Patents Examined by Rupal Dharia
-
Patent number: 12682126Abstract: Systems, methods, and apparatuses relating to an instruction that allows a trusted execution environment to react to an asynchronous exit are described. In one embodiment, a hardware processor includes a register comprising a field, that when set, is to enable an architecturally protected execution environment for code in an architecturally protected enclave in memory, a decoder circuit to decode a single instruction comprising an opcode into a decoded instruction, the opcode to indicate an execution circuit is to invoke a handler to handle an asynchronous exit from execution of the code in the architecturally protected enclave and then resume execution of the code in the architecturally protected enclave from where the asynchronous exit occurred, and the execution circuit to respond to the decoded instruction as specified by the opcode.Type: GrantFiled: December 26, 2020Date of Patent: July 14, 2026Assignee: Intel CorporationInventors: Scott Constable, Mark Shanahan, Mona Vij, Bin Xing, Krystof Zmudzinski
-
Patent number: 12671576Abstract: A method for secure aggregation, by a server, of client-provided inputs includes receiving, from each of a plurality of clients, a respective client input, for which a commitment is published. The commitments were computed using randomness and are aggregated by at least two super-clients and a sum of the aggregated commitments is published by each super-client. A sum of the received client inputs is published such that validity of the sum is checkable, by the clients, by comparing the sum of the received client inputs to a verification algorithm result that uses a sum of additive shares computed by the clients using the randomness, and by verifying that the published sum of the aggregated commitments is the same for each super-client. The method can be applied to use cases, for example, in digital medicine using medical data or smartcity applications to support decision-making.Type: GrantFiled: October 5, 2023Date of Patent: June 30, 2026Assignee: NEC CORPORATIONInventors: Claudio Soriente, Giorgia Marson
-
Patent number: 12671680Abstract: A computer-implemented method includes: receiving, via a computing device, a login request for a resource account; authenticating a user associated with the login request to an account session of the resource account; receiving, via the computing device during the account session, a trade request for performing a first trading action in connection with a tradeable object; in response to receiving the trade request: granting time-limited access to an account operation for the resource account, the first account operation associated with defined first trade parameters for the first trading action; receiving user input for initiating the first account operation at a first time; validating the first account operation based on verifying eligibility of the first trading action and validity of the account session at the first time; and in response to validating the first account operation, cause the first trading action to be executed based on processing the first account operation.Type: GrantFiled: May 6, 2022Date of Patent: June 30, 2026Assignee: The Toronto-Dominion BankInventors: Lauren Erica Miele, Adam Judson, James Wolanski
-
Patent number: 12666255Abstract: Systems and methods for selective User Plane protection in a 5G virtual RAN are provided. A method performed by a gNB Central Unit (gNB-CU) for communicating with a gNB-Distributed Unit (gNB-DU) includes determining whether to selectively encrypt a PDU to be sent to the gNB-DU if the PDU is not otherwise encrypted. In response to determining to selectively encrypt, the method includes encrypting the PDU to be sent to the gNB-DU. In response to determining to not selectively encrypt, the method includes passing the PDU to be sent to the gNB-DU. In this way, additional security is provided while performance impact is minimized. In some embodiments, this provides a lower overhead on the gNB-CU-UP side compared to applying a generic protection of all PDUs. Additionally, the latency overhead is limited since a secure session establishment and handshake is confined to the gNB-CU-UP-SEG domain instead of gNB-CU-UP to gNB-DU.Type: GrantFiled: March 18, 2020Date of Patent: June 23, 2026Assignee: Telefonaktiebolaget LM Ericsson (publ)Inventors: Stere Preda, Daniel Migault, Amine Boukhtouta, Xiaowen Yue
-
Patent number: 12665744Abstract: A cryptographic computer processes a word of p bits in an electronic message as a set of k n-state elements with n an integer greater than 2 and 2{circumflex over (?)}p>n and k>1, with the p bits being characterized as a word of k n-state elements. The computer processes two words of k n-state elements as an radix-n operation that includes a 2 operand reversible n-state operation of which an output is a residue and a 2 operand n-state transition function of which an output is an n-state transition element. An output of the radix-n operation is a word of k n-state elements. The radix-n operation is preferably not reversible and is part of an operation that generates a cryptographic message. A standard cryptographic operation is modified by applying the radix-n operation. The cryptographic message is transmitted over a physical channel.Type: GrantFiled: October 7, 2024Date of Patent: June 23, 2026Inventor: Peter Lablans
-
Patent number: 12665761Abstract: Systems and methods for performing mutual authentication between a hardware access token and a reader device are provided. The systems and methods include reading a unique or pseudo-unique identifier of the hardware access token and computing a password for the hardware access token based on the unique or pseudo-unique identifier and a group secret of the reader device.Type: GrantFiled: June 28, 2021Date of Patent: June 23, 2026Assignee: MOZARC MEDICAL US LLCInventors: Arindam Ghosh Roy, Sharath Nagendra
-
Patent number: 12665769Abstract: Technology related to authentication using an intermediary is disclosed. In one example, a method for authentication can include intercepting a first authentication response destined for a server. The first authentication response identifies a server authentication service and is digitally signed by an identity service provider. The first authentication response can be authenticated using a cryptographic key of the identity service provider to validate an identity service provider signature included in the first authentication response. In response to validating the identity service provider signature, a second authentication response can be sent to the server that identifies the server authentication service.Type: GrantFiled: August 9, 2019Date of Patent: June 23, 2026Assignee: F5, Inc.Inventors: Michael James Coleman, II, Graham Rein Alderson, Charlie Wilson Lesley, III
-
Patent number: 12665899Abstract: An authentication method and an electronic device. The method includes sending, by a first device, in response to a first device determining that a distance between the first device and a second device reaches a first distance, a first request to the second device, so that the second device determines whether wireless communication between the first and second device is relayed before the first device performs a service, determining, in response to the distance between the first and second device reaching a second distance, whether success ciphertext sent by the second device is received, wherein the success ciphertext is sent in response to the second device determining that wireless communication between the first and second device is not relayed and the second distance being less than the first distance, and performing the service in response to reception and successful verification of the success ciphertext.Type: GrantFiled: December 16, 2020Date of Patent: June 23, 2026Assignee: Huawei Technologies Co., Ltd.Inventors: Zhuofei Li, Wei Gao
-
Patent number: 12657349Abstract: Encrypting keystroke data in a multi-session-enabled computing device includes receiving a first control message requesting enabling of keystroke encryption for a protected application executing in a first desktop session. The first control message includes application identification information of the protected application. Keystroke encryption is enabled for keystrokes targeting the first desktop session based on receipt of the first control message. Keystroke data sent to the protected application is encrypted while the protected application maintains keyboard focus in the first desktop session. Unencrypted keystroke data is transmitted to another application of a second desktop session while keystroke encryption is enabled for the protected application in the first desktop session.Type: GrantFiled: September 15, 2023Date of Patent: June 16, 2026Assignee: Omnissa, LLCInventors: Xiaoyu Kong, YiQun Yun, ZhangLin Zhou, Yang Yu
-
Patent number: 12659152Abstract: A system includes a memory configured to store a set of private valid source data. The system includes processors operably coupled to the memory and configured to access the set of private valid source data, and to execute a dynamic data encryption engine configured to identify a sensitivity level of the set of private valid source data and to encrypt the set of private valid source data in accordance with a data encryption algorithm. The data encryption algorithm is selected based on the identified sensitivity level. The processors further execute a data ingestion and dynamic decryption engine configured to ingest the encrypted set of private valid source data into the hybrid cloud computing and storage system, and in response to receiving a request to retrieve the encrypted set of private valid source data from the hybrid cloud computing and storage system, decrypt the encrypted set of private valid source data.Type: GrantFiled: June 26, 2024Date of Patent: June 16, 2026Assignee: Bank of America CorporationInventors: Bikash Dash, Meera Lakshmi
-
Patent number: 12659153Abstract: Intelligent functionality enablement techniques are disclosed. In one example, a method comprises obtaining a functionality enablement file comprising at least a first block and a second block, wherein the first block is usable to activate one or more features of a product and the second block is usable to perform a configuration setup to enable the product to operate in accordance with at least one computing platform.Type: GrantFiled: May 8, 2023Date of Patent: June 16, 2026Assignee: Dell Products L.P.Inventor: Shibi Panikkar
-
Patent number: 12647436Abstract: A machine learning (ML) attack detection and prevention system may monitor operation of an explainable artificial intelligence (AI) model processed by an application server to provide a product or service to a user. The AI model outputs explainable data and/or other outputs used in decision making. The ML attack detection and prevention system derives business rules based on the explainable data produced by the explainable AI model. Additionally, the ML attack detection and prevention system processes rules repositories of simulation failure data, historical failure data and business rules to derive possible fraud rules based on the data collected in above step. Based on a comparison of rules derived from the AI model output and the possible fraud rules, the ML attack detection and prevention system issues an alert if a fraud condition is suspected and causes the application server to revert back to a previous version of the AI model.Type: GrantFiled: February 24, 2022Date of Patent: June 2, 2026Assignee: Bank of America CorporationInventor: Vijay Kumar Yarabolu
-
Patent number: 12627511Abstract: Methods and systems for managing endpoint devices are disclosed. The endpoint devices may be managed by onboarding them. To onboarding the endpoint devices, ownership vouchers and proxy certificates may be used to cryptographically verify to which entities authority over the endpoint devices have been delegated. The proxy certificates may extend certificate and/or delegation chains in ownership vouchers to other devices. The extended chains may eliminate the need for proliferation of keys used to demonstrate authority over endpoint devices.Type: GrantFiled: March 26, 2024Date of Patent: May 12, 2026Assignee: Dell Products L.P.Inventors: Bradley K. Goodman, Joseph Caisse, Govind Pulikode Mukundan
-
Patent number: 12621148Abstract: A system for performing operations using linear integer programming for RSA factorization is provided, including an n/e extractor, a prime factorization calculator, a private key determiner, and a decryptor. The n/e extractor is configured to extract a modulus and a public key exponent from a public key. The prime factorization calculator is configured to: determine a semi-prime number of the modulus according to the modulus; use a tail digit and a head digit set of the semi-prime number of the modulus to perform decomposition and factorization with respect to the semi-prime number into two prime factors. The private key determiner is configured to determine a private key using the public key exponent and the two prime numbers. The decryptor is configured to decrypt an encrypted message using the private key so as to generate a decrypted message.Type: GrantFiled: February 8, 2024Date of Patent: May 5, 2026Assignee: City University of Hong KongInventors: Han-Lin Li, Way Kuo
-
Patent number: 12613960Abstract: Some embodiments include a method for detecting and interrupting a cache-based side-channel attack. The method includes: (1) at least calibrating one or more chiplets of a network by calculating a threshold; (2) determining one or more device heartbeat vectors of the one or more chiplets, the one or more device heartbeat vectors being derived at least part from one or more measurements of activity of one of more dedicated security processors associated with the one or more chiplets; (3) determining that a particular chiplet of the one or more chiplets is being attacked with a cache-based side-channel attack, the determining being based at least in part on a computed disparity exceeding the threshold; and (4) employing countermeasures against the cache-based side-channel attack of the particular chiplet, the countermeasures including revoking one or more access rights of the particular chiplet on the network.Type: GrantFiled: May 22, 2022Date of Patent: April 28, 2026Assignee: Ceremorphic, Inc.Inventors: Joydeep Kumar Devnath, Ananya Shrivastava, Arpan Manna, Chandrajit Pal, Mohammed Sumair, Suyash Kandele, Govardhan Mattela
-
Patent number: 12609928Abstract: An apparatus comprises at least one processing device including a processor and a memory. The at least one processing device is configured to implement an agent application for supporting an authentication process between a client device and a web server over at least one network, to register the agent application with an operating system of the client device, and in conjunction with initiation of the authentication process via a web browser of the client device, to obtain a uniform resource identifier (URI) from the web server, the URI corresponding to a particular endpoint of the web server, and to make the URI accessible to the agent application via the operating system. The at least one processing device is further configured to carry out one or more authentication operations of the authentication process at least in part through interaction between the agent application and the particular endpoint of the web server.Type: GrantFiled: December 22, 2022Date of Patent: April 21, 2026Assignee: Dell Products L.P.Inventor: Jacob R. Hutcheson
-
Patent number: 12608468Abstract: Described systems and methods protect client devices such as personal computers and IoT devices against malicious software. In some embodiments, a plurality of client devices report the occurrence of various events to a security server, each such event caused by a local instance of a target application (e.g., mobile app) executing on a respective device. The security server then collates the behavior of the respective target application across the plurality of client devices. Some embodiments compute an aggregate event set and/or sequence combining events detected on one device with events detected on other devices, and determine whether the target application is malicious according to the aggregate event set/sequence.Type: GrantFiled: August 23, 2022Date of Patent: April 21, 2026Assignee: Bitdefender IRP Management Ltd.Inventors: Marius M. Tivadar, Alexandra S. Bocereg, Razvan G. Gosa
-
Patent number: 12603878Abstract: Various embodiments of the disclosure disclose a method and an apparatus comprising: a communication module comprising communication circuitry, a memory, and a processor operatively connected to at least one of the communication module and the memory, wherein the processor is configured to: based on the electronic device being connected to a vehicle, transmit mobile identity document information stored in the memory to the vehicle through the communication module, receive vehicle information from the vehicle based on the mobile identity document information being completely authenticated by the vehicle, generate a digital key of the vehicle based on the vehicle information or the mobile identity document information, transmit the generated digital key to the vehicle, receive a digital key signed by the vehicle and driver identification information from the vehicle, and store the signed digital key and the driver identification information in the memory.Type: GrantFiled: October 4, 2022Date of Patent: April 14, 2026Assignee: SAMSUNG ELECTRONICS CO., LTD.Inventors: Eunyoung Kwon, Daehaeng Cho, Gawon Lee, Seonhee Lee, Jisoo Lee, Taeckki Lee
-
Patent number: 12602453Abstract: A content owner registers with an identity authority by providing information about the content owner and a public key of a public/private key pair. The content owner registers content to the identity authority and signs the multiple segments of the content with the private key of the public/private key pair. A system that receives the signed content determines an indicated content owner of the received media content and communicates with the identity authority to confirm that the media content was produced by the indicated content owner. The receiving system requests the public key of the content owner from the identity authority and uses the public key to verify the signature of each media content segment. Accordingly, the receiving system is able to determine if the media content was manipulated after being distributed by the content owner.Type: GrantFiled: August 31, 2021Date of Patent: April 14, 2026Assignee: NAGRAVISION SÀRLInventors: Christophe Buffard, Laura Buffard
-
Patent number: 12591687Abstract: A method for providing vulnerability management by using drift analytics is disclosed. The method includes aggregating vulnerability reports that correspond to an application based on a predetermined configuration, the predetermined configuration including a predetermined schedule; appending the vulnerability reports to a historical record that corresponds to the application, the historical record including previously collected vulnerability reports; determining metrics for the application by using the corresponding historical record; generating a drift summary for the application based on the determined metrics and the corresponding historical record; comparing the drift summary with a previously generated drift summary to identify changes, the changes relating to a vulnerability status; and generating a drift report for the application based on the identified changes.Type: GrantFiled: May 3, 2023Date of Patent: March 31, 2026Assignee: JPMORGAN CHASE BANK, N.A.Inventors: Sean Kilgallon, Shazia Khan