Patents Examined by Rupal Dharia
  • Patent number: 12724868
    Abstract: A method of starting up and managing an offline control device with a management control unit and a terminal, includes: implementing of a multi-factor/ID authentication algorithm in the terminal; delivering the terminal and a first storage medium having a storage medium ID and a first security code to a customer; delivering of a second security code generated using the first security code, to a second storage medium of the customer; positioning, by a user, of the first and second storage mediums at the terminal and reading of the storage medium ID and the first and second security codes, and offline checking by the algorithm of the terminal, whether the read first and second security codes are valid with one another; after a positive multi-factor authentication check, storing the storage medium ID as the authorization ID and the first security code in the terminal; and terminating the initial start-up mode.
    Type: Grant
    Filed: December 21, 2022
    Date of Patent: September 1, 2026
    Assignee: Sphinx Electronics GmbH & Co KG
    Inventors: Trong-Nghia Cheng, Reinhard Eggert, Pascal Bodechon
  • Patent number: 12719910
    Abstract: An Information Handling System (IHS), such as a workspace orchestration service IHS, observes location information of a device, and receives location information logged by the device. The observed location information may include telemetry of the device, and/or the received device-logged location information may include below-OS telemetry of the device The IHS correlates the observed location information with the received device-logged location information, and adjusts a security score of the device in accordance with the resulting correlation. Where the device is a workspace instantiation client IHS, the logged location information is logged by the workspace, and the security score is the security score of the workspace. Also, the workspace orchestration service IHS may build a definition for the workspace, that includes one or more localized entitlements for the workspace, or may build the workspace definition to include remediation action, based on the location information and/or adjusted security score.
    Type: Grant
    Filed: January 20, 2023
    Date of Patent: August 25, 2026
    Assignee: Dell Products L.P.
    Inventors: Nicholas D. Grobelny, Girish S. Dhoble, Joseph Kozlowski
  • Patent number: 12719864
    Abstract: In some implementations, a cloud management device may receive, from a user device, a configuration associated with a task for cloud computing. The cloud management device may input one or more properties, associated with the configuration, to a model that is trained on historical cloud computing task information. Accordingly, the cloud management device may receive, from the model, an indication of a selected cloud environment, from a plurality of possible cloud environments based on credentials associated with the user device. The cloud management device may generate instructions for the task based on the selected cloud environment and may trigger execution of the task by the selected cloud environment using the instructions.
    Type: Grant
    Filed: December 9, 2022
    Date of Patent: August 25, 2026
    Assignee: Capital One Services, LLC
    Inventors: Pooja Mulik, Suyog Parajuli, Gita Antoinette Lourdes, Nikhil Agarwal, Prasanth Jain
  • Patent number: 12719677
    Abstract: A device and a network can authenticate using a subscription concealed identifier (SUCI). The device can store (i) a plaintext subscription permanent identifier (SUPI) for the device, (ii) a network static public key, and (iii) a key encapsulation mechanism (KEM) for encryption using the network static public key. The network can store (i) a device database with the SUPI, (ii) a network static private key, and (iii) the KEM for decryption using the network static private key. The device can (i) combine a random number with the SUPI as input into the KEM to generate a ciphertext as the SUCI, and (ii) transmit the ciphertext/SUCI to the network. The network can (i) decrypt the ciphertext using the KEM to read the SUPI, (iii) select a key K from the device database using the SUPI, and (iv) conduct an Authentication and Key Agreement (AKA) with the selected key K.
    Type: Grant
    Filed: December 4, 2023
    Date of Patent: August 25, 2026
    Assignee: Adeia Emerging Technologies Inc.
    Inventor: John A. Nix
  • Patent number: 12712731
    Abstract: Apparatus and methods for prime field modular reduction are described. As an example, a custom modular reduction digital circuit for reducing an n-bit integer based on a modulus, where the modulus comprises a k-bit integer for use with a cryptographic algorithm, is described. The custom modular reduction digital circuit includes a first circuit to generate at least two partial results by processing: (1) k lower order significant bits of the n-bit integer and (2) at least a subset of bits for congruent representations corresponding to any n-k higher order bits of the n-bit integer that are higher in significance than the most significant bit of the k-bit integer. The custom modular reduction digital circuit further includes a second circuit to process the at least two partial results, output by the first circuit, to generate a reduced version of the n-bit integer for use with the cryptographic algorithm.
    Type: Grant
    Filed: November 3, 2023
    Date of Patent: August 18, 2026
    Assignee: Microsoft Technology Licensing, LLC
    Inventor: Jay Scott Fuller
  • Patent number: 12706919
    Abstract: A system can receive, from a remote computer, request data that identifies a request associated with a user account for credentials that are configured to access a computing resource, wherein the request data comprises a concealed value, and wherein the concealed value comprises a deployment public key that is concealed with an ephemeral secret key. The system can unlock the concealed value using a vendor secret key corresponding to the user account, to produce an unlocked concealed value. The system can send the unlocked concealed value to the remote computer, enabling the remote computer to determine a data encryption key based on processing the unlocked concealed value using the ephemeral secret key, enabling the remote computer to decrypt encrypted break-glass credentials using the data encryption key to produce break-glass credentials, and enabling the remote computer to access the computing resource using the break-glass credentials.
    Type: Grant
    Filed: September 29, 2023
    Date of Patent: August 11, 2026
    Assignee: Dell Products L.P.
    Inventors: Seema M. Tahaliyani, Yuanyuan Zhang, Ananthakrishnan Balakrishnan
  • Patent number: 12705371
    Abstract: Point-in-Time data access authorization is realized by a data access broker and data access security manager that provide for a data owner/authorizer to provide access consent at the point in time at which a specific data access request is made, without the need for the data owner to share their service-specific access credentials with the third-party entity/data requester. As a result, the data owner has control over the authorization of each data access request and has knowledge as to when the third-party entity is accessing the data. Further, by not having to share access credentials with the third-party entity/data requester security issues related to exposure and/or misuse of the access credentials are avoided.
    Type: Grant
    Filed: November 4, 2022
    Date of Patent: August 11, 2026
    Assignee: BANK OF AMERICA CORPORATION
    Inventors: Gregory Allen Burkett, Brady Prentice Merkel, David E. Strommer
  • Patent number: 12695606
    Abstract: An encryption key is created, and sensitive security data is sourced from it and from live data collected in real-time from a user context by a group functions. Subsequently, indicators to functions are stored and the encryption key with the sensitive security data is deleted. Redundancy is provided so that the decryption key can be created from different combinations of functions. A decryption key is later generated with sensitive security data using one or more stored indicators of the one or more functions to obtain an instance of live data in real-time from a current user context. Failing to generate the correct decryption key will result in repeating the creation of the decryption key with different groups of functions until access is granted or combinations of redundant stored functions are exhausted.
    Type: Grant
    Filed: June 13, 2023
    Date of Patent: July 28, 2026
    Inventor: Nicolas Leoutsarakos
  • Patent number: 12682126
    Abstract: Systems, methods, and apparatuses relating to an instruction that allows a trusted execution environment to react to an asynchronous exit are described. In one embodiment, a hardware processor includes a register comprising a field, that when set, is to enable an architecturally protected execution environment for code in an architecturally protected enclave in memory, a decoder circuit to decode a single instruction comprising an opcode into a decoded instruction, the opcode to indicate an execution circuit is to invoke a handler to handle an asynchronous exit from execution of the code in the architecturally protected enclave and then resume execution of the code in the architecturally protected enclave from where the asynchronous exit occurred, and the execution circuit to respond to the decoded instruction as specified by the opcode.
    Type: Grant
    Filed: December 26, 2020
    Date of Patent: July 14, 2026
    Assignee: Intel Corporation
    Inventors: Scott Constable, Mark Shanahan, Mona Vij, Bin Xing, Krystof Zmudzinski
  • Patent number: 12671576
    Abstract: A method for secure aggregation, by a server, of client-provided inputs includes receiving, from each of a plurality of clients, a respective client input, for which a commitment is published. The commitments were computed using randomness and are aggregated by at least two super-clients and a sum of the aggregated commitments is published by each super-client. A sum of the received client inputs is published such that validity of the sum is checkable, by the clients, by comparing the sum of the received client inputs to a verification algorithm result that uses a sum of additive shares computed by the clients using the randomness, and by verifying that the published sum of the aggregated commitments is the same for each super-client. The method can be applied to use cases, for example, in digital medicine using medical data or smartcity applications to support decision-making.
    Type: Grant
    Filed: October 5, 2023
    Date of Patent: June 30, 2026
    Assignee: NEC CORPORATION
    Inventors: Claudio Soriente, Giorgia Marson
  • Patent number: 12671680
    Abstract: A computer-implemented method includes: receiving, via a computing device, a login request for a resource account; authenticating a user associated with the login request to an account session of the resource account; receiving, via the computing device during the account session, a trade request for performing a first trading action in connection with a tradeable object; in response to receiving the trade request: granting time-limited access to an account operation for the resource account, the first account operation associated with defined first trade parameters for the first trading action; receiving user input for initiating the first account operation at a first time; validating the first account operation based on verifying eligibility of the first trading action and validity of the account session at the first time; and in response to validating the first account operation, cause the first trading action to be executed based on processing the first account operation.
    Type: Grant
    Filed: May 6, 2022
    Date of Patent: June 30, 2026
    Assignee: The Toronto-Dominion Bank
    Inventors: Lauren Erica Miele, Adam Judson, James Wolanski
  • Patent number: 12666255
    Abstract: Systems and methods for selective User Plane protection in a 5G virtual RAN are provided. A method performed by a gNB Central Unit (gNB-CU) for communicating with a gNB-Distributed Unit (gNB-DU) includes determining whether to selectively encrypt a PDU to be sent to the gNB-DU if the PDU is not otherwise encrypted. In response to determining to selectively encrypt, the method includes encrypting the PDU to be sent to the gNB-DU. In response to determining to not selectively encrypt, the method includes passing the PDU to be sent to the gNB-DU. In this way, additional security is provided while performance impact is minimized. In some embodiments, this provides a lower overhead on the gNB-CU-UP side compared to applying a generic protection of all PDUs. Additionally, the latency overhead is limited since a secure session establishment and handshake is confined to the gNB-CU-UP-SEG domain instead of gNB-CU-UP to gNB-DU.
    Type: Grant
    Filed: March 18, 2020
    Date of Patent: June 23, 2026
    Assignee: Telefonaktiebolaget LM Ericsson (publ)
    Inventors: Stere Preda, Daniel Migault, Amine Boukhtouta, Xiaowen Yue
  • Patent number: 12665744
    Abstract: A cryptographic computer processes a word of p bits in an electronic message as a set of k n-state elements with n an integer greater than 2 and 2{circumflex over (?)}p>n and k>1, with the p bits being characterized as a word of k n-state elements. The computer processes two words of k n-state elements as an radix-n operation that includes a 2 operand reversible n-state operation of which an output is a residue and a 2 operand n-state transition function of which an output is an n-state transition element. An output of the radix-n operation is a word of k n-state elements. The radix-n operation is preferably not reversible and is part of an operation that generates a cryptographic message. A standard cryptographic operation is modified by applying the radix-n operation. The cryptographic message is transmitted over a physical channel.
    Type: Grant
    Filed: October 7, 2024
    Date of Patent: June 23, 2026
    Inventor: Peter Lablans
  • Patent number: 12665761
    Abstract: Systems and methods for performing mutual authentication between a hardware access token and a reader device are provided. The systems and methods include reading a unique or pseudo-unique identifier of the hardware access token and computing a password for the hardware access token based on the unique or pseudo-unique identifier and a group secret of the reader device.
    Type: Grant
    Filed: June 28, 2021
    Date of Patent: June 23, 2026
    Assignee: MOZARC MEDICAL US LLC
    Inventors: Arindam Ghosh Roy, Sharath Nagendra
  • Patent number: 12665899
    Abstract: An authentication method and an electronic device. The method includes sending, by a first device, in response to a first device determining that a distance between the first device and a second device reaches a first distance, a first request to the second device, so that the second device determines whether wireless communication between the first and second device is relayed before the first device performs a service, determining, in response to the distance between the first and second device reaching a second distance, whether success ciphertext sent by the second device is received, wherein the success ciphertext is sent in response to the second device determining that wireless communication between the first and second device is not relayed and the second distance being less than the first distance, and performing the service in response to reception and successful verification of the success ciphertext.
    Type: Grant
    Filed: December 16, 2020
    Date of Patent: June 23, 2026
    Assignee: Huawei Technologies Co., Ltd.
    Inventors: Zhuofei Li, Wei Gao
  • Patent number: 12665769
    Abstract: Technology related to authentication using an intermediary is disclosed. In one example, a method for authentication can include intercepting a first authentication response destined for a server. The first authentication response identifies a server authentication service and is digitally signed by an identity service provider. The first authentication response can be authenticated using a cryptographic key of the identity service provider to validate an identity service provider signature included in the first authentication response. In response to validating the identity service provider signature, a second authentication response can be sent to the server that identifies the server authentication service.
    Type: Grant
    Filed: August 9, 2019
    Date of Patent: June 23, 2026
    Assignee: F5, Inc.
    Inventors: Michael James Coleman, II, Graham Rein Alderson, Charlie Wilson Lesley, III
  • Patent number: 12657349
    Abstract: Encrypting keystroke data in a multi-session-enabled computing device includes receiving a first control message requesting enabling of keystroke encryption for a protected application executing in a first desktop session. The first control message includes application identification information of the protected application. Keystroke encryption is enabled for keystrokes targeting the first desktop session based on receipt of the first control message. Keystroke data sent to the protected application is encrypted while the protected application maintains keyboard focus in the first desktop session. Unencrypted keystroke data is transmitted to another application of a second desktop session while keystroke encryption is enabled for the protected application in the first desktop session.
    Type: Grant
    Filed: September 15, 2023
    Date of Patent: June 16, 2026
    Assignee: Omnissa, LLC
    Inventors: Xiaoyu Kong, YiQun Yun, ZhangLin Zhou, Yang Yu
  • Patent number: 12659152
    Abstract: A system includes a memory configured to store a set of private valid source data. The system includes processors operably coupled to the memory and configured to access the set of private valid source data, and to execute a dynamic data encryption engine configured to identify a sensitivity level of the set of private valid source data and to encrypt the set of private valid source data in accordance with a data encryption algorithm. The data encryption algorithm is selected based on the identified sensitivity level. The processors further execute a data ingestion and dynamic decryption engine configured to ingest the encrypted set of private valid source data into the hybrid cloud computing and storage system, and in response to receiving a request to retrieve the encrypted set of private valid source data from the hybrid cloud computing and storage system, decrypt the encrypted set of private valid source data.
    Type: Grant
    Filed: June 26, 2024
    Date of Patent: June 16, 2026
    Assignee: Bank of America Corporation
    Inventors: Bikash Dash, Meera Lakshmi
  • Patent number: 12659153
    Abstract: Intelligent functionality enablement techniques are disclosed. In one example, a method comprises obtaining a functionality enablement file comprising at least a first block and a second block, wherein the first block is usable to activate one or more features of a product and the second block is usable to perform a configuration setup to enable the product to operate in accordance with at least one computing platform.
    Type: Grant
    Filed: May 8, 2023
    Date of Patent: June 16, 2026
    Assignee: Dell Products L.P.
    Inventor: Shibi Panikkar
  • Patent number: 12647436
    Abstract: A machine learning (ML) attack detection and prevention system may monitor operation of an explainable artificial intelligence (AI) model processed by an application server to provide a product or service to a user. The AI model outputs explainable data and/or other outputs used in decision making. The ML attack detection and prevention system derives business rules based on the explainable data produced by the explainable AI model. Additionally, the ML attack detection and prevention system processes rules repositories of simulation failure data, historical failure data and business rules to derive possible fraud rules based on the data collected in above step. Based on a comparison of rules derived from the AI model output and the possible fraud rules, the ML attack detection and prevention system issues an alert if a fraud condition is suspected and causes the application server to revert back to a previous version of the AI model.
    Type: Grant
    Filed: February 24, 2022
    Date of Patent: June 2, 2026
    Assignee: Bank of America Corporation
    Inventor: Vijay Kumar Yarabolu