Patents Examined by Sameera Wickramasuriya
  • Patent number: 12688313
    Abstract: Disclosed are methods, controllers, and computer-readable media that explicitly label data packets and interfaces as trusted or untrusted. The data packet labeling can occur at a centralized security hub or at the enforcement site itself, i.e., at the interface to the trusted or untrusted region. The packet can be labeled with metadata associated with the packet, and that label can be carried through the transport of the packet to avoid overbroad or unnecessary security procedures. Further, a network administrator can designate certain links as trusted or untrusted so that packets designated as trusted can be sent down trusted links, and untrusted traffic can be sent down untrusted links. Network resources are saved while traffic is better separated and allocated down links with trustworthiness that is congruent with that of the packet.
    Type: Grant
    Filed: June 25, 2024
    Date of Patent: July 21, 2026
    Assignee: Cisco Technology, Inc.
    Inventors: Pritam Baruah, Amjad Inamdar, Avinash Shah, Sagar Soni, Hari Krishna Donti
  • Patent number: 12683973
    Abstract: An exemplary system having a processor and a memory therein includes means for creating an isolation group, in which creating the isolation groups includes: defining isolation requirements, identifying a group of features utilizing call-out functions, and selecting from among the group of features utilizing call-out functions a group of features having the defined isolation requirements; deploying platform software integrating the isolation requirements, in which the platform software contains instructions to map the isolation requirements to a customer organization; creating the customer organization; creating a unique variant of the customer organization, in which creating the unique variant of the customer organization includes declaratively applying an isolation layer containing isolation requirements on top of a base layer for the customer organization; and deploying the unique variant of the customer organization onto the customer organization's computing infrastructure, in which the unique variant vali
    Type: Grant
    Filed: December 27, 2023
    Date of Patent: July 14, 2026
    Assignee: Salesforce, Inc.
    Inventors: Ryan Guest, Theresa Vietvu, Bradley Vine, Sean Gill, Ricardo Vazquez Reyes
  • Patent number: 12683960
    Abstract: Methods, systems, and apparatuses are described herein for improving the accuracy of authentication questions using e-mail processing. A request for access to an account may be received from a user device. A plurality of organizations may be identified. One or more e-mail associated with the account may be identified. The e-mails may be processed to identify one or more organizations that correspond to transactions conducted by a user. A modified plurality of organizations may be generated by removing, from the plurality of organizations, the one or more organizations. An authentication question may be generated and provided to the user device. A response to the authentication question may be received, and the user device may be provided access based on the response.
    Type: Grant
    Filed: September 13, 2024
    Date of Patent: July 14, 2026
    Assignee: Capital One Services, LLC
    Inventors: Viraj Chaudhary, Vyjayanthi Vadrevu, Tyler Maiman, David Septimus, Samuel Rapowitz, Jenny Melendez, Joshua Edwards
  • Patent number: 12671705
    Abstract: A process includes prioritizing candidate network traffic flow profiles. The prioritization includes associating perception scores with respective candidate network traffic flow profiles. Each candidate network traffic flow profile is a member of a profile group of a plurality of profile groups. The process includes associating weights with respective profile groups of the plurality of categories. The process includes, responsive to a network traffic flow, identifying, by a traffic analysis engine, a first observed profile of the network traffic flow corresponding to a first candidate network traffic flow profile. The process includes, based on the perception score associated the first candidate network traffic flow profile and the weight associated with the profile group in which the first candidate network traffic flow profile is a member, determining a policy score; and selecting, by the network analysis engine, a policy to be applied to the network traffic flow based on the policy score.
    Type: Grant
    Filed: April 28, 2023
    Date of Patent: June 30, 2026
    Assignee: Hewlett Packard Enterprise Development LP
    Inventors: Nirmal Rajarathnam, Navaneethan Venugopal, Bhagvan Cheeyandira
  • Patent number: 12652316
    Abstract: A computer-implemented method, according to one embodiment, includes analyzing a deployment plan for an instance of Infrastructure as Code (IaC) code to identify a plurality of milestones of the deployment plan, and creating access policies for the identified milestones. The method further includes monitoring milestone state logs during an execution of the instance of IaC code for occurrence of predetermined milestone events. In response to a determination that a first of the predetermined milestone events has occurred, first user device access permissions are adjusted based on the created access policies. A computer program product, according to one embodiment, includes a computer readable storage medium having program instructions embodied therewith. The program instructions are readable and/or executable by a processing circuit to cause the processing circuit to perform the foregoing method.
    Type: Grant
    Filed: August 1, 2023
    Date of Patent: June 9, 2026
    Assignee: International Business Machines Corporation
    Inventors: Hari Krishna Arla, Albee Jhoney, Praveen Kumar Gostu, Athreya Ks, Rajesh Kumar Pirati
  • Patent number: 12647426
    Abstract: Techniques for managing an access privilege for users of an organization having first and second tenants includes storing, at a data storage, first user account data of a first user account associated with a first user of the first tenant, the first user account data including a first object identifier, a first tenant identifier and first access privilege information including access privileges granted to the first user account of the first tenant to access one or more resources; creating, for the first user associated with the first tenant, a second user account of the second tenant and second user account data of the second user account; setting the second user account data to include linked account information including the first object identifier and the first tenant identifier of the first user account data; and storing, at the data storage, the second user account data including the linked account information.
    Type: Grant
    Filed: September 13, 2022
    Date of Patent: June 2, 2026
    Assignee: Microsoft Technology Licensing, LLC
    Inventors: Ariel Gordon, Somak Bhattacharyya, Manish Shukla
  • Patent number: 12640931
    Abstract: A method for extending a blockchain includes, at a space server in a distributed network: storing a plot file. The method also includes accessing a blockchain: during a current slot in the series of slots, accessing a proof-of-space challenge based on a current slot challenge associated with the current slot and a challenge chain signage point; in response to accessing the proof-of-space challenge, retrieving a proof-of-space based on the proof-of-space challenge and the plot file; calculating a quality-based number of iterations based on the quality of the proof-of-space; generating a block comprising the proof-of-space, the challenge chain signage point, and a reward chain signage point; and broadcasting the block to the distributed network.
    Type: Grant
    Filed: December 19, 2024
    Date of Patent: May 26, 2026
    Assignee: Chia Network Inc.
    Inventors: Bram Cohen, Krzysztof Pietrzak, Mariano Sorgente
  • Patent number: 12627671
    Abstract: In one embodiment, a method may access a plurality of Industrial Internet of Things (IIoT) devices within a network. The method may determine a shared risk model associated with the plurality of IIoT devices within the network. The method may determine, using the shared risk model, a shared risk value for each of the plurality of IIoT devices within the network. The method may determine, using the shared risk model, a plurality of associated clusters of IIoT devices within the network based on the shared risk value for each of the plurality of IIoT devices within the network. The method may determine an associated risk minimization for each of the plurality of IIoT devices within the network based on the plurality of associated clusters of IIoT devices within the network and the shared risk value for each of the plurality of IIoT devices within the network.
    Type: Grant
    Filed: August 3, 2023
    Date of Patent: May 12, 2026
    Assignee: Cisco Technology, Inc.
    Inventors: Navdeep Sood, Praveen Kumar
  • Patent number: 12615261
    Abstract: A system and method for enabling fine-grained access to enterprise applications in an enterprise network. The method includes receiving, via a discovery application running on a computing device, user input from a user, where the user input identifies at least one of an application name, a server name, or an Internet Protocol (IP) address associated with a computing resource for accessing an enterprise application; comparing, via the discovery application, the user input to application information stored in a database accessible by the discovery application; sending, via the discovery application, a message to the user in response to determining a match between the user input and the application information, where the message identifies a membership group containing the computing resource for accessing the enterprise application; and enabling the user to access the membership group using the computing resource when the user is a member of the membership group.
    Type: Grant
    Filed: November 17, 2023
    Date of Patent: April 28, 2026
    Assignee: T-Mobile Innovations LLC
    Inventors: John Hassler, Sindhu Kakarla, Onn Lin Lee, Kevin Kwok Leung
  • Patent number: 12608483
    Abstract: A current a version of an external component (e.g., an open-source component or a third-party component) that is used in a software application is identified. A new version of the current version of the external component is identified (supply chain components). For example, the new version may have been just released by an open-source community. In response to identifying the new version of the current version of the of the external component, a series of actions are implemented that include: identifying changes to Application Programming Interfaces (APIs) in the new version of the current version of the external component; identifying new vulnerabilities in the new version of the current version of the external component; and determining a quality history associated with the new version of the current version of the external component. Based on the actions, a composite score is generated and displayed to a developer.
    Type: Grant
    Filed: December 12, 2022
    Date of Patent: April 21, 2026
    Assignee: Micro Focus LLC
    Inventors: Douglas Max Grover, Michael F. Angelo, Baha Masoud, Alexander Hoole, Carl Emil Orm Wareus
  • Patent number: 12592837
    Abstract: Techniques are disclosed relating to determining identity information of a user associated with a blockchain address. An application of a first user can receive information indicative of a blockchain address of a second user. This information either includes or is usable to retrieve a certificate of the second user, which is signed by a private key of a certificate authority (CA), and which includes identity information of the second user. The application of the first user can verify the certificate using a public key of the CA. The application of the first user can then cause identity information of the second user to be included in a user interface presented to the first user. This information allows the first user to have more information about the second user before commencing an irreversible blockchain transaction with that user.
    Type: Grant
    Filed: March 11, 2022
    Date of Patent: March 31, 2026
    Assignee: PayPal, Inc.
    Inventor: Ben Riva
  • Patent number: 12580894
    Abstract: Systems and methods for a Hypertext Transfer Protocol Secure (HTTPS) proxy service include monitoring traffic via a cloud, the traffic being monitored inline between one or more endpoints and one or more destinations; performing a mutual TLS (mTLS) handshake with an endpoint of the one or more endpoints based on a request to a destination of the one or more destinations; deriving endpoint information based on the mTLS handshake; and performing one or more actions on the request based on the endpoint information.
    Type: Grant
    Filed: February 29, 2024
    Date of Patent: March 17, 2026
    Assignee: Zscaler, Inc.
    Inventor: Yaroslav Rosomakho
  • Patent number: 12567105
    Abstract: Techniques are described herein for deactivating a secured transfer medium of an entity. The secured transfer medium of the entity can be identified based at least on the secured transfer medium having a closed status. Based on the secured transfer medium, a secured location at which a portion of entity resources is reserved can be determined. The entity can provide the reserved entity resources to obtain the secured transfer medium. The reserved entity resources can be returned at least in part to the entity as part of deactivating the secured transfer medium. A return process to return at least a subset of the reserved entity resources to the entity can be initiated. The secured transfer medium can be deactivated such that the entity is unable to access system resources using the secured transfer medium.
    Type: Grant
    Filed: January 22, 2025
    Date of Patent: March 3, 2026
    Assignee: The Huntington National Bank
    Inventors: Kateryna Shyshkova, Harmeet S. Soin, Jatin Patel, James P. Fairall
  • Patent number: 12549386
    Abstract: Embodiments of the present disclosure relate to a method, device, apparatus and computer readable medium for certificate updates. According to embodiments of the present disclosure, a first device receives information of at least one network function. The information at least comprises certificate information of the at least one network function. The first device determines a schedule for triggering certificate update for the at least one network function using an artificial intelligence/machine learning (AI/ML) model on the first device. The first device triggers a certificate update procedure for the at least one network function according to the determined schedule. In this way, it can avoid overload in the system due to bulk certificate updates happening simultaneously.
    Type: Grant
    Filed: April 22, 2022
    Date of Patent: February 10, 2026
    Assignee: Nokia Technologies Oy
    Inventors: Rakshesh Pravinchandra Bhatt, Pramod P Pillai
  • Patent number: 12549688
    Abstract: Introduced here is a surveillance system that is able to employ an approach to sharing security information, such that organizations have the ability to voluntarily share relevant security information with the individuals who frequent the corresponding buildings. The surveillance system introduced here may not only be able to protect the safety of organizations, but also the privacy of users. In order for a member of the public to truly feel safe—not only from material loss or bodily harm—it is crucial for her to know what information is being recorded, stored, and used.
    Type: Grant
    Filed: May 16, 2023
    Date of Patent: February 10, 2026
    Assignee: Verkada Inc.
    Inventors: Karl Erik Gustav Rehnby, Julia Lin, Arjun Krishnaiah, Matthew Timothy Bornski
  • Patent number: 12547746
    Abstract: A server computer system is configured to forward secure data. The system stores secure data in a database. Each unit of secure data for which the system supports forwarding is associated with a respective token. The system receives from a first server, a request comprising at least: an indicator associated with a secure data, a destination indicator, a first API key, a second API key, and a body having a predefined data format. The system validates the request based on the first API key, references the database to obtain the secure data based on the indicator and the respective token, and populates the body with the secure data. Once populated, the system transmits a second request comprising the second API key and the populated body to a second server, based on the destination indicator.
    Type: Grant
    Filed: June 24, 2024
    Date of Patent: February 10, 2026
    Assignee: Stripe, Inc.
    Inventors: Venil Loyd Noronha, Angel Samsuddin Maredia, Tushar Dhoot, Bryan Berg, Daniel James Cobb, Joyce Zhang, Matthew Jeffryes, Ben Dong, Frank Yu
  • Patent number: 12537796
    Abstract: Aspects of the present application relate to systems and methods for automated web-based filter tuning. The method can include receiving information characterizing a plurality of attributes of a web server and normalizing the received information. The method can include identifying a set of relevant tags to the web server via comparison of the normalized received information to data contained in a tag database, and forming a set of signatures relevant to the web server based at least in part on the set of relevant tags. The method can include receiving an administrator selection of at least some of the set of signatures, enabling the selected at least some of the set of signatures for filtering of received web requests.
    Type: Grant
    Filed: December 21, 2020
    Date of Patent: January 27, 2026
    Assignee: Oracle International Corporation
    Inventors: Alexandre Vincent Laplume, Marcos Negreira, Leonid Kuperman, Michael Levin, Jorge Luis Espinoza Calderon
  • Patent number: 12519807
    Abstract: A relay device includes a first input/output unit (111), a second input/output unit (112), a security monitoring unit (121) that determines whether or not a packet input to the first input/output unit (111) or the second input/output unit (112) is normal, and a relay unit (113) that outputs a packet determined to be normal by the security monitoring unit (121) from the first input/output unit (111) or the second input/output unit (112); the security monitoring unit (121) uses a whitelist to perform whitelist-based attack detection to determine whether or not a packet is normal, and uses a learning model learned through machine learning to perform machine-learning-based attack detection on a packet that is not determined to be normal through the whitelist-based attack detection, to determine whether or not the packet is normal.
    Type: Grant
    Filed: January 15, 2020
    Date of Patent: January 6, 2026
    Assignee: MITSUBISHI ELECTRIC CORPORATION
    Inventors: Tatsunori Minami, Teruyoshi Yamaguchi
  • Patent number: 12513152
    Abstract: A method which performs, inter alia, the following: performing a login process at a web page for a first user, wherein the first user is assigned an identifier; performing a digital object generation process based on data entered by the first user at the web page, wherein the data includes an indication of an amount of a resource and a time period, and wherein the digital object includes the identifier and the indication of the amount of the resource and the time period.
    Type: Grant
    Filed: October 13, 2022
    Date of Patent: December 30, 2025
    Assignee: EPLAN GMBH & CO. KG
    Inventors: Frank Engler, Phillip Falkenhagen
  • Patent number: 12494918
    Abstract: Devices, systems, and processes are described for re-imaging image data on a client device. A process may include establishing, by a client device, a communications link with a server; communicating an image data request to the server; wherein the image data request identifies a first Image Data Segment (1IDS) in an Image Data Volume (IDV); receiving a 1IDS packet from the server; decompressing the 1IDS packet; identifying a first header and a 1IDS in the 1IDS packet; decrypting the first header and the 1IDS; identifying a first signature in the decrypted first header; first calculating a third signature for the decrypted 1IDS; comparing the first signature to the third signature; and accepting, when the first signature matches the third signature, the 1IDS for non-transient storage on a computer readable medium for the client device. The process may include second calculating a total signature for the 1IDS packet.
    Type: Grant
    Filed: June 10, 2022
    Date of Patent: December 9, 2025
    Assignee: DISH Network L.L.C.
    Inventors: Geoffrey Charles Kemp, Fred Earl Starks, Mary Abigale Strebel