3, 2023
    Date of Patent: August 25, 2026
    Assignee: Darktrace Holdings Limited
    Inventors: John Anthony Boyer, Jake Lal
  • Patent number: 12712732
    Abstract: Provided is a method for post-quantum resistant authentication of a service provider device to a user device, using a legacy certificate of said service provider device and a quantum safe cryptography (QSC) certificate of said service provider device. The method includes verifying by a trusted third party device, using said identifier of the legacy certificate comprised in the QSC certificate, a binding of said QSC certificate to the legacy certificate of the service provider device, and verifying a validity of said QSC certificate by said trusted third party device. The binding and validity have been successfully verified by the trusted third party device, authentication of the service provider device to said user device, using said legacy certificate of the service provider device from which can be obtained said identifier comprised in the QSC certificate whose validity has been verified.
    Type: Grant
    Filed: May 10, 2022
    Date of Patent: August 18, 2026
    Assignee: THALES DIS FRANCE SAS
    Inventors: Georges Debois, Gérald Maunier, Mourad Faher
  • Patent number: 12707015
    Abstract: In an image forming apparatus, personal identification information for identifying a user is associated with the user and as such registered. If a request for deletion of a registered user is received, whether to forbid reuse of the personal identification information, which is associated with the registered user for which the request for deletion is received, is determined. A request for registration of a user which a piece of personal identification information is associated with is refused in accordance with a determination to forbid reuse of the piece of personal identification information.
    Type: Grant
    Filed: May 26, 2023
    Date of Patent: August 11, 2026
    Assignee: SHARP KABUSHIKI KAISHA
    Inventor: Harunobu Mori
  • Patent number: 12689613
    Abstract: Systems and methods for privileged remote access to Operational Technology (OT)/Internet of Things (IOT)/Industrial IOT (IIOT)/Industrial Control System (ICS) infrastructure, implemented in a cloud-based system. The method includes steps of, responsive to determining a user can access an application associated with the OT/IOT/IIOT/ICS infrastructure, determining the users security and access policies and creating a session for the user; establishing a secure connection to the application via a lightweight connector connected to the application; and brokering a connection between the users device and the application through the lightweight connector, enabling the user to interact with the application for the OT/IOT/IIOT/ICS infrastructure, based on the user's security and access policies.
    Type: Grant
    Filed: July 13, 2022
    Date of Patent: July 21, 2026
    Assignee: Zscaler, Inc.
    Inventors: Clifford Kahn, William Fehring, Maneesh Sahu, Deepak Patel, Sunil Menon, Dejan Mihajlovic
  • Patent number: 12688301
    Abstract: Aspects of the present disclosure enable a system to perform automated risk analysis of source code of applications. The system may include a machine learning model to analyze the source code. The machine learning model may output an application risk value. Further, the application risk value may be used to determine a remedial action. The remedial action may address a risk associated with the application risk value, or allow for publication of the application.
    Type: Grant
    Filed: December 15, 2023
    Date of Patent: July 21, 2026
    Assignee: Amazon Technologies, Inc.
    Inventors: Brendan Cruz Colon, Matthew Michael Sommer, Consuelo Manas Pilot, Dustin Michael Ingalls, Adam Edward Powers
  • Patent number: 12665918
    Abstract: Systems and methods include, responsive to security research identifying a zero-day Common Vulnerabilities and Exposure (CVE), receiving the associated signatures of the zero-day CVE, responsive to determining a user can access an application via a cloud-based system, obtaining an inspection profile for the user with the inspection profile including a plurality of rules, performing inspection of transactions after the access using the plurality of rules and responsive to results of any of the plurality of rules, performing an action to the access via the cloud-based system.
    Type: Grant
    Filed: June 20, 2022
    Date of Patent: June 23, 2026
    Assignee: Zscaler, Inc.
    Inventors: Pooja Deshmukh, Amit Banker, Kanti Varanasi, John A. Chanak, William Fehring, Nishant Gupta
  • Patent number: 12648451
    Abstract: A method includes generating pattern data including common chip design data and one or more bit spaces or place holders reserved for non-common chip design data or information related to the non-common chip design data. The method includes introducing the non-common chip design data or information related to the non-common chip design data into the one or more bit spaces or place holders of the pattern data before streaming the pattern data to the maskless pattern writer. The common chip design data defines a common design layout part of an electronic device to be created on a wafer using the maskless pattern writer. The non-common chip design data defines a non-common design layout part of the electronic device to be created on the wafer using the maskless pattern writer, the non-common design layout part being different from other electronic devices created on the wafer.
    Type: Grant
    Filed: May 16, 2023
    Date of Patent: June 2, 2026
    Assignee: ASML Netherlands B.V.
    Inventors: Johannes Cornelis Jacobus De Langen, Marcel Nicolaas Jacobus van Kervinck, Vincent Sylvester Kuiper
  • Patent number: 12640913
    Abstract: Systems and techniques are provided for establishing a connection. For instance, a first chiplet root of trust (C-RoT) of a first chiplet of a plurality of chiplets can receive a request for a cryptographic key. The first C-RoT can generate the cryptographic key and wrap the cryptographic key using a wrapping key to generate a wrapped cryptographic key. The first C-RoT can output the wrapped cryptographic key and a second C-RoT of a second chiplet of the plurality of chiplets can receive the wrapped cryptographic key. The second C-RoT can unwrap the wrapped cryptographic key using the wrapping key and can perform an operation based on the cryptographic key.
    Type: Grant
    Filed: September 15, 2023
    Date of Patent: May 26, 2026
    Assignee: QUALCOMM Incorporated
    Inventors: Rengarajan Ragavan, Arun Menon, Samar Asbe, Aseem Brahma, Shivaprasad Hongal, Changjian Gao, Denis Pochuev
  • Patent number: 12640932
    Abstract: An end-to-end mechanism is disclosed herein for transporting encrypted messages over hypertext transport protocol (HTTP) sent to a group of recipients. In particular, the disclosed mechanism receives a message (e.g., as an input from a user) and encrypts that message using an encryption mechanism with a key unique to a particular user and to the message (e.g., different messages are encrypted using different keys). The encrypted message is then stored in a generated object along with other metadata needed for message processing. Once the object is generated, it is signed and encoded into a binary representation that is then sent to a server. The server system receives the binary representation and decodes it back into the object. The metadata of the object is then used to route the message to the correct recipient applications for decryption.
    Type: Grant
    Filed: July 7, 2025
    Date of Patent: May 26, 2026
    Assignee: Sentriqs, Inc.
    Inventors: Paul Dillon, Kyle Bebee, Damien Fortune, Robert Wilson
  • Patent number: 12627509
    Abstract: In a general aspect, a cryptography system includes a multiple-key pair root certificate authority. In some aspects, a plurality of distinct cryptographic pairs of public keys and private keys of a root certificate authority are generated. A plurality of distinct self-signed root certificates of the root certificate authority are generated. The plurality of distinct self-signed root certificates are each based on and correspond to a respective one of plurality of distinct cryptographic key pairs. A cryptographically authenticated database is generated that includes the plurality of distinct self-signed root certificates and represents the root certificate authority. The cryptographically authenticated database includes validity information of each of the plurality of self-signed root certificates. The cryptographically authenticated database is distributed to entities in a public key infrastructure.
    Type: Grant
    Filed: July 21, 2023
    Date of Patent: May 12, 2026
    Assignee: ISARA Corporation
    Inventor: Atsushi Yamada
  • Patent number: 12621268
    Abstract: Systems and methods include, receiving a request from a user to access an application; determining if the user meets one or more requirements, wherein responsive to the user meeting the one or more requirements, presenting the user with a login page; validating credentials of the user with one or more additional sources; responsive to successful validation of the users' credentials, authenticating the user and evaluating one or more access policies for the user; and initiating a connection between the user and the application based on the one or more access policies.
    Type: Grant
    Filed: January 27, 2023
    Date of Patent: May 5, 2026
    Assignee: Zscaler, Inc.
    Inventors: John A. Chanak, William Fehring, Richard Miles, Shujaat Jaffrey, Jose Padin, Matthew Moulton
  • Patent number: 12608485
    Abstract: Systems and methods for enhancing container security are provided. In one example, exposure of a containerize application to potential security vulnerabilities is reduced by identifying dynamically loaded symbols by the application via performance of static and/or dynamic symbol analysis to identify dynamically loaded symbols that are potentially and/or actually used, respectively, and that correspond to functions contained within shared libraries. Based on a shared library's usage of functions within a standard library and a known mapping between functions of the standard library and system calls, those system calls potentially and actually accessed by the application may be identified and a security policy may be generated and configured for enforcement by a kernel security module to limit system call usage accordingly. Additionally, removal of files or functions of libraries that are deemed unnecessary for proper execution of the applications may be performed to reduce the footprint of the application.
    Type: Grant
    Filed: December 14, 2023
    Date of Patent: April 21, 2026
    Assignee: NetApp, Inc.
    Inventor: Azzedine Benameur
  • Patent number: 12598234
    Abstract: The arrangements disclosed herein relate to systems, apparatus, methods, and non-transitory computer readable media for a network of plurality of roving cryptography devices. Each of the plurality of roving cryptography devices includes a locomotion system configured to move each of the plurality of roving cryptography devices to a respective one of a plurality of locations of the plurality of roving cryptography devices, a network interface circuit configured to provide wireless communication services to a user device of a plurality of user devices through a network of the plurality of roving cryptography devices, and a cryptography service system configured to provide cryptographic material to the user device. The plurality of roving cryptography devices at the plurality of locations form the network for providing the wireless communication services and the cryptographic materials to the plurality of user devices.
    Type: Grant
    Filed: December 1, 2023
    Date of Patent: April 7, 2026
    Assignee: Wells Fargo Bank, N.A.
    Inventors: Jeffrey J. Stapleton, Peter Bordow
  • Patent number: 12591675
    Abstract: A computer-implemented method of automatically securing a computer system or network against a suspect binary file (SBF) by, in response to detection of the SBF, initiating an automatic defence strategy comprising an action known to mitigate a known threat posed by a closest known malicious binary file (KMBF). The method further includes identifying the closest KMBF by comparing an SBF application programming interface (API) profile generated in respect of the SBF with respective KMBF API profiles generated in respect of each of a plurality of KMBFs, the SBF and KMBF API profiles being generated by: identifying any API calls in the respective binary file; and assigning each of said identified API calls to one of a plurality of API call categories defined by one or more actions known to be effective in mitigating one or more possible threats posed by the respective API call category.
    Type: Grant
    Filed: June 10, 2021
    Date of Patent: March 31, 2026
    Assignee: British Telecomunications Public Limited Company
    Inventor: Fadi El-Moussa
  • Patent number: 12587506
    Abstract: Techniques for preserving privacy while still allowing secure access to private resources. Among other things, the techniques may include receiving a request to provide a remote device with access to a private resource. In some instances, the request may be redirected to an identity provider service to authenticate the user of the remote device to maintain anonymity of an identity of the user. The techniques may also include receiving an indication of an entitlement-set provided by the identity provider service, the indication of the entitlement-set indicative of whether the user is entitled to access the resource without revealing the identity of the user. The techniques may also include at least one of authorizing the remote device to access the resource or refraining from authorizing the remote device to access the resource based at least in part on the indication of the entitlement-set.
    Type: Grant
    Filed: December 29, 2022
    Date of Patent: March 24, 2026
    Assignee: Cisco Technology, Inc.
    Inventor: Vincent E. Parla
  • Patent number: 12579271
    Abstract: The invention discloses a cross-architecture automated detection method and system for third-party components and security risks, comprising: identify and reverse the firmware of the IoT device, classify the resulting reverse products into binary and non-binary files; disassemble binary files to mine the semantic information in them; convert non-binary files into string text files; build a database containing third-party components and their known CVE; combine pattern matching to scan string text files automatically, collect third-party components in the firmware of IoT device, and collect and retrieve vulnerabilities of corresponding third-party components. Through organically combining the semantic information of the vulnerability assembly code and the semantic information of the firmware assembly code of IoT device, the similarity comparison across architectures and deep learning is realized, and the specific pattern vulnerability is mined and verified automatically.
    Type: Grant
    Filed: November 21, 2022
    Date of Patent: March 17, 2026
    Assignee: HANGZHOU EVERGREEN INFORMATION TECHNOLOGY CO., LTD.
    Inventors: Meng Han, Changting Lin, Peng Duan, Melody Xiaoyun Shan, Lei Zhang, Qiang Gong, Binbin Zhao, Haitao Xu, Jiacheng Xu, Bin Wang, Weiping Yu
  • Patent number: 12580747
    Abstract: A communication system according to an embodiment includes an edge device generating edge data and a service device making use of the edge data. The edge device generates a message authentication code by using a shared key shared with the service device. The edge device transmits first communication data representing communication data in which the message authentication code is assigned to the edge data. The service device verifies source of generation of the edge data included in the first communication data. The verification is performed in accordance with verification result of verifying the message authentication code included in the first communication data by using a shared key shared with the edge device.
    Type: Grant
    Filed: February 27, 2023
    Date of Patent: March 17, 2026
    Assignee: Kabushiki Kaisha Toshiba
    Inventors: Yasuyuki Tanaka, Mitsuru Kanda
  • Patent number: 12580775
    Abstract: Connection authorization from a communication device (CD) to an application server (AS) uses an electronic device (ED) to provide a first dataset to a security server (SS) in response to a first request, the first dataset related to a certificate of the ED. The ED retrieves an intermediary certificate generated by the SS based on the first dataset and signed by the SS. When the ED is connected to a CD intended to be introduced in a secured network, the ED receives a second request from the CD including a second dataset related to a certificate of the CD. The ED then generates a third dataset related to a signature of certificate of the CD and to the intermediary certificate. The ED thereafter sends the third dataset to the CD to obtain authorization to access to the secure network from the AS by using the third dataset.
    Type: Grant
    Filed: June 16, 2023
    Date of Patent: March 17, 2026
    Assignee: Schneider Electric Industries SAS
    Inventors: Ramses Alexander Escobar Ariza, Matthieu Adam