Patents Examined by Eric W Shepperd
  • Patent number: 12732379
    Abstract: A method is provided for temporarily enabling functionality of a secure device. The method includes storing public keys for respective trusted devices of at least one trusted device, storing device-unique data that is unique for the secure device, generating a unique hashed-based message authentication code (HMAC) key, computing, based on the HMAC key and the device-unique data, a unique HMAC, transmitting the HMAC to a trusted device of the at least one trusted device, receiving a signed HMAC from the trusted device, wherein the signed HMAC is the HMAC as signed by the trusted device using a private key of the trusted device, decrypting the signed HMAC using the public key for the trusted device, comparing the decrypted signed HMAC to the HMAC, and enabling functionality of the secure device based on a result of the comparison.
    Type: Grant
    Filed: January 11, 2024
    Date of Patent: September 8, 2026
    Assignee: Schneider Electric USA, Inc.
    Inventors: Kevin M. Jefferies, Gregory Harrison, Yvain Achino
  • Patent number: 12732535
    Abstract: Computer systems and methods are provided for storing a first path profile. A computing device receives a first request to access a first location of a website, transmits the first request to a server, and receives a first cookie that includes identifying information for the first location. In response to receiving the first cookie, the device stores the identifying information. The device receives a second request to access a second location of the website that is distinct from the first location. The second request includes the identifying information for the first location. The device transmits the second request to the server and receives a second cookie that includes the identifying information for the first location and for the second location. In response to receiving the second cookie, the device stores the first path profile that includes the identifying information for the first location and the second location.
    Type: Grant
    Filed: November 27, 2023
    Date of Patent: September 8, 2026
    Assignee: Palo Alto Networks, Inc.
    Inventors: Subramanian Varadarajan, Rosarin Jolly Roy Antonyraj, Kumaravel Senthivel
  • Patent number: 12726478
    Abstract: A method for access control to a wireless local area communication network, including a gateway for accessing the local area network and a plurality of user terminals capable of being connected to the local area network via the access gateway. The access control of one of the user terminals to the network includes: authenticating the user terminal on the basis of an item of information derived from a biometric print of a user of the user terminal, and applying, to the user terminal, a network access profile personalized for the user to whom the biometric print belongs.
    Type: Grant
    Filed: February 21, 2022
    Date of Patent: September 1, 2026
    Assignee: Orange
    Inventors: Xavier Le Guillou, Coralie Bonnet
  • Patent number: 12706937
    Abstract: An information processing apparatus includes processing circuitry configured to acquire a security log including information regarding unauthorized communication stored in an upper network device being a device constituting an overlay network, an authentication log stored in a cloud server, and a communication log stored in a lower network device being a device constituting an underlay network, specify information such that, when the authentication log includes a connection source IP address that does not exist in the communication log acquired and the security log includes information regarding an access not permitted to be used from the connection source IP address, the processing circuitry specifies the information regarding the access as unauthorized communication, and give an instruction to block the unauthorized communication specified.
    Type: Grant
    Filed: October 16, 2024
    Date of Patent: August 11, 2026
    Assignee: NTT DOCOMO BUSINESS, INC.
    Inventors: Takeshi Takatsu, Mitsuhiro Hatada
  • Patent number: 12701113
    Abstract: A method and system for mitigating a threat associated with network data packets are provided. The method commences with receiving, by an authentication server, a request for access to a server from a client. The method further includes authenticating the client by the authentication server. The authentication includes providing an authentication token to the client. The method continues with receiving, by a mitigation device, from the client, at least one network packet directed to the server. The at least one network packet embeds the authentication token. The method further includes validating, by the mitigation device, authenticity of the authentication token and selectively forwarding, based on the validation, the at least one network packet to the server. The authentication token is independently generated by the authentication server and the mitigation device, and is unique for each packet.
    Type: Grant
    Filed: November 7, 2023
    Date of Patent: August 4, 2026
    Assignee: A10 Networks, Inc.
    Inventor: Yutun (Tony) Tseng
  • Patent number: 12695609
    Abstract: The implementations provide a method including: encrypting records on one or more computing devices using a key of the one or more computing devices to generate a first set of encrypted records; preparing a matrix indicating that each of the first set of encrypted records is present on the one or more computing devices; responsive to receiving, from a remote device, a second set of encrypted records encrypted by the second device using a key of the remote device, encrypting the second set of encrypted records using the key of the one or more computing devices; and transmitting the second set of doubly encrypted records, along with the matrix, to the remote device for the remote device to determine, using the matrix, whether at least one of the second set of encrypted records of the second device is included in the first set of encrypted records on the first device.
    Type: Grant
    Filed: May 29, 2024
    Date of Patent: July 28, 2026
    Assignees: Lemon Inc., Beijing Zitiao Network Technology Co., Ltd.
    Inventors: Yongchuan Niu, Chuyuan Chen, Shengjun Zhong, Yonghao Yi, Brendon Lim Chee How, Li Wang, Qiang Yan
  • Patent number: 12682068
    Abstract: Methods and systems for securely deploying an artificial intelligence (AI) model. The system can identify one or more deficiencies of the AI model, and protect the AI model from being attacked by external data based upon the identifying. The system can be used for fraud detection based on tabular data, voice authentication, facial recognition, object detection, or a combination thereof.
    Type: Grant
    Filed: February 25, 2022
    Date of Patent: July 14, 2026
    Assignee: Robust Intelligence LLC
    Inventors: Harrison Chase, Kojin Oshiba, Yaron Singer
  • Patent number: 12683972
    Abstract: A trust store management system for a network communication ecosystem is provided. The system is programmed to a) receive a DNSSEC entry address of a DNSSEC entry stored at a DNSSEC server; b) transmit a request to a DNSSEC server to access information stored in the DNSSEC entry associated with the DNSSEC entry address; c) receive, from the DNSSEC server, the information stored in the DNSSEC entry; d) receive a trust store; and e) validate the trust store based on the information stored in the DNSSEC entry.
    Type: Grant
    Filed: November 25, 2024
    Date of Patent: July 14, 2026
    Assignee: Cable Television Laboratories, Inc.
    Inventor: Massimiliano Pala
  • Patent number: 12676754
    Abstract: A system for performing a multi-party computation (MPC) operation may include an MPC node executed in a secure enclave. The MPC node includes executable instructions injected into the secure enclave to create an execution environment. The secure enclave performs an attestation check on the execution environment, generates a result of the attestation check, and cause the secure enclave to create a cryptographic signature on the result of the attestation check. The system may also include an attestation node in communication with the secure enclave. The attestation node verifies the cryptographic signature on the result of the attestation check and cause a decryption of an encrypted private cryptographic key shard to generate a decrypted private cryptographic key shard. The decrypted cryptographic key shard is used by the MPC node to perform part of the MPC operation.
    Type: Grant
    Filed: August 10, 2023
    Date of Patent: July 7, 2026
    Assignee: Blockdaemon Inc.
    Inventors: Vincent Kobel, Alexandre Karlov, Kevin Truckenmiller, Jakob Pagter
  • Patent number: 12666262
    Abstract: A device, system and method for providing services between a communication device and an application server is provided. A trust session is established between a gateway device and an application server. The gateway device provides, to the application server, on behalf of a communication device served by the gateway device: a service request that requests a service from the application server; an indication of successful authentication of the gateway device by the application server, the indication associated with the trust session; and a payload including an indicator of the communication device. The gateway device receives, from the application server, a verification of the service request determined using at least the indication associated with the trust session. The service is provided between the communication device and the application server via one or more of the gateway device and a network.
    Type: Grant
    Filed: April 11, 2024
    Date of Patent: June 23, 2026
    Assignee: MOTOROLA SOLUTIONS, INC.
    Inventors: Madhusudan K. Pai, Harisha M. Negalaguli, Debabrata Dash
  • Patent number: 12659171
    Abstract: A method may include obtaining a manifest file that includes various software definitions for various peripheral device functions. The method may further include determining whether the manifest file is signed by a predetermined cryptographic key. The method may further include obtaining, in response to determining that the manifest file is signed by the predetermined cryptographic key, a selection of a peripheral device function among the peripheral device functions in the manifest file. The method may further include performing the peripheral device function using a peripheral device in response to obtaining the selection of the peripheral device function.
    Type: Grant
    Filed: April 3, 2024
    Date of Patent: June 16, 2026
    Assignee: Lenovo (Singapore) Pte. Ltd.
    Inventors: Nozomi Mandokoro, Alfredo Zugasti
  • Patent number: 12652175
    Abstract: A computer-implemented method, according to one approach, includes: generating lookup tables for signatures during compile time, the lookup tables having cryptographic information. A secret key is used to encrypt the lookup tables, and the secret key is stored in a secure storage which is accessible only to a secure engine. Moreover, in response to experiencing an initial boot: the lookup tables are decrypted using the secret key, and the decrypted lookup tables are stored in the secure storage. Other systems, methods, and computer program products are described in additional approaches.
    Type: Grant
    Filed: April 30, 2024
    Date of Patent: June 9, 2026
    Assignee: International Business Machines Corporation
    Inventors: Akhilesh S, Rajat Rao, Sandeep Korrapati
  • Patent number: 12647402
    Abstract: The techniques herein are directed generally to a “zero-knowledge” data management network. Users are able to share verifiable proof of data and/or identity information, and businesses are able to request, consume, and act on the data—all without a data storage server or those businesses ever seeing or having access to the raw sensitive information (where server-stored data is viewable only by the intended recipients, which may even be selected after storage). In one embodiment, source data is encrypted with a source encryption key (e.g., source public key), with a rekeying key being an encrypting combination of a source decryption key (e.g., source private key) and a recipient's public key. Without being able to decrypt the data, the storage server can use the rekeying key to re-encrypt the source data with the recipient's public key, to then be decrypted only by the corresponding recipient using its private key, accordingly.
    Type: Grant
    Filed: May 20, 2022
    Date of Patent: June 2, 2026
    Assignee: Journey.ai
    Inventors: Brett Shockley, Alexander John Shockley, Michael Joseph Frendo, Shmuel Shaffer, Kenneth Keiter, James M. Behmke
  • Patent number: 12645778
    Abstract: The present disclosure generally relates to methods and user interfaces for authentication, including providing and controlling authentication at a computer system using an external device in accordance with some embodiments.
    Type: Grant
    Filed: September 3, 2024
    Date of Patent: June 2, 2026
    Assignee: Apple Inc.
    Inventor: Grant R. Paul
  • Patent number: 12621163
    Abstract: A method for controlling access to a resource in an electronic device including a secure element with a permanent memory having an OTP area. The method includes the following steps performed first when the secure element or the electronic device boots: checking presence of at least one of a secret data and an initialization value in the permanent memory and, in a negative event, generating an initialization value and storing it into the OTP area, in a positive event, if the permanent memory includes secret data, decrypting, within the secure element, the secret data by using an algorithm using a cryptographic key and, if the permanent memory further includes an initialization value, the initialization value, and checking the integrity of the secret data by using a signature stored in the permanent memory and, on successful completion, providing access to the resource.
    Type: Grant
    Filed: December 16, 2021
    Date of Patent: May 5, 2026
    Assignee: NAGRAVISION SARL
    Inventors: Luis Ruiz, Didier Hunacek
  • Patent number: 12603911
    Abstract: A system is provided for intelligent automated simulation of penetration testing and isolation of vulnerable distributed electronic data registers. In particular, the system may extract metadata regarding one or more nodes or sections of a distributed register. Based on the metadata, the system may generate a knowledge graph that may indicate the vulnerabilities associated with particular nodes, blocks, and/or sections of the distributed register. Based on the knowledge graph, the system may compute vulnerability scores for the various nodes, blocks, and/or sections, and generate a vulnerability heatmap based on the scores. The system may further be configured to allow a user to perform automatic simulated penetration tests on the vulnerable portions of the distributed register and/or execute one or more remediation process on such vulnerable portions. In this way, the system provides an efficient way to identify and remediate vulnerabilities within a distributed register.
    Type: Grant
    Filed: August 25, 2023
    Date of Patent: April 14, 2026
    Assignee: BANK OF AMERICA CORPORATION
    Inventors: Shailendra Singh, Krishna Rangarao Mamadapur
  • Patent number: 12604191
    Abstract: Methods, systems, and apparatuses are described for identifying unauthorized (e.g., rogue) access points. Authorized access points can detect the presence of rogue access points by determining signal strengths associated with other access points. A detected variance from an expected signal strength can indicate a presence of a rogue access point.
    Type: Grant
    Filed: December 21, 2020
    Date of Patent: April 14, 2026
    Assignee: Comcast Cable Communications, LLC
    Inventors: Ryan Van Antwerp, James Bradley Hein
  • Patent number: 12592831
    Abstract: Techniques are provided for email protection using email signatures based on signing tokens. One method comprises obtaining a signed email from an email sender. The signed email comprises a second hash value generated using a source version of the signed email embedded with a signing token of the email sender. A data record stores a first hash value, based on the source version, and the second hash value. The second hash value is obtained from the signed email and compared to: (i) a copy of the second hash value obtained from the data record and/or (ii) a comparison value generated using a regenerated version of the source version embedded with the signing token of the email sender. A delivery of the signed email to an email recipient may be based on a result of the comparison.
    Type: Grant
    Filed: January 26, 2024
    Date of Patent: March 31, 2026
    Assignee: Dell Products L.P.
    Inventors: Rajiv Popat, Manav Ghosh
  • Patent number: 12591644
    Abstract: Systems and methods provide a password reset for a management controller, which is not exposed to the Internet. Upon receiving a request to reset the password, the management controller generates computer-readable information such as a barcode, where the computer-readable information indicates attributes of an information handling system associated with the management controller as well as a timestamp. A user can transmit the computer-readable information to a vendor application service via for example a mobile device that reads the computer-readable information. The vendor application service verifies the request and generates a temporary password from the timestamp and the attributes. Independently of the vendor application service, the management controller also generates the temporary password from the timestamp in the attributes. The vendor application service may then cause the temporary password to be sent to verified contact information.
    Type: Grant
    Filed: September 22, 2023
    Date of Patent: March 31, 2026
    Assignee: Dell Products, L.P.
    Inventors: Harshendra Shetty, Shivendra Katiyar, Nikhil S
  • Patent number: 12587390
    Abstract: A method of operating a secure programming system is provided. The method can use the first authentication module as the root authentication module to authorize the second authentication module of the program burning system when the first authentication module fails to provide the private key. In this way, the second authentication module obtains the second certificate composed of the second digital signature and becomes the first relay authentication module authorized by the first authentication module to issue certificates on behalf of the first authentication module, so that the program burning system can perform burning operations and process operations. Therefore, the method of the present disclosure can not only achieve the purpose of signing the same certificate in a more secure manner, but also help the first authentication module to be more flexible in classifying the second authentication module according to different product application categories or methods.
    Type: Grant
    Filed: July 9, 2024
    Date of Patent: March 24, 2026
    Assignee: DEDIPROG TECHNOLOGY CO., LTD.
    Inventors: Ming-Hui Kang, Hui-Kai Huang