Patents Examined by Bryan F Wright
-
Patent number: 12689613Abstract: Systems and methods for privileged remote access to Operational Technology (OT)/Internet of Things (IOT)/Industrial IOT (IIOT)/Industrial Control System (ICS) infrastructure, implemented in a cloud-based system. The method includes steps of, responsive to determining a user can access an application associated with the OT/IOT/IIOT/ICS infrastructure, determining the users security and access policies and creating a session for the user; establishing a secure connection to the application via a lightweight connector connected to the application; and brokering a connection between the users device and the application through the lightweight connector, enabling the user to interact with the application for the OT/IOT/IIOT/ICS infrastructure, based on the user's security and access policies.Type: GrantFiled: July 13, 2022Date of Patent: July 21, 2026Assignee: Zscaler, Inc.Inventors: Clifford Kahn, William Fehring, Maneesh Sahu, Deepak Patel, Sunil Menon, Dejan Mihajlovic
-
Patent number: 12688301Abstract: Aspects of the present disclosure enable a system to perform automated risk analysis of source code of applications. The system may include a machine learning model to analyze the source code. The machine learning model may output an application risk value. Further, the application risk value may be used to determine a remedial action. The remedial action may address a risk associated with the application risk value, or allow for publication of the application.Type: GrantFiled: December 15, 2023Date of Patent: July 21, 2026Assignee: Amazon Technologies, Inc.Inventors: Brendan Cruz Colon, Matthew Michael Sommer, Consuelo Manas Pilot, Dustin Michael Ingalls, Adam Edward Powers
-
Patent number: 12665918Abstract: Systems and methods include, responsive to security research identifying a zero-day Common Vulnerabilities and Exposure (CVE), receiving the associated signatures of the zero-day CVE, responsive to determining a user can access an application via a cloud-based system, obtaining an inspection profile for the user with the inspection profile including a plurality of rules, performing inspection of transactions after the access using the plurality of rules and responsive to results of any of the plurality of rules, performing an action to the access via the cloud-based system.Type: GrantFiled: June 20, 2022Date of Patent: June 23, 2026Assignee: Zscaler, Inc.Inventors: Pooja Deshmukh, Amit Banker, Kanti Varanasi, John A. Chanak, William Fehring, Nishant Gupta
-
Patent number: 12648451Abstract: A method includes generating pattern data including common chip design data and one or more bit spaces or place holders reserved for non-common chip design data or information related to the non-common chip design data. The method includes introducing the non-common chip design data or information related to the non-common chip design data into the one or more bit spaces or place holders of the pattern data before streaming the pattern data to the maskless pattern writer. The common chip design data defines a common design layout part of an electronic device to be created on a wafer using the maskless pattern writer. The non-common chip design data defines a non-common design layout part of the electronic device to be created on the wafer using the maskless pattern writer, the non-common design layout part being different from other electronic devices created on the wafer.Type: GrantFiled: May 16, 2023Date of Patent: June 2, 2026Assignee: ASML Netherlands B.V.Inventors: Johannes Cornelis Jacobus De Langen, Marcel Nicolaas Jacobus van Kervinck, Vincent Sylvester Kuiper
-
Patent number: 12640913Abstract: Systems and techniques are provided for establishing a connection. For instance, a first chiplet root of trust (C-RoT) of a first chiplet of a plurality of chiplets can receive a request for a cryptographic key. The first C-RoT can generate the cryptographic key and wrap the cryptographic key using a wrapping key to generate a wrapped cryptographic key. The first C-RoT can output the wrapped cryptographic key and a second C-RoT of a second chiplet of the plurality of chiplets can receive the wrapped cryptographic key. The second C-RoT can unwrap the wrapped cryptographic key using the wrapping key and can perform an operation based on the cryptographic key.Type: GrantFiled: September 15, 2023Date of Patent: May 26, 2026Assignee: QUALCOMM IncorporatedInventors: Rengarajan Ragavan, Arun Menon, Samar Asbe, Aseem Brahma, Shivaprasad Hongal, Changjian Gao, Denis Pochuev
-
Patent number: 12640932Abstract: An end-to-end mechanism is disclosed herein for transporting encrypted messages over hypertext transport protocol (HTTP) sent to a group of recipients. In particular, the disclosed mechanism receives a message (e.g., as an input from a user) and encrypts that message using an encryption mechanism with a key unique to a particular user and to the message (e.g., different messages are encrypted using different keys). The encrypted message is then stored in a generated object along with other metadata needed for message processing. Once the object is generated, it is signed and encoded into a binary representation that is then sent to a server. The server system receives the binary representation and decodes it back into the object. The metadata of the object is then used to route the message to the correct recipient applications for decryption.Type: GrantFiled: July 7, 2025Date of Patent: May 26, 2026Assignee: Sentriqs, Inc.Inventors: Paul Dillon, Kyle Bebee, Damien Fortune, Robert Wilson
-
Cryptographically authenticated database representing a multiple-key-pair root certificate authority
Patent number: 12627509Abstract: In a general aspect, a cryptography system includes a multiple-key pair root certificate authority. In some aspects, a plurality of distinct cryptographic pairs of public keys and private keys of a root certificate authority are generated. A plurality of distinct self-signed root certificates of the root certificate authority are generated. The plurality of distinct self-signed root certificates are each based on and correspond to a respective one of plurality of distinct cryptographic key pairs. A cryptographically authenticated database is generated that includes the plurality of distinct self-signed root certificates and represents the root certificate authority. The cryptographically authenticated database includes validity information of each of the plurality of self-signed root certificates. The cryptographically authenticated database is distributed to entities in a public key infrastructure.Type: GrantFiled: July 21, 2023Date of Patent: May 12, 2026Assignee: ISARA CorporationInventor: Atsushi Yamada -
Patent number: 12621268Abstract: Systems and methods include, receiving a request from a user to access an application; determining if the user meets one or more requirements, wherein responsive to the user meeting the one or more requirements, presenting the user with a login page; validating credentials of the user with one or more additional sources; responsive to successful validation of the users' credentials, authenticating the user and evaluating one or more access policies for the user; and initiating a connection between the user and the application based on the one or more access policies.Type: GrantFiled: January 27, 2023Date of Patent: May 5, 2026Assignee: Zscaler, Inc.Inventors: John A. Chanak, William Fehring, Richard Miles, Shujaat Jaffrey, Jose Padin, Matthew Moulton
-
Patent number: 12608485Abstract: Systems and methods for enhancing container security are provided. In one example, exposure of a containerize application to potential security vulnerabilities is reduced by identifying dynamically loaded symbols by the application via performance of static and/or dynamic symbol analysis to identify dynamically loaded symbols that are potentially and/or actually used, respectively, and that correspond to functions contained within shared libraries. Based on a shared library's usage of functions within a standard library and a known mapping between functions of the standard library and system calls, those system calls potentially and actually accessed by the application may be identified and a security policy may be generated and configured for enforcement by a kernel security module to limit system call usage accordingly. Additionally, removal of files or functions of libraries that are deemed unnecessary for proper execution of the applications may be performed to reduce the footprint of the application.Type: GrantFiled: December 14, 2023Date of Patent: April 21, 2026Assignee: NetApp, Inc.Inventor: Azzedine Benameur
-
Patent number: 12598234Abstract: The arrangements disclosed herein relate to systems, apparatus, methods, and non-transitory computer readable media for a network of plurality of roving cryptography devices. Each of the plurality of roving cryptography devices includes a locomotion system configured to move each of the plurality of roving cryptography devices to a respective one of a plurality of locations of the plurality of roving cryptography devices, a network interface circuit configured to provide wireless communication services to a user device of a plurality of user devices through a network of the plurality of roving cryptography devices, and a cryptography service system configured to provide cryptographic material to the user device. The plurality of roving cryptography devices at the plurality of locations form the network for providing the wireless communication services and the cryptographic materials to the plurality of user devices.Type: GrantFiled: December 1, 2023Date of Patent: April 7, 2026Assignee: Wells Fargo Bank, N.A.Inventors: Jeffrey J. Stapleton, Peter Bordow
-
Patent number: 12591675Abstract: A computer-implemented method of automatically securing a computer system or network against a suspect binary file (SBF) by, in response to detection of the SBF, initiating an automatic defence strategy comprising an action known to mitigate a known threat posed by a closest known malicious binary file (KMBF). The method further includes identifying the closest KMBF by comparing an SBF application programming interface (API) profile generated in respect of the SBF with respective KMBF API profiles generated in respect of each of a plurality of KMBFs, the SBF and KMBF API profiles being generated by: identifying any API calls in the respective binary file; and assigning each of said identified API calls to one of a plurality of API call categories defined by one or more actions known to be effective in mitigating one or more possible threats posed by the respective API call category.Type: GrantFiled: June 10, 2021Date of Patent: March 31, 2026Assignee: British Telecomunications Public Limited CompanyInventor: Fadi El-Moussa
-
Patent number: 12587506Abstract: Techniques for preserving privacy while still allowing secure access to private resources. Among other things, the techniques may include receiving a request to provide a remote device with access to a private resource. In some instances, the request may be redirected to an identity provider service to authenticate the user of the remote device to maintain anonymity of an identity of the user. The techniques may also include receiving an indication of an entitlement-set provided by the identity provider service, the indication of the entitlement-set indicative of whether the user is entitled to access the resource without revealing the identity of the user. The techniques may also include at least one of authorizing the remote device to access the resource or refraining from authorizing the remote device to access the resource based at least in part on the indication of the entitlement-set.Type: GrantFiled: December 29, 2022Date of Patent: March 24, 2026Assignee: Cisco Technology, Inc.Inventor: Vincent E. Parla
-
Patent number: 12580747Abstract: A communication system according to an embodiment includes an edge device generating edge data and a service device making use of the edge data. The edge device generates a message authentication code by using a shared key shared with the service device. The edge device transmits first communication data representing communication data in which the message authentication code is assigned to the edge data. The service device verifies source of generation of the edge data included in the first communication data. The verification is performed in accordance with verification result of verifying the message authentication code included in the first communication data by using a shared key shared with the edge device.Type: GrantFiled: February 27, 2023Date of Patent: March 17, 2026Assignee: Kabushiki Kaisha ToshibaInventors: Yasuyuki Tanaka, Mitsuru Kanda
-
Patent number: 12579271Abstract: The invention discloses a cross-architecture automated detection method and system for third-party components and security risks, comprising: identify and reverse the firmware of the IoT device, classify the resulting reverse products into binary and non-binary files; disassemble binary files to mine the semantic information in them; convert non-binary files into string text files; build a database containing third-party components and their known CVE; combine pattern matching to scan string text files automatically, collect third-party components in the firmware of IoT device, and collect and retrieve vulnerabilities of corresponding third-party components. Through organically combining the semantic information of the vulnerability assembly code and the semantic information of the firmware assembly code of IoT device, the similarity comparison across architectures and deep learning is realized, and the specific pattern vulnerability is mined and verified automatically.Type: GrantFiled: November 21, 2022Date of Patent: March 17, 2026Assignee: HANGZHOU EVERGREEN INFORMATION TECHNOLOGY CO., LTD.Inventors: Meng Han, Changting Lin, Peng Duan, Melody Xiaoyun Shan, Lei Zhang, Qiang Gong, Binbin Zhao, Haitao Xu, Jiacheng Xu, Bin Wang, Weiping Yu
-
Patent number: 12580775Abstract: Connection authorization from a communication device (CD) to an application server (AS) uses an electronic device (ED) to provide a first dataset to a security server (SS) in response to a first request, the first dataset related to a certificate of the ED. The ED retrieves an intermediary certificate generated by the SS based on the first dataset and signed by the SS. When the ED is connected to a CD intended to be introduced in a secured network, the ED receives a second request from the CD including a second dataset related to a certificate of the CD. The ED then generates a third dataset related to a signature of certificate of the CD and to the intermediary certificate. The ED thereafter sends the third dataset to the CD to obtain authorization to access to the secure network from the AS by using the third dataset.Type: GrantFiled: June 16, 2023Date of Patent: March 17, 2026Assignee: Schneider Electric Industries SASInventors: Ramses Alexander Escobar Ariza, Matthieu Adam
-
Patent number: 12574396Abstract: A method for transmitting a report to a vehicle (10) comprises the following steps: —detecting, by a station (22), an anomaly relating to the vehicle; —transmitting to the vehicle (10) a report relating to the detected anomaly.Type: GrantFiled: June 18, 2018Date of Patent: March 10, 2026Assignee: VALEO COMFORT AND DRIVING ASSISTANCEInventor: Richard Denis
-
Patent number: 12568094Abstract: A method and a computing device for identifying, in a network infrastructure, network devices compromised by DNS tunneling are provided. The method comprises: receiving a portion of traffic of the network infrastructure; identifying, from the traffic, a plurality of DNS queries having been generated by network devices of the network infrastructure; generating, by the processor, for a given one of the plurality of DNS queries, a respective set of feature; applying, by the processor, to the respective set of features, a pre-trained decision rule; in response to the pre-trained decision rule rendering a positive outcome, increasing a penalty score for a respective network device of the network infrastructure having transmitted the given one of the plurality of DNS queries; and in response to the penalty score associated with the respective network device exceeding a predetermined penalty score threshold, identifying the respective network device as being compromised.Type: GrantFiled: July 14, 2022Date of Patent: March 3, 2026Assignee: GROUP-IB GLOBAL PRIVATE LIMITEDInventor: Anton Victorovich Afonin
-
Patent number: 12542759Abstract: A method comprises; receiving original electronic information from a lesser trusted network in a first electrical zone; permitting electronic information to be transferred between the first electrical zone and the second electrical zone in one direction only; verifying the original electronic information for at least one predetermined characteristic within the second electrical zone so as to provide a verifier output status and verified electronic information; forwarding the verified electronic information to a third electrical zone. The original electronic information at the first electrical zone is received by the third electrical zone via the second electrical zone as verified electronic information in either a transformed state or an untransformed state. The transformed state or the untransformed state is selected dependent upon the verifier output status. The method further comprising creating an electronic key and providing the verified electronic information in dependence upon the electronic key.Type: GrantFiled: September 14, 2019Date of Patent: February 3, 2026Assignee: The Secretary of State for Foreign and Commonwealth AffairsInventors: Robert John Dale, John Alan Thorp
-
Patent number: 12542681Abstract: An end-to-end mechanism is disclosed herein for transporting encrypted messages over hypertext transport protocol (HTTP) sent to a group of recipients. In particular, the disclosed mechanism receives a message (e.g., as an input from a user) and encrypts that message using an encryption mechanism with a key unique to a particular user and to the message (e.g., different messages are encrypted using different keys). The encrypted message is then stored in a generated object along with other metadata needed for message processing. Once the object is generated, it is signed and encoded into a binary representation that is then sent to a server. The server system receives the binary representation and decodes it back into the object. The metadata of the object is then used to route the message to the correct recipient applications for decryption.Type: GrantFiled: July 7, 2025Date of Patent: February 3, 2026Assignee: Sentriqs, Inc.Inventors: Paul Dillon, Kyle Bebee, Damien Fortune, Robert Wilson
-
Patent number: 12542763Abstract: Techniques are disclosed for establishing a distributed virtual private network within a virtual bootstrap environment. A distributed computing system can generate a virtual cloud network in a data center of a host region. The virtual cloud network can include a plurality of host instances, including an instance hosting a virtual private network router. A second instance can provide a secondary network address to the virtual private network router. A third instance can send a request addressed to the secondary network address. The virtual cloud network may route the request to the virtual private network router according to a default route of a routing table. The request may then be forwarded by the virtual private network router to the secondary address using a networking tunnel established between the first instance and the second instance.Type: GrantFiled: February 3, 2023Date of Patent: February 3, 2026Assignee: Oracle International CorporationInventor: Michel Belleau