Patents Examined by Rupal Dharia
-
Patent number: 12724868Abstract: A method of starting up and managing an offline control device with a management control unit and a terminal, includes: implementing of a multi-factor/ID authentication algorithm in the terminal; delivering the terminal and a first storage medium having a storage medium ID and a first security code to a customer; delivering of a second security code generated using the first security code, to a second storage medium of the customer; positioning, by a user, of the first and second storage mediums at the terminal and reading of the storage medium ID and the first and second security codes, and offline checking by the algorithm of the terminal, whether the read first and second security codes are valid with one another; after a positive multi-factor authentication check, storing the storage medium ID as the authorization ID and the first security code in the terminal; and terminating the initial start-up mode.Type: GrantFiled: December 21, 2022Date of Patent: September 1, 2026Assignee: Sphinx Electronics GmbH & Co KGInventors: Trong-Nghia Cheng, Reinhard Eggert, Pascal Bodechon
-
Patent number: 12719910Abstract: An Information Handling System (IHS), such as a workspace orchestration service IHS, observes location information of a device, and receives location information logged by the device. The observed location information may include telemetry of the device, and/or the received device-logged location information may include below-OS telemetry of the device The IHS correlates the observed location information with the received device-logged location information, and adjusts a security score of the device in accordance with the resulting correlation. Where the device is a workspace instantiation client IHS, the logged location information is logged by the workspace, and the security score is the security score of the workspace. Also, the workspace orchestration service IHS may build a definition for the workspace, that includes one or more localized entitlements for the workspace, or may build the workspace definition to include remediation action, based on the location information and/or adjusted security score.Type: GrantFiled: January 20, 2023Date of Patent: August 25, 2026Assignee: Dell Products L.P.Inventors: Nicholas D. Grobelny, Girish S. Dhoble, Joseph Kozlowski
-
Patent number: 12719864Abstract: In some implementations, a cloud management device may receive, from a user device, a configuration associated with a task for cloud computing. The cloud management device may input one or more properties, associated with the configuration, to a model that is trained on historical cloud computing task information. Accordingly, the cloud management device may receive, from the model, an indication of a selected cloud environment, from a plurality of possible cloud environments based on credentials associated with the user device. The cloud management device may generate instructions for the task based on the selected cloud environment and may trigger execution of the task by the selected cloud environment using the instructions.Type: GrantFiled: December 9, 2022Date of Patent: August 25, 2026Assignee: Capital One Services, LLCInventors: Pooja Mulik, Suyog Parajuli, Gita Antoinette Lourdes, Nikhil Agarwal, Prasanth Jain
-
Patent number: 12719677Abstract: A device and a network can authenticate using a subscription concealed identifier (SUCI). The device can store (i) a plaintext subscription permanent identifier (SUPI) for the device, (ii) a network static public key, and (iii) a key encapsulation mechanism (KEM) for encryption using the network static public key. The network can store (i) a device database with the SUPI, (ii) a network static private key, and (iii) the KEM for decryption using the network static private key. The device can (i) combine a random number with the SUPI as input into the KEM to generate a ciphertext as the SUCI, and (ii) transmit the ciphertext/SUCI to the network. The network can (i) decrypt the ciphertext using the KEM to read the SUPI, (iii) select a key K from the device database using the SUPI, and (iv) conduct an Authentication and Key Agreement (AKA) with the selected key K.Type: GrantFiled: December 4, 2023Date of Patent: August 25, 2026Assignee: Adeia Emerging Technologies Inc.Inventor: John A. Nix
-
Patent number: 12712731Abstract: Apparatus and methods for prime field modular reduction are described. As an example, a custom modular reduction digital circuit for reducing an n-bit integer based on a modulus, where the modulus comprises a k-bit integer for use with a cryptographic algorithm, is described. The custom modular reduction digital circuit includes a first circuit to generate at least two partial results by processing: (1) k lower order significant bits of the n-bit integer and (2) at least a subset of bits for congruent representations corresponding to any n-k higher order bits of the n-bit integer that are higher in significance than the most significant bit of the k-bit integer. The custom modular reduction digital circuit further includes a second circuit to process the at least two partial results, output by the first circuit, to generate a reduced version of the n-bit integer for use with the cryptographic algorithm.Type: GrantFiled: November 3, 2023Date of Patent: August 18, 2026Assignee: Microsoft Technology Licensing, LLCInventor: Jay Scott Fuller
-
Patent number: 12706919Abstract: A system can receive, from a remote computer, request data that identifies a request associated with a user account for credentials that are configured to access a computing resource, wherein the request data comprises a concealed value, and wherein the concealed value comprises a deployment public key that is concealed with an ephemeral secret key. The system can unlock the concealed value using a vendor secret key corresponding to the user account, to produce an unlocked concealed value. The system can send the unlocked concealed value to the remote computer, enabling the remote computer to determine a data encryption key based on processing the unlocked concealed value using the ephemeral secret key, enabling the remote computer to decrypt encrypted break-glass credentials using the data encryption key to produce break-glass credentials, and enabling the remote computer to access the computing resource using the break-glass credentials.Type: GrantFiled: September 29, 2023Date of Patent: August 11, 2026Assignee: Dell Products L.P.Inventors: Seema M. Tahaliyani, Yuanyuan Zhang, Ananthakrishnan Balakrishnan
-
Patent number: 12705371Abstract: Point-in-Time data access authorization is realized by a data access broker and data access security manager that provide for a data owner/authorizer to provide access consent at the point in time at which a specific data access request is made, without the need for the data owner to share their service-specific access credentials with the third-party entity/data requester. As a result, the data owner has control over the authorization of each data access request and has knowledge as to when the third-party entity is accessing the data. Further, by not having to share access credentials with the third-party entity/data requester security issues related to exposure and/or misuse of the access credentials are avoided.Type: GrantFiled: November 4, 2022Date of Patent: August 11, 2026Assignee: BANK OF AMERICA CORPORATIONInventors: Gregory Allen Burkett, Brady Prentice Merkel, David E. Strommer
-
Patent number: 12695606Abstract: An encryption key is created, and sensitive security data is sourced from it and from live data collected in real-time from a user context by a group functions. Subsequently, indicators to functions are stored and the encryption key with the sensitive security data is deleted. Redundancy is provided so that the decryption key can be created from different combinations of functions. A decryption key is later generated with sensitive security data using one or more stored indicators of the one or more functions to obtain an instance of live data in real-time from a current user context. Failing to generate the correct decryption key will result in repeating the creation of the decryption key with different groups of functions until access is granted or combinations of redundant stored functions are exhausted.Type: GrantFiled: June 13, 2023Date of Patent: July 28, 2026Inventor: Nicolas Leoutsarakos
-
Patent number: 12682126Abstract: Systems, methods, and apparatuses relating to an instruction that allows a trusted execution environment to react to an asynchronous exit are described. In one embodiment, a hardware processor includes a register comprising a field, that when set, is to enable an architecturally protected execution environment for code in an architecturally protected enclave in memory, a decoder circuit to decode a single instruction comprising an opcode into a decoded instruction, the opcode to indicate an execution circuit is to invoke a handler to handle an asynchronous exit from execution of the code in the architecturally protected enclave and then resume execution of the code in the architecturally protected enclave from where the asynchronous exit occurred, and the execution circuit to respond to the decoded instruction as specified by the opcode.Type: GrantFiled: December 26, 2020Date of Patent: July 14, 2026Assignee: Intel CorporationInventors: Scott Constable, Mark Shanahan, Mona Vij, Bin Xing, Krystof Zmudzinski
-
Patent number: 12671576Abstract: A method for secure aggregation, by a server, of client-provided inputs includes receiving, from each of a plurality of clients, a respective client input, for which a commitment is published. The commitments were computed using randomness and are aggregated by at least two super-clients and a sum of the aggregated commitments is published by each super-client. A sum of the received client inputs is published such that validity of the sum is checkable, by the clients, by comparing the sum of the received client inputs to a verification algorithm result that uses a sum of additive shares computed by the clients using the randomness, and by verifying that the published sum of the aggregated commitments is the same for each super-client. The method can be applied to use cases, for example, in digital medicine using medical data or smartcity applications to support decision-making.Type: GrantFiled: October 5, 2023Date of Patent: June 30, 2026Assignee: NEC CORPORATIONInventors: Claudio Soriente, Giorgia Marson
-
Patent number: 12671680Abstract: A computer-implemented method includes: receiving, via a computing device, a login request for a resource account; authenticating a user associated with the login request to an account session of the resource account; receiving, via the computing device during the account session, a trade request for performing a first trading action in connection with a tradeable object; in response to receiving the trade request: granting time-limited access to an account operation for the resource account, the first account operation associated with defined first trade parameters for the first trading action; receiving user input for initiating the first account operation at a first time; validating the first account operation based on verifying eligibility of the first trading action and validity of the account session at the first time; and in response to validating the first account operation, cause the first trading action to be executed based on processing the first account operation.Type: GrantFiled: May 6, 2022Date of Patent: June 30, 2026Assignee: The Toronto-Dominion BankInventors: Lauren Erica Miele, Adam Judson, James Wolanski
-
Patent number: 12666255Abstract: Systems and methods for selective User Plane protection in a 5G virtual RAN are provided. A method performed by a gNB Central Unit (gNB-CU) for communicating with a gNB-Distributed Unit (gNB-DU) includes determining whether to selectively encrypt a PDU to be sent to the gNB-DU if the PDU is not otherwise encrypted. In response to determining to selectively encrypt, the method includes encrypting the PDU to be sent to the gNB-DU. In response to determining to not selectively encrypt, the method includes passing the PDU to be sent to the gNB-DU. In this way, additional security is provided while performance impact is minimized. In some embodiments, this provides a lower overhead on the gNB-CU-UP side compared to applying a generic protection of all PDUs. Additionally, the latency overhead is limited since a secure session establishment and handshake is confined to the gNB-CU-UP-SEG domain instead of gNB-CU-UP to gNB-DU.Type: GrantFiled: March 18, 2020Date of Patent: June 23, 2026Assignee: Telefonaktiebolaget LM Ericsson (publ)Inventors: Stere Preda, Daniel Migault, Amine Boukhtouta, Xiaowen Yue
-
Patent number: 12665744Abstract: A cryptographic computer processes a word of p bits in an electronic message as a set of k n-state elements with n an integer greater than 2 and 2{circumflex over (?)}p>n and k>1, with the p bits being characterized as a word of k n-state elements. The computer processes two words of k n-state elements as an radix-n operation that includes a 2 operand reversible n-state operation of which an output is a residue and a 2 operand n-state transition function of which an output is an n-state transition element. An output of the radix-n operation is a word of k n-state elements. The radix-n operation is preferably not reversible and is part of an operation that generates a cryptographic message. A standard cryptographic operation is modified by applying the radix-n operation. The cryptographic message is transmitted over a physical channel.Type: GrantFiled: October 7, 2024Date of Patent: June 23, 2026Inventor: Peter Lablans
-
Patent number: 12665761Abstract: Systems and methods for performing mutual authentication between a hardware access token and a reader device are provided. The systems and methods include reading a unique or pseudo-unique identifier of the hardware access token and computing a password for the hardware access token based on the unique or pseudo-unique identifier and a group secret of the reader device.Type: GrantFiled: June 28, 2021Date of Patent: June 23, 2026Assignee: MOZARC MEDICAL US LLCInventors: Arindam Ghosh Roy, Sharath Nagendra
-
Patent number: 12665899Abstract: An authentication method and an electronic device. The method includes sending, by a first device, in response to a first device determining that a distance between the first device and a second device reaches a first distance, a first request to the second device, so that the second device determines whether wireless communication between the first and second device is relayed before the first device performs a service, determining, in response to the distance between the first and second device reaching a second distance, whether success ciphertext sent by the second device is received, wherein the success ciphertext is sent in response to the second device determining that wireless communication between the first and second device is not relayed and the second distance being less than the first distance, and performing the service in response to reception and successful verification of the success ciphertext.Type: GrantFiled: December 16, 2020Date of Patent: June 23, 2026Assignee: Huawei Technologies Co., Ltd.Inventors: Zhuofei Li, Wei Gao
-
Patent number: 12665769Abstract: Technology related to authentication using an intermediary is disclosed. In one example, a method for authentication can include intercepting a first authentication response destined for a server. The first authentication response identifies a server authentication service and is digitally signed by an identity service provider. The first authentication response can be authenticated using a cryptographic key of the identity service provider to validate an identity service provider signature included in the first authentication response. In response to validating the identity service provider signature, a second authentication response can be sent to the server that identifies the server authentication service.Type: GrantFiled: August 9, 2019Date of Patent: June 23, 2026Assignee: F5, Inc.Inventors: Michael James Coleman, II, Graham Rein Alderson, Charlie Wilson Lesley, III
-
Patent number: 12657349Abstract: Encrypting keystroke data in a multi-session-enabled computing device includes receiving a first control message requesting enabling of keystroke encryption for a protected application executing in a first desktop session. The first control message includes application identification information of the protected application. Keystroke encryption is enabled for keystrokes targeting the first desktop session based on receipt of the first control message. Keystroke data sent to the protected application is encrypted while the protected application maintains keyboard focus in the first desktop session. Unencrypted keystroke data is transmitted to another application of a second desktop session while keystroke encryption is enabled for the protected application in the first desktop session.Type: GrantFiled: September 15, 2023Date of Patent: June 16, 2026Assignee: Omnissa, LLCInventors: Xiaoyu Kong, YiQun Yun, ZhangLin Zhou, Yang Yu
-
Patent number: 12659152Abstract: A system includes a memory configured to store a set of private valid source data. The system includes processors operably coupled to the memory and configured to access the set of private valid source data, and to execute a dynamic data encryption engine configured to identify a sensitivity level of the set of private valid source data and to encrypt the set of private valid source data in accordance with a data encryption algorithm. The data encryption algorithm is selected based on the identified sensitivity level. The processors further execute a data ingestion and dynamic decryption engine configured to ingest the encrypted set of private valid source data into the hybrid cloud computing and storage system, and in response to receiving a request to retrieve the encrypted set of private valid source data from the hybrid cloud computing and storage system, decrypt the encrypted set of private valid source data.Type: GrantFiled: June 26, 2024Date of Patent: June 16, 2026Assignee: Bank of America CorporationInventors: Bikash Dash, Meera Lakshmi
-
Patent number: 12659153Abstract: Intelligent functionality enablement techniques are disclosed. In one example, a method comprises obtaining a functionality enablement file comprising at least a first block and a second block, wherein the first block is usable to activate one or more features of a product and the second block is usable to perform a configuration setup to enable the product to operate in accordance with at least one computing platform.Type: GrantFiled: May 8, 2023Date of Patent: June 16, 2026Assignee: Dell Products L.P.Inventor: Shibi Panikkar
-
Patent number: 12647436Abstract: A machine learning (ML) attack detection and prevention system may monitor operation of an explainable artificial intelligence (AI) model processed by an application server to provide a product or service to a user. The AI model outputs explainable data and/or other outputs used in decision making. The ML attack detection and prevention system derives business rules based on the explainable data produced by the explainable AI model. Additionally, the ML attack detection and prevention system processes rules repositories of simulation failure data, historical failure data and business rules to derive possible fraud rules based on the data collected in above step. Based on a comparison of rules derived from the AI model output and the possible fraud rules, the ML attack detection and prevention system issues an alert if a fraud condition is suspected and causes the application server to revert back to a previous version of the AI model.Type: GrantFiled: February 24, 2022Date of Patent: June 2, 2026Assignee: Bank of America CorporationInventor: Vijay Kumar Yarabolu