Patents Examined by Rupal Dharia
-
Patent number: 12744768Abstract: Systems and methods for connecting users in an extended reality setting are provided. One embodiment includes creating a private group for an extended reality session, registering a facility user for the private group and a first user identifier for the facility user, and registering a first device to link to the facility user. Some embodiments include registering a first user for the private group and a second user identifier for the first user, registering a second device to link to the first user, and receiving a request from a device of a possible user to join the session. Still some embodiments include retrieving a security certificate from the device, determining whether the security certificate corresponds, and in response to determining that the security certificate corresponds granting access to the possible user to the extended reality session. In response to determining that the security certificate does not correspond, denying access.Type: GrantFiled: August 23, 2022Date of Patent: September 22, 2026Inventor: Richard Hoagland
-
Patent number: 12744660Abstract: The present invention backs up a sensitive field in a data object in a storage system using an external backup system without enabling the external backup system to view the data in the sensitive field. The system sets up the sensitive field for backup by adding an encrypted field to a data object that includes the sensitive field, configuring access to the sensitive field and the encrypted field, creating an encrypted copy of the data in the sensitive field with an encryption key controlled by the data owner, and storing the encrypted copy in the encrypted field. The system backs up the sensitive field without enabling the external backup system to view the data in the sensitive field by sending the encrypted copy in the encrypted field to the external backup system, where the external backup system has no access to the encryption key controlled by the data owner.Type: GrantFiled: November 30, 2022Date of Patent: September 22, 2026Assignee: Odaseva Technologies SASInventors: Sovane Bin, Saddek Dekoum, Remi Poujeaux, Arnaud Deronne, Francois Lopitaux, Arnaud Treps
-
Patent number: 12743534Abstract: Managing versioning of data objects for a project revised from a first version to a revised version by producing a dataset representing the data objects as a group by scanning the data objects to identify metadata of the grouped data to be processed similarly within a current version of the lifecycle, and storing the identified metadata in the dataset. Data object changed from the first version to the revised version are identified, and the corresponding metadata for changed data objects in the dataset is updated. A version control operation is then performed on the dataset to update all data objects referenced by the dataset from the first version to the revised version. A commit-map and commit-tree are stored in a repository, and version control operations including commit, checkout, merge, branch and merge-branch are performed on the dataset snapshot.Type: GrantFiled: October 28, 2022Date of Patent: September 22, 2026Assignee: Dell Products L.P.Inventors: Adam Brenner, Jehuda Shemer, Steven Sadhwani, Valerie Lotosh, Erez Sharvit
-
Patent number: 12724868Abstract: A method of starting up and managing an offline control device with a management control unit and a terminal, includes: implementing of a multi-factor/ID authentication algorithm in the terminal; delivering the terminal and a first storage medium having a storage medium ID and a first security code to a customer; delivering of a second security code generated using the first security code, to a second storage medium of the customer; positioning, by a user, of the first and second storage mediums at the terminal and reading of the storage medium ID and the first and second security codes, and offline checking by the algorithm of the terminal, whether the read first and second security codes are valid with one another; after a positive multi-factor authentication check, storing the storage medium ID as the authorization ID and the first security code in the terminal; and terminating the initial start-up mode.Type: GrantFiled: December 21, 2022Date of Patent: September 1, 2026Assignee: Sphinx Electronics GmbH & Co KGInventors: Trong-Nghia Cheng, Reinhard Eggert, Pascal Bodechon
-
Patent number: 12719910Abstract: An Information Handling System (IHS), such as a workspace orchestration service IHS, observes location information of a device, and receives location information logged by the device. The observed location information may include telemetry of the device, and/or the received device-logged location information may include below-OS telemetry of the device The IHS correlates the observed location information with the received device-logged location information, and adjusts a security score of the device in accordance with the resulting correlation. Where the device is a workspace instantiation client IHS, the logged location information is logged by the workspace, and the security score is the security score of the workspace. Also, the workspace orchestration service IHS may build a definition for the workspace, that includes one or more localized entitlements for the workspace, or may build the workspace definition to include remediation action, based on the location information and/or adjusted security score.Type: GrantFiled: January 20, 2023Date of Patent: August 25, 2026Assignee: Dell Products L.P.Inventors: Nicholas D. Grobelny, Girish S. Dhoble, Joseph Kozlowski
-
Patent number: 12719864Abstract: In some implementations, a cloud management device may receive, from a user device, a configuration associated with a task for cloud computing. The cloud management device may input one or more properties, associated with the configuration, to a model that is trained on historical cloud computing task information. Accordingly, the cloud management device may receive, from the model, an indication of a selected cloud environment, from a plurality of possible cloud environments based on credentials associated with the user device. The cloud management device may generate instructions for the task based on the selected cloud environment and may trigger execution of the task by the selected cloud environment using the instructions.Type: GrantFiled: December 9, 2022Date of Patent: August 25, 2026Assignee: Capital One Services, LLCInventors: Pooja Mulik, Suyog Parajuli, Gita Antoinette Lourdes, Nikhil Agarwal, Prasanth Jain
-
Patent number: 12719677Abstract: A device and a network can authenticate using a subscription concealed identifier (SUCI). The device can store (i) a plaintext subscription permanent identifier (SUPI) for the device, (ii) a network static public key, and (iii) a key encapsulation mechanism (KEM) for encryption using the network static public key. The network can store (i) a device database with the SUPI, (ii) a network static private key, and (iii) the KEM for decryption using the network static private key. The device can (i) combine a random number with the SUPI as input into the KEM to generate a ciphertext as the SUCI, and (ii) transmit the ciphertext/SUCI to the network. The network can (i) decrypt the ciphertext using the KEM to read the SUPI, (iii) select a key K from the device database using the SUPI, and (iv) conduct an Authentication and Key Agreement (AKA) with the selected key K.Type: GrantFiled: December 4, 2023Date of Patent: August 25, 2026Assignee: Adeia Emerging Technologies Inc.Inventor: John A. Nix
-
Patent number: 12712731Abstract: Apparatus and methods for prime field modular reduction are described. As an example, a custom modular reduction digital circuit for reducing an n-bit integer based on a modulus, where the modulus comprises a k-bit integer for use with a cryptographic algorithm, is described. The custom modular reduction digital circuit includes a first circuit to generate at least two partial results by processing: (1) k lower order significant bits of the n-bit integer and (2) at least a subset of bits for congruent representations corresponding to any n-k higher order bits of the n-bit integer that are higher in significance than the most significant bit of the k-bit integer. The custom modular reduction digital circuit further includes a second circuit to process the at least two partial results, output by the first circuit, to generate a reduced version of the n-bit integer for use with the cryptographic algorithm.Type: GrantFiled: November 3, 2023Date of Patent: August 18, 2026Assignee: Microsoft Technology Licensing, LLCInventor: Jay Scott Fuller
-
Patent number: 12706919Abstract: A system can receive, from a remote computer, request data that identifies a request associated with a user account for credentials that are configured to access a computing resource, wherein the request data comprises a concealed value, and wherein the concealed value comprises a deployment public key that is concealed with an ephemeral secret key. The system can unlock the concealed value using a vendor secret key corresponding to the user account, to produce an unlocked concealed value. The system can send the unlocked concealed value to the remote computer, enabling the remote computer to determine a data encryption key based on processing the unlocked concealed value using the ephemeral secret key, enabling the remote computer to decrypt encrypted break-glass credentials using the data encryption key to produce break-glass credentials, and enabling the remote computer to access the computing resource using the break-glass credentials.Type: GrantFiled: September 29, 2023Date of Patent: August 11, 2026Assignee: Dell Products L.P.Inventors: Seema M. Tahaliyani, Yuanyuan Zhang, Ananthakrishnan Balakrishnan
-
Patent number: 12705371Abstract: Point-in-Time data access authorization is realized by a data access broker and data access security manager that provide for a data owner/authorizer to provide access consent at the point in time at which a specific data access request is made, without the need for the data owner to share their service-specific access credentials with the third-party entity/data requester. As a result, the data owner has control over the authorization of each data access request and has knowledge as to when the third-party entity is accessing the data. Further, by not having to share access credentials with the third-party entity/data requester security issues related to exposure and/or misuse of the access credentials are avoided.Type: GrantFiled: November 4, 2022Date of Patent: August 11, 2026Assignee: BANK OF AMERICA CORPORATIONInventors: Gregory Allen Burkett, Brady Prentice Merkel, David E. Strommer
-
Patent number: 12695606Abstract: An encryption key is created, and sensitive security data is sourced from it and from live data collected in real-time from a user context by a group functions. Subsequently, indicators to functions are stored and the encryption key with the sensitive security data is deleted. Redundancy is provided so that the decryption key can be created from different combinations of functions. A decryption key is later generated with sensitive security data using one or more stored indicators of the one or more functions to obtain an instance of live data in real-time from a current user context. Failing to generate the correct decryption key will result in repeating the creation of the decryption key with different groups of functions until access is granted or combinations of redundant stored functions are exhausted.Type: GrantFiled: June 13, 2023Date of Patent: July 28, 2026Inventor: Nicolas Leoutsarakos
-
Patent number: 12682126Abstract: Systems, methods, and apparatuses relating to an instruction that allows a trusted execution environment to react to an asynchronous exit are described. In one embodiment, a hardware processor includes a register comprising a field, that when set, is to enable an architecturally protected execution environment for code in an architecturally protected enclave in memory, a decoder circuit to decode a single instruction comprising an opcode into a decoded instruction, the opcode to indicate an execution circuit is to invoke a handler to handle an asynchronous exit from execution of the code in the architecturally protected enclave and then resume execution of the code in the architecturally protected enclave from where the asynchronous exit occurred, and the execution circuit to respond to the decoded instruction as specified by the opcode.Type: GrantFiled: December 26, 2020Date of Patent: July 14, 2026Assignee: Intel CorporationInventors: Scott Constable, Mark Shanahan, Mona Vij, Bin Xing, Krystof Zmudzinski
-
Patent number: 12671576Abstract: A method for secure aggregation, by a server, of client-provided inputs includes receiving, from each of a plurality of clients, a respective client input, for which a commitment is published. The commitments were computed using randomness and are aggregated by at least two super-clients and a sum of the aggregated commitments is published by each super-client. A sum of the received client inputs is published such that validity of the sum is checkable, by the clients, by comparing the sum of the received client inputs to a verification algorithm result that uses a sum of additive shares computed by the clients using the randomness, and by verifying that the published sum of the aggregated commitments is the same for each super-client. The method can be applied to use cases, for example, in digital medicine using medical data or smartcity applications to support decision-making.Type: GrantFiled: October 5, 2023Date of Patent: June 30, 2026Assignee: NEC CORPORATIONInventors: Claudio Soriente, Giorgia Marson
-
Patent number: 12671680Abstract: A computer-implemented method includes: receiving, via a computing device, a login request for a resource account; authenticating a user associated with the login request to an account session of the resource account; receiving, via the computing device during the account session, a trade request for performing a first trading action in connection with a tradeable object; in response to receiving the trade request: granting time-limited access to an account operation for the resource account, the first account operation associated with defined first trade parameters for the first trading action; receiving user input for initiating the first account operation at a first time; validating the first account operation based on verifying eligibility of the first trading action and validity of the account session at the first time; and in response to validating the first account operation, cause the first trading action to be executed based on processing the first account operation.Type: GrantFiled: May 6, 2022Date of Patent: June 30, 2026Assignee: The Toronto-Dominion BankInventors: Lauren Erica Miele, Adam Judson, James Wolanski
-
Patent number: 12666255Abstract: Systems and methods for selective User Plane protection in a 5G virtual RAN are provided. A method performed by a gNB Central Unit (gNB-CU) for communicating with a gNB-Distributed Unit (gNB-DU) includes determining whether to selectively encrypt a PDU to be sent to the gNB-DU if the PDU is not otherwise encrypted. In response to determining to selectively encrypt, the method includes encrypting the PDU to be sent to the gNB-DU. In response to determining to not selectively encrypt, the method includes passing the PDU to be sent to the gNB-DU. In this way, additional security is provided while performance impact is minimized. In some embodiments, this provides a lower overhead on the gNB-CU-UP side compared to applying a generic protection of all PDUs. Additionally, the latency overhead is limited since a secure session establishment and handshake is confined to the gNB-CU-UP-SEG domain instead of gNB-CU-UP to gNB-DU.Type: GrantFiled: March 18, 2020Date of Patent: June 23, 2026Assignee: Telefonaktiebolaget LM Ericsson (publ)Inventors: Stere Preda, Daniel Migault, Amine Boukhtouta, Xiaowen Yue
-
Patent number: 12665744Abstract: A cryptographic computer processes a word of p bits in an electronic message as a set of k n-state elements with n an integer greater than 2 and 2{circumflex over (?)}p>n and k>1, with the p bits being characterized as a word of k n-state elements. The computer processes two words of k n-state elements as an radix-n operation that includes a 2 operand reversible n-state operation of which an output is a residue and a 2 operand n-state transition function of which an output is an n-state transition element. An output of the radix-n operation is a word of k n-state elements. The radix-n operation is preferably not reversible and is part of an operation that generates a cryptographic message. A standard cryptographic operation is modified by applying the radix-n operation. The cryptographic message is transmitted over a physical channel.Type: GrantFiled: October 7, 2024Date of Patent: June 23, 2026Inventor: Peter Lablans
-
Patent number: 12665761Abstract: Systems and methods for performing mutual authentication between a hardware access token and a reader device are provided. The systems and methods include reading a unique or pseudo-unique identifier of the hardware access token and computing a password for the hardware access token based on the unique or pseudo-unique identifier and a group secret of the reader device.Type: GrantFiled: June 28, 2021Date of Patent: June 23, 2026Assignee: MOZARC MEDICAL US LLCInventors: Arindam Ghosh Roy, Sharath Nagendra
-
Patent number: 12665769Abstract: Technology related to authentication using an intermediary is disclosed. In one example, a method for authentication can include intercepting a first authentication response destined for a server. The first authentication response identifies a server authentication service and is digitally signed by an identity service provider. The first authentication response can be authenticated using a cryptographic key of the identity service provider to validate an identity service provider signature included in the first authentication response. In response to validating the identity service provider signature, a second authentication response can be sent to the server that identifies the server authentication service.Type: GrantFiled: August 9, 2019Date of Patent: June 23, 2026Assignee: F5, Inc.Inventors: Michael James Coleman, II, Graham Rein Alderson, Charlie Wilson Lesley, III
-
Patent number: 12665899Abstract: An authentication method and an electronic device. The method includes sending, by a first device, in response to a first device determining that a distance between the first device and a second device reaches a first distance, a first request to the second device, so that the second device determines whether wireless communication between the first and second device is relayed before the first device performs a service, determining, in response to the distance between the first and second device reaching a second distance, whether success ciphertext sent by the second device is received, wherein the success ciphertext is sent in response to the second device determining that wireless communication between the first and second device is not relayed and the second distance being less than the first distance, and performing the service in response to reception and successful verification of the success ciphertext.Type: GrantFiled: December 16, 2020Date of Patent: June 23, 2026Assignee: Huawei Technologies Co., Ltd.Inventors: Zhuofei Li, Wei Gao
-
Patent number: 12657349Abstract: Encrypting keystroke data in a multi-session-enabled computing device includes receiving a first control message requesting enabling of keystroke encryption for a protected application executing in a first desktop session. The first control message includes application identification information of the protected application. Keystroke encryption is enabled for keystrokes targeting the first desktop session based on receipt of the first control message. Keystroke data sent to the protected application is encrypted while the protected application maintains keyboard focus in the first desktop session. Unencrypted keystroke data is transmitted to another application of a second desktop session while keystroke encryption is enabled for the protected application in the first desktop session.Type: GrantFiled: September 15, 2023Date of Patent: June 16, 2026Assignee: Omnissa, LLCInventors: Xiaoyu Kong, YiQun Yun, ZhangLin Zhou, Yang Yu