Patents Examined by John B King
  • Patent number: 12732530
    Abstract: An autonomous pentesting agent may execute an autonomous pentest of a network involving a password spraying operation and using a custom sequence of password candidates. The autonomous pentesting agent may execute an autonomous pentest of the network associated with multiple user accounts having access to respective network assets. The autonomous pentesting agent may obtain the custom sequence of password candidates for the user accounts based on character pattern tokens and environmental factors of the network. Each character pattern token may be associated with a set of character strings having a defined statistical probability of inclusion in a password that includes the character pattern token. The autonomous pentesting agent may perform the password spraying operation during the autonomous pentest. The password spraying operation may involve successive attempts to compromise a password of user accounts in accordance with the custom sequence of password candidates.
    Type: Grant
    Filed: December 6, 2024
    Date of Patent: September 8, 2026
    Assignee: Horizon 3 AI, Inc.
    Inventors: Zachary Daniel Hanley, James Horseman, Anthony Pillitiere
  • Patent number: 12730916
    Abstract: Techniques are provided for data protection using policy-based digital vault rotation. One method comprises obtaining data to be stored; selecting one of multiple digital vaults; and storing the data in the selected digital vault, wherein a different one of the multiple digital vaults is selected using a rotation policy in response to rotation criteria being satisfied and wherein the data is moved to the selected different digital vault. The multiple digital vaults may comprise multiple digital vaults having different memory spaces on a given device and/or multiple digital vaults on different devices. The multiple digital vaults may only respond to a designated vault proxy service. An active digital vault may be identified using the rotation policy in response to a request for data and the data may be retrieved from the active digital vault and provided to a requester associated with the request.
    Type: Grant
    Filed: June 7, 2023
    Date of Patent: September 8, 2026
    Assignee: Dell Products L.P.
    Inventors: Roman Bober, Maxim Balin, Stav Sapir
  • Patent number: 12730922
    Abstract: The present disclosure provides a database container configured to contain multiple data sources. A first command is received to add a new data source to the database container. In response, the new data source is created within the database container, where the database container acts as a parent such that the new data source inherits properties of the database container including a first set of access permissions. Display of the new data source is caused via the database container. The system receives a second command to link an existing data source residing outside the database container to the database container. In response, a view of the existing data source is created within the database container without containing the existing data source, causing the existing data source to retain a second set of access permissions different from the first set of access permissions.
    Type: Grant
    Filed: January 7, 2026
    Date of Patent: September 8, 2026
    Assignee: Notion Labs, Inc.
    Inventors: Marina Schimidinger Camim, Ken Chen, James Wills, Atul Varma, Michelle Lim, Emily Hong, Ron Offer Yehoshua
  • Patent number: 12726523
    Abstract: In some embodiments, a system/process/computer program product for flow metadata exchanges between network and security functions for a security service includes receiving a flow at a software-defined wide area network (SD-WAN) device; analyzing the flow to determine whether the flow is associated with a split tunnel, comprising: extracting meta data information associated with one flow of the flow to determine the meta data information, wherein the meta data information includes one or more of the following: a user identifier, an application identifier, and/or a device identifier; comparing the extracted meta data information with meta data information associated with a predetermined set of users, applications, and devices; and in the event that the extracted meta data information matches the meta data information associated with one or more of the predetermined set of users, applications, and devices, then determining that the one flow is associated with the split tunnel; and monitoring the flow at the SD-W
    Type: Grant
    Filed: February 13, 2025
    Date of Patent: September 1, 2026
    Assignee: Palo Alto Networks, Inc.
    Inventors: Anand Oswal, Arivu Mani Ramasamy, Kumar Ramachandran
  • Patent number: 12719845
    Abstract: Methods and systems for providing computer implemented services are disclosed. To provide the services, requests for access to resources may be sent. Prior to servicing requests that are received, the requests may be evaluated using a distributed consensus analysis process. The distributed consensus analysis process may take into account views of multiple devices regarding whether the requests can be validated. Requests that are validated via the distributed consensus analysis process may be honored.
    Type: Grant
    Filed: October 29, 2024
    Date of Patent: August 25, 2026
    Assignee: Dell Products L.P.
    Inventors: Maxim Balin, Efi Levi, Lior Benisty
  • Patent number: 12719674
    Abstract: A method implemented in a computing system hosting a three-dimensional virtual reality world. The computer system stores a set of searchable records, each having: a searchable hash of at least a portion of personally identifiable information; and an encrypted identity, decryptable using an encryption key generated based at least in part on the searchable hash and a global key. In response to a search request identifying at least a portion of personally identifiable information as a search criterion, the computer system generates a hash of the search criterion, and finds a matching searchable record that has a searchable hash equal to the hash computed from the search criterion. An encryption key is computed based on the global key and the matched searchable record to decrypt an encrypted identity of a user having at least the portion of personally identifiable information that is the search criterion in the search request.
    Type: Grant
    Filed: January 31, 2023
    Date of Patent: August 25, 2026
    Assignee: Thunes Financial Services LLC
    Inventors: Nicolas J. Scheiblauer, Aaron Torres, Christopher Allen Nowell
  • Patent number: 12719870
    Abstract: A computing machine stores supervised computing resources and private computing resources. The computing machine facilitates tracking, by a supervision service, of activity of the computing machine with respect to a supervised computing resource of the supervised resources that is executing on the computing machine. The computing machine supports user privacy, by the supervision service, with respect to a private computing resource of the private computing resources that is executing on the computing machine.
    Type: Grant
    Filed: February 14, 2024
    Date of Patent: August 25, 2026
    Assignee: Venn Technology Corporation
    Inventors: Aleksandr Osipov, David Matalon
  • Patent number: 12719663
    Abstract: There is provided a computer-implemented method for establishing a communication channel for exchanging messages securely between an initiator device and an endpoint device using an intermediary server. The initiator device is in communication with the intermediary server via a first session encrypted according to a cryptographic protocol. The endpoint device is in communication with the intermediary server via a second session encrypted according to a cryptographic protocol. A request for a handover token via the first session is sent to intermediary server. The handover token includes data that has been generated at the endpoint device and is configured to be used in setting up the communication channel between the initiator device and the endpoint device. The handover token is received from the intermediary server via the first session encrypted according to a cryptographic protocol. The communication channel is established between the initiator device and the endpoint device.
    Type: Grant
    Filed: April 25, 2022
    Date of Patent: August 25, 2026
    Assignee: Mastercard International Incorporated
    Inventors: Cédric Colnot, Jean-Bernard Collet, Duncan Garrett
  • Patent number: 12712737
    Abstract: A system for securely transmitting data between two devices is disclosed. Each device comprises an interface, an encryption module, a decryption module and a message authentication code (MAC) generator. The encryption and decryption modules may utilize a stream cipher, while the MAC generator utilizes a hashing algorithm. A MAC is transmitted after a predetermined amount of time, regardless of the amount of activity on the interface. The device receiving the MAC compares it to the MAC that it generated to ensure that they match. This guarantees that a breach of integrity can be detected in a reasonable amount of time and addressed accordingly. This system may utilize an interface having bidirectional data signals or unidirectional data signals.
    Type: Grant
    Filed: March 14, 2022
    Date of Patent: August 18, 2026
    Assignee: Silicon Laboratories Inc.
    Inventor: Joshua J. Norem
  • Patent number: 12711391
    Abstract: There is provided a computer-implemented method of reinforcement learning for training a machine learning model configured to provision and/or deprovision virtual application instances of an application in a distributed compute network having one or more compute nodes, the method being performed by at least one hardware processor and the method comprising: a) defining an action space for a training environment representative of the distributed compute network, the training environment having a plurality of states and, for each state, one or more available actions in the action space, each action being operable to transition the distributed compute network in the training environment from a current state to a new state; b) selecting one or more available actions in the action space to define a new state; c) determining a reward for the one or more selected actions based upon a predicted change in load characteristics for the distributed compute network in the training environment in moving from the current sta
    Type: Grant
    Filed: September 1, 2023
    Date of Patent: August 18, 2026
    Assignee: BunnyWay Informacijske storitve d.o.o
    Inventors: Anton Zvonko Gazvoda, Nikiforos Pittaras
  • Patent number: 12705188
    Abstract: A method for extending a memory isolation domain includes allocating memories of multiple isolation domains, where the multiple isolation domains are in a correspondence with N protection keys and M extended page tables. When a first application is allowed to access a memory of a first isolation domain, the method further includes determining, based on the correspondence, a first protection key and a first extended page table that correspond to the first isolation domain, where the multiple isolation domains include the first isolation domain, the N protection keys include the first protection key, and the M extended page tables include the first extended page table. The method further includes enabling access permission for the first isolation domain based on the first protection key and the first extended page table, for the first application to access the memory of the first isolation domain.
    Type: Grant
    Filed: January 8, 2025
    Date of Patent: August 11, 2026
    Assignee: HUAWEI TECHNOLOGIES CO., LTD.
    Inventors: Wentai Li, Jinyu Gu, Haibo Chen, Kang Sun
  • Patent number: 12699809
    Abstract: A data deidentification system that extracts insights from user data and retains both the insights and user data in a form that complies with applicable data privacy and related standards. The system receives user data, which can include personal identifying information and other sensitive data governed by one or more standards, including standards specifying how the data can be used and how long it can be retained. From the data, the system extracts insights characterizing various aspects of the associated users. The system also selectively hashes portions of the data, obscuring the identity of associated users. Neither the insights nor the selectively hashed data identify individual users, and therefore they are not subject to the same standards and can be retained indefinitely. Later, after the standards-protected data has been discarded, the system can provide insight information in response to a request.
    Type: Grant
    Filed: August 15, 2024
    Date of Patent: August 4, 2026
    Assignee: Telesign Corporation
    Inventors: Humberto Morales, Gordana Djankovic, Cynthia Ng
  • Patent number: 12700991
    Abstract: Methods and systems for data security are provided. The method includes generating respective tags for data segments in a dataset, deriving respective temporal keys associated with the respective tags for the plurality of data segments from a master key, and transforming the plurality of data segments from a plaintext to a ciphertext using the respective temporal keys as a first input and the respective tags as a second input, while format-preserving the data segments. The master key can be updated to prevent from reverse-transforming a selected data segment in the dataset from the ciphertext to the plaintext.
    Type: Grant
    Filed: October 31, 2023
    Date of Patent: August 4, 2026
    Assignee: Lemon Inc.
    Inventors: Yongjun Zhao, Wei Dai, Donghang Lu, Qiang Yan
  • Patent number: 12688330
    Abstract: A data deidentification system that extracts insights from user data and retains both the insights and user data in a form that complies with applicable data privacy and related standards. The system receives user data, which can include personal identifying information and other sensitive data governed by one or more standards, including standards specifying how the data can be used and how long it can be retained. From the data, the system extracts insights characterizing various aspects of the associated users. The system also selectively hashes portions of the data, obscuring the identity of associated users. Neither the insights nor the selectively hashed data identify individual users, and therefore they are not subject to the same standards and can be retained indefinitely. Later, after the standards-protected data has been discarded, the system can provide insight information in response to a request.
    Type: Grant
    Filed: August 14, 2024
    Date of Patent: July 21, 2026
    Assignee: Telesign Corporation
    Inventors: Humberto Morales, Gordana Djankovic, Cynthia Ng
  • Patent number: 12671577
    Abstract: A method for pairing a content provider system and a receiving device, a cryptographic function and a receiving device unique identifier being populated in the receiving device. According to such method, the receiving device executes: obtaining a first key which is a result of a first function taking as arguments an Identity Based Encryption scheme master key owned by an authority server and an output of the cryptographic function applied to the receiving device unique identifier; receiving, from the content provider system, a content provider unique identifier; and computing a secret key which is a result of a second function taking as operands the first key and an output of the cryptographic function applied to the content provider unique identifier, the secret key being known from the content provider system.
    Type: Grant
    Filed: May 1, 2024
    Date of Patent: June 30, 2026
    Assignee: NAGRAVISION SÀRL
    Inventors: Marco Macchetti, Didier Hunacek, Karine Villegas
  • Patent number: 12670010
    Abstract: A method and system for generating cluster level explanations for an input data having limited or special values are disclosed. The method includes obtaining an input data set and a clustering stopping criteria, the input data set including multiple features, and each of the features having multiple feature values; performing features decomposition on the input data; performing correlation analysis based on the features decomposition and a correlation threshold value; grouping the features having different feature values into multiple clusters; training a model based on the obtained input data; obtaining a target input data to be tested and a number of cores; grouping the number of cores into multiple clusters; and computing explanations at a cluster level.
    Type: Grant
    Filed: September 21, 2023
    Date of Patent: June 30, 2026
    Assignee: JPMORGAN CHASE BANK, N.A.
    Inventors: Emanuele Albini, Sanjay Kariyappa, Leonidas Tsepenekas, Mikhail Solonin, Freddy Lecue, Daniele Magazzeni
  • Patent number: 12665925
    Abstract: Method and system for detecting a Denial-of-Service (DoS) attack on a network. The method includes sampling a traffic carried by the network between data processing devices, the traffic comprising data packets transmitted between the data processing devices, determining statistically estimated features of the traffic based on the sampling thereof, executing one or more heuristic algorithm based on the statistically estimated features, the one or more heuristic algorithms being configured to generate a confidence score indicative of a probability that at least some of the data packets constitute a DoS attack and comparing the confidence score with a confidence threshold to determine whether a mitigation order is to be generated.
    Type: Grant
    Filed: August 23, 2024
    Date of Patent: June 23, 2026
    Assignee: OVH
    Inventors: Clement Boin, Gilles Grimaud, Xavier Guillaume, Michael Hauspie, Tristan Groleat
  • Patent number: 12659289
    Abstract: Provided is a method for providing a response to a user query for domain-related information of a domain. The method can include obtaining, at a client over a network, the user query for the domain-related information, and identifying one or more thick services based on thin data for the domain. The method can also include providing, by the client, the user query to the identified one or more thick services and obtaining a first answer to the user query from the one or more thick services. Furthermore, the method can include providing a second answer to a user based on the first answer.
    Type: Grant
    Filed: February 17, 2021
    Date of Patent: June 16, 2026
    Assignee: VeriSign, Inc.
    Inventors: Patrick Kane, Marc Anderson, Scott Hollenbeck, Swapneel Sheth, Joseph Waldron, James Gould
  • Patent number: 12645777
    Abstract: Implementations are described herein for unlocking a wireless device using image analysis and liveliness detection. A wireless device may capture, using a camera of the wireless device, an image of a person that is interacting with the wireless device. The wireless device may transmit a first signal using a first antenna and may receive a second signal using a second antenna. The wireless device may determine whether the image corresponds to a stored image. The wireless device may determine whether the second signal indicates a movement of the person or a depth characteristic of the person. The wireless device may selectively unlock the wireless device based on whether the image matches a stored image of the plurality of the stored images and based on whether the second signal indicates at least one of the movement of the person or the depth characteristic of the person.
    Type: Grant
    Filed: June 27, 2024
    Date of Patent: June 2, 2026
    Assignee: AMAZON TECHNOLOGIES, INC.
    Inventor: Hannan Ma
  • Patent number: 12647488
    Abstract: Systems and methods for account association with voice-enabled devices are disclosed. For example, a voice-enabled device situated in a managed environment, such as a hotel room, may be taken by a temporary resident or guest of the environment. Upon determining that the device has been removed from the environment, a device identifier associated with the device may be dissociated from components and/or services associated with environment and/or systems related thereto, and the device identifier may be associated with a user account of the user.
    Type: Grant
    Filed: August 14, 2024
    Date of Patent: June 2, 2026
    Assignee: Amazon Technologies, Inc.
    Inventor: Anand Kishor Mehta