Patents Examined by Michael Simitoski
  • Patent number: 12712747
    Abstract: A procedure is provided for initiating a secure communication session between a card and a host. A static encryption key is assigned to the card and stored in the card. Each of the card and the host provide a key version number and a key identifier of the static key.
    Type: Grant
    Filed: August 14, 2024
    Date of Patent: August 18, 2026
    Assignee: GIESECKE+DEVRIENT MOBILE SECURITY GERMANY GMBH
    Inventor: Praveen Patel
  • Patent number: 12705380
    Abstract: The present disclosure involves systems, software, and computer implemented methods for data privacy. One example method includes receiving a request to export and then delete personal data for a data subject. A work package is sent to applications that requests a respective application to perform a blocking check and a data export for an object that represents the data subject. A data privacy integration service receives, from the applications, response information to the work package that includes blocking check information and personal data export information. The personal data export information is evaluated, and a determination is made that each application has completed a requested personal data export.
    Type: Grant
    Filed: November 5, 2024
    Date of Patent: August 11, 2026
    Assignee: SAP SE
    Inventors: Benny Rolle, Matthias Vogel
  • Patent number: 12694136
    Abstract: In some examples, a system computes read burst indicators of read input/output (I/O) bursts to a storage system at respective time points, and computes encryption burst indicators of encryption I/O bursts at the respective time points. The system calculates a score based on the read burst indicators, the encryption burst indicators, and a distance factor that is based on a time distance between when a burst read I/O burst of the read I/O bursts occurred and when an encryption I/O burst of the encryption I/O bursts occurred. The system determines whether unauthorized access of a computing environment is occurring based on the score.
    Type: Grant
    Filed: October 28, 2024
    Date of Patent: July 28, 2026
    Assignee: Hewlett Packard Enterprise Development LP
    Inventors: Omer Uretzky, Gil Barash
  • Patent number: 12695722
    Abstract: A firewall receives bypass traffic obtained by performing a copy operation on the network traffic, and detects a packet in the bypass traffic, to obtain a packet control message. The firewall control module receives the packet control message sent by the firewall, and performs a target operation such as forwarding, discarding, or buffering on a target packet in the plurality of packets. In this method, the firewall deployed in a bypass manner parses data in parallel, and the firewall control module does not need to parse any data.
    Type: Grant
    Filed: March 15, 2024
    Date of Patent: July 28, 2026
    Assignee: HUAWEI CLOUD COMPUTING TECHNOLGOIES CO., LTD.
    Inventors: Zhaoyu Luo, Mian Guo, Jianbiao Li, Wei Deng
  • Patent number: 12695631
    Abstract: Methods, apparatuses, devices and computer readable media are provided in relation to enrolment. In one example, an electronic device is provided. The electronic device comprises a security module having a physical unclonable function (PUF). The security module is configured to establish an enrolment key pair (EPK,ESK) based on a first challenge and response to the PUF, the enrolment key pair comprising an enrolment public key (EPK) and an enrolment secret key (ESK). The electronic device further comprises one or more memories. The electronic device further comprises one or more processors configured to, over a secure connection, transmit a certificate signing request (CSR) comprising a device identifier and the EPK to a server for a certificate certifying that the EPK is associated with the device identifier, wherein the CSR is signed using the ESK, and wherein the device identifier is based on a function of the EPK.
    Type: Grant
    Filed: April 12, 2022
    Date of Patent: July 28, 2026
    Assignee: CRYPTO QUANTIQUE LIMITED
    Inventors: Joanne Woodage, Kenneth Paterson, Shahram Mossayebi
  • Patent number: 12689646
    Abstract: Systems and methods for methods network activity. The methods include receiving at an interface connection data associated with a request from a first device to download an application from a source, downloading the application to a second device based on the request, and executing, using one or more processors executing instructions stored on memory, the downloaded application to obtain behavioral data of the application. The methods further include assigning, using the one or more processors, a risk score to the application based on the behavioral data of the application to determine whether the application is malicious before the application is downloaded by the first device, and implementing, using the one or more processors, a download decision for the first device based on the assigned risk score, wherein the download decision indicates at least whether the first device is able to download the application associated with the request.
    Type: Grant
    Filed: December 9, 2022
    Date of Patent: July 21, 2026
    Assignee: Sophos Limited
    Inventors: Shankar Jayaraman, Rahul Pandey, Santosh Subramanya, Dhwanit Shah, Guy Roberts
  • Patent number: 12688311
    Abstract: System and techniques to generate a cryptographic key specific to a type of hardware are described herein. Software distribution and execution can use cryptographic keys tailored to specific hardware. A secret is generated from a hardware public key. The secret is used to create software public and private keys. The secret is used to protect the data and the public key is distributed with the software for use on a class of hardware to which the hardware private key is applicable. The hardware then uses the software public key and a local copy of the hardware private key to find the secret and decrypt the software to run the software locally.
    Type: Grant
    Filed: June 14, 2024
    Date of Patent: July 21, 2026
    Assignee: Analog Devices, Inc.
    Inventor: Deniz Karakoyunlu
  • Patent number: 12682127
    Abstract: An integrated-circuit device comprising a non-volatile memory (NVM), a debug port, and debug-port control circuitry for controlling access to the integrated-circuit device through the debug port. The debug-port control circuitry is configured to read a first bit array and a second bit array from respective predetermined locations in the NVM in a single read cycle. The second bit array is distinct from the first bit array, and at least the second bit array contains a plurality of bits. The debug-port control circuitry is further configured to determine whether the first bit array has a first predetermined bit pattern and whether the second bit array has a pattern other than a second predetermined bit pattern, and to control access through the debug port at least partly in dependence on said determination.
    Type: Grant
    Filed: August 22, 2022
    Date of Patent: July 14, 2026
    Assignee: Nordic Semiconductor ASA
    Inventors: Bjørnar Hernes, Berend Dekens, Håkon Prestegärd, Hannu Koivuranta
  • Patent number: 12684093
    Abstract: A method, performed by an image processing device, of encrypting image data includes: selecting an encryption target unit from among a plurality units constituting an image; generating a table including identification information about the encryption target unit; generating a first encryption unit including data obtained by encrypting the encryption target unit; generating a second encryption unit including data obtained by encrypting the table; and generating a bitstream including the first encryption unit, the second encryption unit, and units other than the encryption target unit among the plurality of units constituting the image.
    Type: Grant
    Filed: November 19, 2023
    Date of Patent: July 14, 2026
    Assignee: Hanwha Vision Co., Ltd.
    Inventor: Byoung Man An
  • Patent number: 12664248
    Abstract: A method includes obtaining, by an application running on a computing device, a single sign-on (SSO) username of a user who is using the device, without input from the user. The method further includes passing the SSO username to an identity provider (IdP) so as to authenticate the user to the application via an SSO process, thereby causing the IdP to send information about the user to the application, and performing a function, by the application, based on the information. Other embodiments are also described.
    Type: Grant
    Filed: May 29, 2023
    Date of Patent: June 23, 2026
    Assignee: SAILPOINT TECHNOLOGIES, INC.
    Inventors: David Ben Zakai, Eldar Kleiner, Avishai Lazar, Timor Eizenman
  • Patent number: 12657279
    Abstract: An example computing device comprises a memory to store control instructions, and a processor to: perform a first authentication of the control instructions using a first key; and in response to receipt of a command to enable a second authentication of the control instructions, add a second key to a one-time programmable portion of the memory, wherein the command is signed using the first key, the second key to perform a second authentication of the control instructions with the first key to perform the first authentication of the control instructions.
    Type: Grant
    Filed: January 13, 2022
    Date of Patent: June 16, 2026
    Assignee: Hewlett-Packard Development Company, L.P.
    Inventors: Jeffrey Kevin Jeansonne, Mason Andrew Gunyuzlu
  • Patent number: 12647267
    Abstract: Various aspects of the present disclosure relate to attribute-based credentials for resource access. An apparatus, such as a UE, generates one or more credentials comprising one or more first public keys and one or more attributes associated with a service request. The apparatus communicates a credential issuance request comprising at least a portion of the one or more credentials, and receives, based at least in part on the credential issuance request, one or more signed credentials comprising one or more encrypted root keys and one or more encrypted subscription identities associated with the service request.
    Type: Grant
    Filed: May 24, 2024
    Date of Patent: June 2, 2026
    Assignee: Lenovo (Singapore) Pte Ltd
    Inventors: Andreas Kunz, Sheeba Backia Mary Baskaran
  • Patent number: 12632558
    Abstract: An adapter provides an expansion function to an information handling system. The adapter includes an adapter application specific integrated circuit (ASIC), a memory device, and a control unit. The adapter ASIC provides the expansion function. The memory device stores firmware for the adapter ASIC. The control unit validates the firmware.
    Type: Grant
    Filed: April 19, 2024
    Date of Patent: May 19, 2026
    Assignee: Dell Products L.P.
    Inventors: Lee E. Ballard, Jason B. Kilpatrick, Jonathan Foster Lewis, Jason Christopher Rock
  • Patent number: 12625968
    Abstract: A method includes building a firmware image to execute on a bootloader of a system on chip (SoC), the firmware image including first encryption public and private keys, and digitally signing the firmware image with a second encryption private key. The signed firmware image is encrypted with a symmetric encryption key, which in turn is encrypted with a second encryption public key. The encrypted signed firmware image and the encrypted symmetric encryption key are sent to the SoC to cause the SoC to (1) decrypt the encrypted symmetric encryption key to produce the symmetric encryption key using a third encryption private key from a first asymmetric key pair, (2) decrypt the encrypted signed firmware image to produce the signed firmware image using the symmetric encryption key, and (3) verify a digital signature of the signed firmware image using a third encryption public key from a second asymmetric key pair.
    Type: Grant
    Filed: November 20, 2023
    Date of Patent: May 12, 2026
    Assignee: Verkada Inc.
    Inventors: Andrei Goverdovskii, Nick Pelis
  • Patent number: 12619743
    Abstract: A memory controller can operate to provide various data protection schemes without a need of a cache. A unit of data transfer between the memory controller and memory devices can correspond to a size of data corresponding to a host read and/or write command. The memory controller operating without a cache can still ensure data integrity of the memory system to be compliant with standardized requirements and/or protocols, such as trusted execution engine security protocol (TSP).
    Type: Grant
    Filed: June 28, 2023
    Date of Patent: May 5, 2026
    Assignee: Micron Technology, Inc.
    Inventors: Marco Sforzin, Paolo Amato
  • Patent number: 12613959
    Abstract: A first detection unit (121) executes object detection for a subject image. A processing unit (130) generates a painted-out image per bounding box of the subject image by painting out the bounding box of the subject image. A second detection unit (122) executes, per painted-out image, object detection for the painted-out image. A determination unit (140) determines whether an adversarial example patch attack has been conducted, on a basis of a score value of each bounding box of the subject image and a score value of each bounding box of a painted-out image group.
    Type: Grant
    Filed: October 1, 2024
    Date of Patent: April 28, 2026
    Assignee: MITSUBISHI ELECTRIC CORPORATION
    Inventor: Yoshihiro Koseki
  • Patent number: 12615141
    Abstract: A sender system is equipped with an optical transmitter that transmits an encoded optical signal at a predetermined strength via an LOS communication channel, and a key distillator that generates a cryptographic key from a random bit sequence of the optical transmitter by a key distillation processing via the authenticated public communication channel. A legitimate receiver is equipped with an optical receiver that receives the optical signal from the optical transmitter via the LOS communication channel, and a key distillator that generates a cryptographic key from the random bit sequence from the optical receiver through a key distillation processing via the authenticated public communication channel.
    Type: Grant
    Filed: December 21, 2022
    Date of Patent: April 28, 2026
    Assignee: NATIONAL INSTITUTE OF INFORMATION AND COMMUNICATIONS TECHNOLOGY
    Inventors: Hiroyuki Endo, Masahide Sasaki, Mikio Fujiwara, Masahiro Takeoka, Masato Koashi, Toshihiko Sasaki
  • Patent number: 12585236
    Abstract: A SCADA web HMI client device comprises a processor and a memory. The memory stores a user access level, image data for an HMI screen, and screen access authority information, all received from a web server. The screen access authority information includes an operation access level of the HMI screen and operation permission/prohibition of the HMI screen by the web browser. The processor draws the HMI screen in an operable state on the web browser in a case where the user access level is greater than or equal to the operation access level and where operation of the HMI screen by the web browser is permitted. The processor draws the HMI screen in an inoperable state on the web browser in a case where the user access level is less than the operation access level or operation of the HMI screen by the web browser is not permitted.
    Type: Grant
    Filed: March 30, 2022
    Date of Patent: March 24, 2026
    Assignee: TMEIC CORPORATION
    Inventors: Ryo Shimizu, Akira Nojima, Nobuo Shimizu
  • Patent number: 12585768
    Abstract: Disclosed herein are systems and methods for detecting malware in scripts. A method includes: monitoring, at a first computing device, an execution flow of at least one portion of a script; computing a fingerprint that represents the execution flow; determining whether the fingerprint is present in a local fingerprint database that includes a plurality of entries for known scripts; in response to determining that the fingerprint is not present in the local fingerprint database, transmitting the fingerprint to a central database server including a universal fingerprint database; in response to receiving an indication that the fingerprint is not present in the universal fingerprint database, scanning the at least one portion of the script for malware; and blocking the script in response to determining that the at least one portion of the script includes malware based on the scanning.
    Type: Grant
    Filed: June 19, 2024
    Date of Patent: March 24, 2026
    Assignee: Cloud Linux Software, Inc.
    Inventors: Igor Seletskiy, Serhii Brazhnyk, Arsenii Pastushenko
  • Patent number: 12585782
    Abstract: Systems and methods are provided for validation and enforcement of the use of factory-provisioned boot restrictions for the operation of an (Information Handling Systems). During factory provisioning of the IHS, a factory-signed certificate is uploaded to the IHS that identifies the factory-installed hardware of the IHS and any boot restrictions on individual factory-installed hardware, such as restrictions on a hardware component to boot using only factory-provision firmware or the component is to be disabled. Upon deployment of the IHS, validation procedures use an inventory from the certificate to validate the detected IHS hardware as factory-installed. The validation procedures use the boot restriction from the certificate to confirm the detected IHS hardware components are each configured for operation according to the boot restrictions.
    Type: Grant
    Filed: November 17, 2023
    Date of Patent: March 24, 2026
    Assignee: Dell Products L.P.
    Inventors: Rama Rao Bisa, Mini Thottunkal Thankappan, Vineeth Radhakrishnan, Dharma Bhushan Ramaiah, Shinose Abdul Rahiman, A Anis Ahmed, Jason Matthew Young