Patents Examined by Mohammed Waliullah
-
Patent number: 12732374Abstract: Methods, systems, apparatuses, and computer-readable storage mediums described herein enable executable code of a hardware security platform (HSP) circuit to communicate with a hypervisor in a separate processor. The hypervisor generates and manages virtual machines. The HSP code comprises trusted platform module (TPM) logic, that processes TPM commands received via the hypervisor, and in response to the processing, communicates security information (e.g., measurements, keys, authorization data) with the virtual machines via the hypervisor. The TPM logic receives security information related to a virtual machine from the hypervisor and stores the security information in non-volatile memory of the HSP circuit, where security information from a particular VM is distinguishable from security information from another VM in the HSP memory.Type: GrantFiled: August 23, 2024Date of Patent: September 8, 2026Assignee: Microsoft Technology Licensing, LLCInventors: Md. Nazmus Sakib, Ronald Aigner, Ling Tony Chen, Peter David Waxman, David Guy Weston, Bryan David Kelly
-
Patent number: 12722600Abstract: A terminal device includes a communication device, configured to detect whether a native system of the terminal device includes components for adapting a public protocol of a digital vehicle key, and communicating with a target communication party based on the public protocol in case of absence of at least one of the components in the native system, in which the target communication party is a participant of the public protocol.Type: GrantFiled: July 3, 2023Date of Patent: September 1, 2026Assignee: XIAOMI EV TECHNOLOGY CO., LTD.Inventor: Changyu Sun
-
Patent number: 12726370Abstract: Methods for the generation and use of session keys for authentication of a user of a server device are disclosed. The methods use a biological objects of the user to generate responses to challenges. During enrollment, the server device receives a password, hashes it a first number of times, and sends the hash to the user. The user interprets the hash as a set of challenges for the biological object, applies the challenges, and stores the responses. During authentication, the server hashes the password a second number of times, less than the first number, and sends the hash to the user. The user iteratively applies second hash to the biological object, compares the responses to the stored responses, and if there is not a match, hashes the challenges again until there is a match. The number of hashes needed for a match is a session key or subkey.Type: GrantFiled: December 27, 2023Date of Patent: September 1, 2026Assignee: Arizona Board of Regents on Behalf of Northern Arizona UniversityInventors: Bertrand F. Cambou, Michael L. Garrett
-
Patent number: 12726521Abstract: A system and method for movement and manipulation of secure data. The system and method combine the ability to restrict and control the transport and processing of data based on specified directives and provide rich auditable provenance to support evidentiary requirements. The system may additionally automatically optimize data routes and specify processing hardware based on data residency, sovereignty, or localization restrictions, constraints, or economic considerations, furthermore, protect sensitive data from compromise by generating and integrating digital tokens and employing observability sensors, processing flows, and analytics on devices in the data transport, storage and compute chain to provide a secure method of data transport and utilization within applications.Type: GrantFiled: February 19, 2024Date of Patent: September 1, 2026Assignee: QOMPLX LLCInventors: Jason Crabtree, Andrew Sellers
-
Patent number: 12712861Abstract: This disclosure describes a secure tunneling mechanism with DoS mitigation operating in a VPN-based mesh network. The mechanism uses a combination of static and temporal cookies to enable a server to identify peers while still retaining anonymity, and without requiring the server to perform expensive asymmetric cryptography (D-H) operations. In this approach, peers are identifiable by just performing hashes and using symmetric cryptography. The mechanism implements a generalized method of packet handling that provides for data scattering and gathering, thereby enabling encrypted frames conforming to a packet format and communicated by a peer to be spread across multiple physical packets both during a handshake, as well as during the exchange of data (between peers) during the session.Type: GrantFiled: June 27, 2025Date of Patent: August 18, 2026Assignee: CORTWO CORP.Inventors: Aaron Kutch, Gil Meir
-
Patent number: 12712857Abstract: Embodiments of this application provide a message processing method and apparatus, and an electronic device. The method is applied to a terminal device, and the method includes: receiving a first message; and pulling up a first application when the first message is a reassembly message, so that the first application performs message reassembly on the first message, including: reading, by the first application, message reassembly configuration information, and performing a message reassembly operation on the first message based on the message reassembly configuration information, to generate a second message. According to the method in the embodiments of this application, after a pushed message is received, the first application is pulled up to reassemble the message, so as to improve user experience of message display.Type: GrantFiled: April 17, 2023Date of Patent: August 18, 2026Assignee: Honor Device Co., Ltd.Inventor: Ping Li
-
Patent number: 12711278Abstract: A node on a blockchain network, includes: a memory that stores asset related data including information on an owner of an asset, and contract related data including a transaction price of the asset or a ratio corresponding to the price of the asset; and circuitry to transmit the asset related data and the contract related data to one or more other nodes on the blockchain network to share the asset related data and the contract related data.Type: GrantFiled: December 27, 2023Date of Patent: August 18, 2026Assignee: RICOH COMPANY, LTD.Inventor: Hitoshi Namiki
-
Patent number: 12705390Abstract: Techniques for data security are provided. Face data for a patient is received, where the face data is linked to an identifier of the patient. A suggested medical device is determined by processing the face data using a recommendation model. Therapy data stored in a first data store and equipment data stored in a second data store are identified based on the identifier, where the equipment data indicates an actual medical device that was provided to the patient. The suggested medical device, the therapy data, and the equipment data are associated.Type: GrantFiled: December 6, 2022Date of Patent: August 11, 2026Assignee: ResMed Pty LtdInventors: Gregory Robert Peake, Michael C. Hogg, Hongjiang Yu
-
Patent number: 12695613Abstract: A data communication system includes a center device that distributes update data to a master device, and a master device that installs the update data downloaded from the center device in an electronic control unit to be reprogrammed. The center device generates a common key for encrypting the update data; encrypts the update data with the common key; encrypts the common key; stores the common key encrypted in a campaign notification; places the update data encrypted with the common key in a content delivery network (CDN); and transmits the campaign notification. The master device acquires the common key from the campaign notification; decrypts the encrypted common key to extract the common key; downloads and acquires encrypted update data from the CDN; performs an exclusive OR operation; and transfers the decrypted update data to the electronic control unit, and installs the update data in the electronic control unit.Type: GrantFiled: March 27, 2024Date of Patent: July 28, 2026Assignee: DENSO CORPORATIONInventors: Hideo Yoshimi, Masaaki Abe, Koto Tomatsu
-
Patent number: 12695610Abstract: In a blockchain data processing method, service updating data of each of a plurality of encrypted data is received. The service updating data of each of the plurality of encrypted data includes encrypted primary key information of the respective encrypted data. Each of the plurality of encrypted data includes service data encrypted by a respective service node of a plurality of service nodes. Service intersection data is generated based on a data intersection of the service updating data of the plurality of encrypted data. The service intersection data is transmitted to a service node of the plurality of service nodes. The service intersection data includes supplemental text data from another service node of the plurality of service nodes.Type: GrantFiled: December 2, 2023Date of Patent: July 28, 2026Assignee: Tencent Technology (Shenzhen) Company LimitedInventors: Hanqing Liu, Zongyou Wang, Hu Lan, Yifang Shi, Gengliang Zhu, Qucheng Liu, Zhiyong Liao
-
Patent number: 12695783Abstract: A processing device is configured to detect potential encryption downgrades in network communications. The processing device accesses network traffic and detects an attempted first connection between a first entity and a second entity in which the first entity offered at least one post-quantum cryptography (PQC) algorithm to encrypt the attempted first connection. The method detects that the attempted first connection failed, and that a second connection between the first entity and the second entity successfully completed without a PQC algorithm, within a threshold time after the attempted first connection. The processing device identifies this second detection as a downgrade attack and performs a remedial action.Type: GrantFiled: November 17, 2025Date of Patent: July 28, 2026Assignee: FORESCOUT TECHNOLOGIES, INC.Inventors: Robert McNutt, Daniel Ricardo dos Santos
-
Patent number: 12682081Abstract: Embodiments described herein provide techniques for securely validating firmware on a device using keys and providing a mechanism for deprecating such keys when a traditional certificate authority is unavailable or otherwise cannot be used. When a first firmware package is installed on the device, a first public key in a first secure memory key location is associated with an active status. Responsive to installation of a second firmware package on the device, a second public key in a second secure memory key location on the device is associated with an active status. During a boot-up operation on the device, embodiments determine to use the second public key to validate the second firmware package by starting at a predefined secure memory key location and scanning backwards until a status of active is identified. The second firmware package on the device is then validated using the second public key.Type: GrantFiled: January 11, 2024Date of Patent: July 14, 2026Assignee: Schneider Electric USA, Inc.Inventor: Michael Pyle
-
Patent number: 12682061Abstract: Communication of dynamically analyzed malware is mediated. Even in a case where communication with the attacker server is stopped, a response accumulated as past data is returned to continue dynamic analysis.Type: GrantFiled: September 10, 2024Date of Patent: July 14, 2026Assignee: Hitachi, LtdInventors: Shota Fujii, Rei Yamagishi, Katsuya Nishijima, Tomohiro Shigemoto, Takayuki Sato
-
Computer-based systems configured to select a monitored data segmentation and methods of use thereof
Patent number: 12683763Abstract: In some embodiments, the present disclosure provides an exemplary system and method that may include steps of identifying a device capable of processing a data stream; calculating a plurality of hash keys for a plurality of monitored segmentations associated with the device capable of the data stream; generating an increment data counter that corresponds to each hash key in a plurality of counting structures; calculating an anomaly score associated for the plurality of monitored segmentations; selecting a monitored segmentation based on the anomaly score; determining that a selected monitored segmentation meets a predetermined threshold associated with the anomaly score; and automatically marking the device capable of the data stream with a pre-generated label.Type: GrantFiled: December 29, 2023Date of Patent: July 14, 2026Assignee: Capital One Services, LLCInventors: Nikita Seleznev, Christopher Bayan Bruss, Chaya Glendon, Senthil Kumar -
Patent number: 12671683Abstract: PKI Certificates are fingerprinted bi-directionally, replacing traditional certificate exchange in constrained computing and networking environments during a D/TLS session initiation for faster logon to well acquainted peers. Fingerprinting PKI Certificates bi-directionally allows for certificate compression when one or both peers are unacquainted and use of OCSP stapling or OCSP trusted responders offloading validation to robust clusters. A handshake is described for certificate exchange in an OCSP stapling or OSCP with trusted responder environment, and where the network and clients are constrained, which address the deficiencies of the RFC's.Type: GrantFiled: October 9, 2023Date of Patent: June 30, 2026Assignee: ARINC IncorporatedInventor: Jonathan M. Graefe
-
Patent number: 12665763Abstract: Systems and processes are described for establishing and using a secure channel. A shared secret may be used for authentication of session initiation messages as well as for generation of a private/public key pair for the session. A number of ways of agreeing on the shared secret are described and include pre-sharing the keys, reliance on a key management system, or via a token mechanism that uses a third entity such as a hub to manage authentication, for example. In some instances, the third party may also perform endpoint selection (e.g., load balancing) by providing a particular endpoint along with the token.Type: GrantFiled: October 10, 2023Date of Patent: June 23, 2026Assignee: Amazon Technologies, Inc.Inventors: Allan Henry Vermeulen, Matthew John Campagna, Colm Gearóid MacCárthaigh
-
Patent number: 12652318Abstract: There is provided a method for implementing a zero trust role-based microsegmentation based on a network switch. The method includes steps of: (a) registering, by a network controller, the specific network device in a specific segment among preset segments by referring to asset information corresponding to the specific network device; and (b) transmitting, by the network controller, a specific segment ID corresponding to the specific segment to the access switch, to thereby instruct the access switch to assign the specific segment ID as metadata to a specific MAC address of the specific network device by using VACL, and control an access of the specific network device to the network resources based on at least one specific resource access control rule corresponding to the specific segment ID by using IACL.Type: GrantFiled: October 31, 2025Date of Patent: June 9, 2026Assignee: PIOLINK, INC.Inventors: Junnyung Choi, Nam Pyo Kim, Jae Young Park
-
Patent number: 12634127Abstract: The present disclosure provides an information processing apparatus that enables updating of a key for program verification without invalidating a program verification function. An information processing apparatus 1 that calculates a verification value using a key for program verification and that verifies whether the verification value matches a verification expected value stored in advance. The information processing apparatus 1 includes: a key updating control unit 12 that updates the key; a storage unit 100 that stores in advance a verification expected value corresponding to a key updated by the key updating control unit 12; and a verification expected value changing unit 13 that when a verification value calculated based on the updated key is verified, changes the verification expected value in the storage unit, the verification expected value being referred to for verification, to a verification value corresponding to the updated key.Type: GrantFiled: August 12, 2022Date of Patent: May 19, 2026Assignee: HITACHI ASTEMO, LTD.Inventors: Nobuyoshi Morita, Mikio Kataoka, Yasuhiro Fujii, Masashi Yano
-
Patent number: 12634118Abstract: Systems and techniques for cryptographically protecting data in a computer memory are disclosed. The techniques include dividing the data into a first portion and a second portion, encrypting the first portion of the data to create a first stored form of the data, encrypting the second portion of the data, and storing, in the computer memory, the first stored form of the data and a second stored form of the data. The techniques include, to encrypt the second portion, calculating a hash based on the first stored form of the data, applying a first pseudorandom function to the hash to obtain a bit sequence, and combining the bit sequence with the second portion of the data to obtain the second stored form of the data.Type: GrantFiled: May 9, 2024Date of Patent: May 19, 2026Assignee: Cryptography Research, Inc.Inventors: Michael Alexander Hamburg, Evan Lawrence Erickson, Ajay Kapoor
-
Patent number: 12627484Abstract: Methods for the encoding an encryption key for secure storage are disclosed. The methods rely on the use of unclonable, one-way functions, such as images of biological objects that may be measured according to challenges to result in responses. A biometric print of a biological object is measured with a set of n challenges resulting in n responses. The responses are an ordered sequence, with each response having a fixed position in the sequence. A key is generated of bit length n. A subset of m responses in the full set of n responses is selected, where the selected responses correspond to positions of is in the key. The response subset is stored. The key is then used, and deleted. A party wishing to re-generate the key generates the same set of challenges, measures the same biological object with the challenges a second time, and generates a second set of n responses.Type: GrantFiled: April 17, 2024Date of Patent: May 12, 2026Assignees: ARIZONA BOARD OF REGENTS ON BEHALF OF NORTHERN ARIZONA UNIVERSITY, BROWN UNIVERSITYInventors: Bertrand F Cambou, Jeffrey Hoffstein