Patents Examined by Techane Gergiso
  • Patent number: 12712888
    Abstract: The present disclosure relates to a system, a method, and a non-transitory computer readable storage medium for deep packet inspection scanning at an application layer of a computer. A method of the presently claimed invention may scan pieces of data received out of order without reassembly at an application layer from a first input state generating one or more output states for each piece of data. The method may then identify that the first input state includes one or more characters that are associated with malicious content. The method may then identify that the data set may include malicious content when the first input state combined with one or more output states matches a known piece of malicious content.
    Type: Grant
    Filed: September 17, 2024
    Date of Patent: August 18, 2026
    Assignee: SONICWALL US HOLDINGS INC.
    Inventors: Hui Ling, Cuiping Yu, Zhong Chen
  • Patent number: 12712734
    Abstract: A method of delivering a one-time password to an entity is provided. The entity requesting the one-time password provides a public key of a public-private key pair to the authentication service. The entity can then submit a challenge request to the authentication service. The authentication service will generate a one-time password, and encrypt the one-time password with the public key. The encrypted one-time password is delivered to the entity via an unauthenticated channel.
    Type: Grant
    Filed: August 31, 2023
    Date of Patent: August 18, 2026
    Assignee: Entrust Corporation
    Inventors: Ian Reilly, Emilio Belmonte
  • Patent number: 12712744
    Abstract: Techniques are disclosed relating to securely authenticating communicating devices. In various embodiments, a computing device receives, via a network connection with a network, a first certificate for a first public key pair of the computing device. The computing device provides the first certificate to an offline accessory device and receives a second certificate for a second public key pair maintained by the offline accessory device. The computing device performs a verification of the second certificate and, responsive to the verification being successful, interacts with the offline accessory device. In some embodiments, prior to providing the first certificate, the computing device determines an ordering in which the first and second certificates are to be exchanged by the first computing device and the offline accessory device, and the first certificate is provided to the offline accessory device in accordance with the determined ordering.
    Type: Grant
    Filed: December 13, 2024
    Date of Patent: August 18, 2026
    Assignee: Apple Inc.
    Inventors: Steven A. Myers, Kyle C. Brogle, Sean P. Devlin, Edwin W. Foo, John T. Perry
  • Patent number: 12706759
    Abstract: The present disclosure provides methods, apparatuses and systems for key management and service processing. In one aspect, a method includes receiving, by a authentication server from a trusted execution environment (TEE) of a terminal device, device authentication information through a secure channel between the TEE and the authentication server. The device authentication information is configured to prove an identity of the terminal device. The method includes performing, by the authentication server based on the device authentication information, device authentication on the terminal device. The method further includes in response to determining that the terminal device passes the device authentication, sending, by the authentication server, a service encryption key and a device identity certificate to the TEE through the secure channel.
    Type: Grant
    Filed: July 30, 2024
    Date of Patent: August 11, 2026
    Assignee: Alipay (Hangzhou) Information Technology Co., Ltd.
    Inventors: Xianyi Zheng, Dengwei Xu, Zhi Xin, Xiaofei Wan
  • Patent number: 12706883
    Abstract: A data item is provided to an on-premises proxy service by a peer-to-peer (P2P) client device associated with a video conferencing platform. The P2P client device and the on-premises proxy service are associated with a private network. The data item comprises topological information corresponding to the private network. A transformed version of the data item is received from the on-premises proxy service. The transformed version of the data item obscures the topological information corresponding to the private network. The transformed version of the data item is provided to an external tracking service for a P2P configuration operation. The external tracking service is associated with the video conferencing platform and is external to the private network.
    Type: Grant
    Filed: August 12, 2024
    Date of Patent: August 11, 2026
    Assignee: Google LLC
    Inventors: Alexander Schäfer, Christopher Probst-Ranly, Stefan Lindmark
  • Patent number: 12700052
    Abstract: A cross-certificate method is performed by an electric vehicle (EV) for being supplied with power from electric vehicle supply equipment (EVSE) associated with a charging point operator (CPO) having established a trust relationship with a first vehicle to grid (V2G) root certificate authority (rootCA) and a second V2G root certificate authority. The cross-certificate method may include steps of: requesting charging from the electric vehicle supply equipment; receiving, from the electric vehicle supply equipment, a certificate chain held by the electric vehicle supply equipment; and verifying whether or not a last certificate of the certificate chain has been signed by the second V2G root certificate authority, wherein the last certificate of the certificate chain can be a cross-certificate issued by the second V2G root certificate authority.
    Type: Grant
    Filed: July 22, 2024
    Date of Patent: August 4, 2026
    Assignees: Hyundai Motor Company, Kia Corporation, Myongji University Industry and Academia Cooperation Foundation
    Inventor: Min Ho Shin
  • Patent number: 12701017
    Abstract: Examples of the present disclosure provide an authenticator system that protects secret authentication keys associated with relying parties to which a user is authenticating. Present systems and methods allow cross-platform and cross-device WebAuthn usage. Example systems employ a server-based secure enclave and secure tunnel communication between the browser application or mobile application and the secure enclave server. A user of a service provider of the authenticator system owns the secret authentication key, which is stored in an encrypted vault protected by a user secret and hosted by the service provider. Decrypting the secret key may be based on a key arrangement, where keys from the user, the service provider, and the secure enclave are used to successfully decrypt the secret authentication key within the secure enclave.
    Type: Grant
    Filed: January 19, 2024
    Date of Patent: August 4, 2026
    Assignee: Dashlane SAS
    Inventors: Mohammed Ruhul Islam, Ludovic Widmer, Guillaume Maron, Cyril Leclerc, Corentin Mors, Frédéric Rivain
  • Patent number: 12695599
    Abstract: A method for using cryptographic keys in a vehicle on-board communication network. The method includes, during an initialization of a vehicle-bound power supply time period of a vehicle: generating at least one cryptographic key by a central electronic control unit for the respectively initialized vehicle-bound power supply time period of the vehicle; transferring the generated at least one cryptographic key by the central electronic control unit using at least one cryptographic algorithm to at least one further electronic control unit in the on-board communication network; using the transferred cryptographic key by at least one electronic control unit for at least one further or for the same cryptographic algorithm for a communication between the electronic control units for the duration of the respective initialized vehicle-bound power supply time period in the on-board communication network.
    Type: Grant
    Filed: July 5, 2023
    Date of Patent: July 28, 2026
    Assignee: ROBERT BOSCH GMBH
    Inventor: Stefan Heinrich
  • Patent number: 12675557
    Abstract: A computer-implemented method includes receiving a subscriber-initiated request to remove protected content from a raw media item, detecting a plurality of acoustic features associated with the raw media item, based on the plurality of acoustic features indicating that the raw media item includes the one or more protected media assets, automatically routing the raw media item to an audio sanitization service, separating, in response to the audio sanitization service executing a plurality of audio separation machine learning models, the one or more protected media assets from non-protected portions of the raw media item to generate a plurality of sanitized instances of the raw media item; and returning, as a response to the subscriber-initiated request, the plurality of sanitized instances of the raw media item to prevent unauthorized electronic distribution of the one or more protected media assets within the raw media item.
    Type: Grant
    Filed: November 10, 2025
    Date of Patent: July 7, 2026
    Assignee: Whitebalance Video Corp
    Inventors: Hariharan Mohanraj, Lorraine Ma, Christopher Landschoot
  • Patent number: 12670257
    Abstract: Versions of an application program are evaluated to protect a customer from a supply chain attack. The versions of the application program are executed in to identify behaviors exhibited by the versions of the application program, each of the behaviors including activities that perform computer operations. A behavior change is detected by identifying a behavior that is not common to the versions of the application program.
    Type: Grant
    Filed: January 8, 2025
    Date of Patent: June 30, 2026
    Assignee: VicOne Corporation
    Inventors: Shih-Han Hsu, Wei-Jen Chang, Yao-Tang Chang, Yi-Li Cheng
  • Patent number: 12645765
    Abstract: A system for secure delivery of data, algorithms, or intellectual property into an untrusted environment utilizes an embedded transcoder within the client computing environment. The embedded transcoder takes advantage of cloud computing functionality to isolate the embedded transcoder from the client application, with a proxy junction between the client application and embedded transcoder. Communication to a provider cloud environment is maintained through a generic authentication appliance system (GAAS) with a client-facing application programming interface (API), with the GAAS also communicating to the customer cloud environment components through the proxy junction. To provide the client application permission to access specific components within the provider application, the API authorizes the client application through tokens activated with public/private keys.
    Type: Grant
    Filed: November 19, 2022
    Date of Patent: June 2, 2026
    Assignee: LiveRamp, Inc.
    Inventor: Joseph Shannon Duncan
  • Patent number: 12647399
    Abstract: Systems and methods are provided for effectuating overlay tunnels between software-defined wide area network (SD-WAN) end-point devices despite the use of IPSec passthrough in one or more network devices, such as modems or routers that exist between the end-point devices. In particular, the Internet Key Exchange (IKE) protocol can be allowed to progress until a modem/router is able to establish an IKE tunnel, after which overlay packets using cloud-managed keys can be allowed to pass through the modem/router. An overlay tunnel may then be established between the end-point devices, and the IKE tunnel can be taken down.
    Type: Grant
    Filed: March 21, 2024
    Date of Patent: June 2, 2026
    Assignee: Hewlett Packard Enterprise Development LP
    Inventors: Shreekanth Chandranna, Bhagvan Cheeyandira, Gopalakrishnan Gunasekaran
  • Patent number: 12639414
    Abstract: An apparatus comprises processing circuitry to execute instructions, and decode circuitry to decode the instructions for execution by the processing circuitry. The decode circuitry is responsive to an authentication code generation instruction specifying a first source value to control the processing circuitry to generate an authentication code dependent on the first source value, and store the authentication code to a memory location associated with a store address formed using a value obtained from a register. By providing a single instruction, this reduces register pressure enabling improved performance by avoiding unnecessary load/store operations, and makes compilation of code using the authentication code generation instruction simpler.
    Type: Grant
    Filed: June 23, 2021
    Date of Patent: May 26, 2026
    Assignee: Arm Limited
    Inventor: Guy Larri
  • Patent number: 12639433
    Abstract: A method for protecting against malware when a client computer causes file operations at a server computer, comprising: gathering, by the server computer, information for each file operation performed into an event, the information including at least a identifier and a type of the operation, developing, not by the client computer, an event-level feature vector including at least two features which are numerical data representing an aspect of the gathered information for each event; grouping the event-level feature vectors into a file-level feature vector for each file; supplying, not by the client computer, the file-level feature vectors to a trained machine learning classifier and receiving as an output of the classifier at least one risk score indicating a likelihood of a presence of malware activity; and when malware activity is indicated by an aggregate risk score based on the at least one risk score, initiating incident handling.
    Type: Grant
    Filed: June 30, 2023
    Date of Patent: May 26, 2026
    Assignee: CTERA Networks Ltd.
    Inventors: Aron Brand, Doron Sher, Simon Taib
  • Patent number: 12641423
    Abstract: A network system includes a processor and computer-readable memory. The computer-readable memory is encoded with instructions that, when executed by the processor, cause the network system to register a unique pre-shared key, a user profile, and a network policy. The instructions further associate the unique pre-shared key with the user profile to form a key-user pair, associate the key-user pair with the network policy to form a mapped key-user pair, and provide the unique pre-shared key to a user to connect one or more devices to a wireless network. The unique pre-shared key is used to encrypt and decrypt data transmitted between a connected wireless device and the wireless network.
    Type: Grant
    Filed: May 31, 2024
    Date of Patent: May 26, 2026
    Assignee: Insight Direct USA, Inc.
    Inventors: Benjamin Kotvis, Cory Douglas Peterson, Michael James Sciacero
  • Patent number: 12632520
    Abstract: A system is provided for provisioning authenticated access to resources linked with individual characteristic data. In particular, the system may comprise an endpoint device associated with a primary user, where the endpoint device stores a resource that is secured using the authentication credentials of the primary user. The endpoint device may have an authentication agent installed thereon that may manage authenticated access to the endpoint device and/or the resources stored thereon. In the event of the primary user's unavailability, a secondary user may attempt to pass the authentication check of the primary user's endpoint device. If a match is found, the authentication agent may grant authorization for the secondary user to access the endpoint device and/or the resources stored thereon.
    Type: Grant
    Filed: January 12, 2023
    Date of Patent: May 19, 2026
    Assignee: BANK OF AMERICA CORPORATION
    Inventors: Adam B. Richman, Derryn Bronstein
  • Patent number: 12633120
    Abstract: Examples of the present disclosure describe systems and methods for detecting and preventing digital media piracy. In example aspects, a machine learning model is trained on a dataset related to digital media content. Input data may then be collected by a data collection engine and provided to a multimedia processor. The multimedia processor may extract multimedia features (e.g., audio, visual, etc.) and recognized patterns from the input data and provide the extracted multimedia features to a trained machine learning model. The trained machine learning model may compare the extracted features to the model, and a confidence value may be generated. The confidence value may be compared to a confidence threshold. If the confidence value is equal to or exceeds the confidence threshold, then the input data may be classified as pirated digital media. Remedial action response(s) may subsequently be deployed to thwart the piracy of the digital media.
    Type: Grant
    Filed: July 17, 2019
    Date of Patent: May 19, 2026
    Assignee: NAGRASTAR, LLC
    Inventors: Benjamin Brian Ellis, Diego Gonzalez
  • Patent number: 12634274
    Abstract: Methods, systems, and devices for secure endpoint authentication credential control are described. An endpoint agent may receive an indication from an operating system of an endpoint device that the operating has received authentication credentials from a user. The endpoint agent may be housed in the endpoint device, and may detect a change between the received set of authentication credentials and a previous version of authentication credentials. Based on this detection, the endpoint agent may transmit the received authentication credentials to a central server. The central server may transmit the authentication credentials to an information technology (IT) resource which requires user authentication prior to granting access to a user.
    Type: Grant
    Filed: November 21, 2023
    Date of Patent: May 19, 2026
    Assignee: JumpCloud, Inc.
    Inventors: Rajat Bhargava, Peter Gengler, Jacob Beck, Greg Keller, Tae Kim
  • Patent number: 12619783
    Abstract: Provided is an automatic pseudonymization technique recommendation method using artificial intelligence, including receiving a training dataset including a plurality of pieces of data including a column name, a data type, a pseudonymization technique recommendation, adding, a data type vector obtained from the data type to a word vector obtained corresponding to the column name to obtain a numeric vector, and labeling the numeric vector with the pseudonymization technique recommendation to generate a plurality of pieces of training data, training a first learning model using the plurality of pieces of training data so that the first learning model outputs a pseudonymization technique recommendation in response to an input of the numeric vector, obtaining a numeric vector corresponding to each column of the dataset to be pseudonymized, and inputting the numeric vector obtained into the trained first learning model to obtain a pseudonymization technique recommendation for each column of the dataset.
    Type: Grant
    Filed: August 22, 2024
    Date of Patent: May 5, 2026
    Assignee: EASYCERTI INC.
    Inventors: Gi Chang Shim, Yong Kyu Park
  • Patent number: 12621543
    Abstract: A method for managing transmission of a multimedia content protected against copying, referred to as the protected content, from a reader terminal to a rendering device via a communication link with a view to a rendition on the rendering device. The reader terminal includes a first protective module. The method includes verifying presence on the rendering device of a second protective module compatible with the first protective module, and, in the negative case, transmitting, via the communication link, a request to render an unprotected content instead of the protected content.
    Type: Grant
    Filed: May 11, 2022
    Date of Patent: May 5, 2026
    Inventors: Mathieu Rivoalen, Hervé Marchand