Patents Examined by Techane Gergiso
-
Patent number: 12712888Abstract: The present disclosure relates to a system, a method, and a non-transitory computer readable storage medium for deep packet inspection scanning at an application layer of a computer. A method of the presently claimed invention may scan pieces of data received out of order without reassembly at an application layer from a first input state generating one or more output states for each piece of data. The method may then identify that the first input state includes one or more characters that are associated with malicious content. The method may then identify that the data set may include malicious content when the first input state combined with one or more output states matches a known piece of malicious content.Type: GrantFiled: September 17, 2024Date of Patent: August 18, 2026Assignee: SONICWALL US HOLDINGS INC.Inventors: Hui Ling, Cuiping Yu, Zhong Chen
-
Patent number: 12712734Abstract: A method of delivering a one-time password to an entity is provided. The entity requesting the one-time password provides a public key of a public-private key pair to the authentication service. The entity can then submit a challenge request to the authentication service. The authentication service will generate a one-time password, and encrypt the one-time password with the public key. The encrypted one-time password is delivered to the entity via an unauthenticated channel.Type: GrantFiled: August 31, 2023Date of Patent: August 18, 2026Assignee: Entrust CorporationInventors: Ian Reilly, Emilio Belmonte
-
Patent number: 12712744Abstract: Techniques are disclosed relating to securely authenticating communicating devices. In various embodiments, a computing device receives, via a network connection with a network, a first certificate for a first public key pair of the computing device. The computing device provides the first certificate to an offline accessory device and receives a second certificate for a second public key pair maintained by the offline accessory device. The computing device performs a verification of the second certificate and, responsive to the verification being successful, interacts with the offline accessory device. In some embodiments, prior to providing the first certificate, the computing device determines an ordering in which the first and second certificates are to be exchanged by the first computing device and the offline accessory device, and the first certificate is provided to the offline accessory device in accordance with the determined ordering.Type: GrantFiled: December 13, 2024Date of Patent: August 18, 2026Assignee: Apple Inc.Inventors: Steven A. Myers, Kyle C. Brogle, Sean P. Devlin, Edwin W. Foo, John T. Perry
-
Patent number: 12706759Abstract: The present disclosure provides methods, apparatuses and systems for key management and service processing. In one aspect, a method includes receiving, by a authentication server from a trusted execution environment (TEE) of a terminal device, device authentication information through a secure channel between the TEE and the authentication server. The device authentication information is configured to prove an identity of the terminal device. The method includes performing, by the authentication server based on the device authentication information, device authentication on the terminal device. The method further includes in response to determining that the terminal device passes the device authentication, sending, by the authentication server, a service encryption key and a device identity certificate to the TEE through the secure channel.Type: GrantFiled: July 30, 2024Date of Patent: August 11, 2026Assignee: Alipay (Hangzhou) Information Technology Co., Ltd.Inventors: Xianyi Zheng, Dengwei Xu, Zhi Xin, Xiaofei Wan
-
Patent number: 12706883Abstract: A data item is provided to an on-premises proxy service by a peer-to-peer (P2P) client device associated with a video conferencing platform. The P2P client device and the on-premises proxy service are associated with a private network. The data item comprises topological information corresponding to the private network. A transformed version of the data item is received from the on-premises proxy service. The transformed version of the data item obscures the topological information corresponding to the private network. The transformed version of the data item is provided to an external tracking service for a P2P configuration operation. The external tracking service is associated with the video conferencing platform and is external to the private network.Type: GrantFiled: August 12, 2024Date of Patent: August 11, 2026Assignee: Google LLCInventors: Alexander Schäfer, Christopher Probst-Ranly, Stefan Lindmark
-
Patent number: 12700052Abstract: A cross-certificate method is performed by an electric vehicle (EV) for being supplied with power from electric vehicle supply equipment (EVSE) associated with a charging point operator (CPO) having established a trust relationship with a first vehicle to grid (V2G) root certificate authority (rootCA) and a second V2G root certificate authority. The cross-certificate method may include steps of: requesting charging from the electric vehicle supply equipment; receiving, from the electric vehicle supply equipment, a certificate chain held by the electric vehicle supply equipment; and verifying whether or not a last certificate of the certificate chain has been signed by the second V2G root certificate authority, wherein the last certificate of the certificate chain can be a cross-certificate issued by the second V2G root certificate authority.Type: GrantFiled: July 22, 2024Date of Patent: August 4, 2026Assignees: Hyundai Motor Company, Kia Corporation, Myongji University Industry and Academia Cooperation FoundationInventor: Min Ho Shin
-
Patent number: 12701017Abstract: Examples of the present disclosure provide an authenticator system that protects secret authentication keys associated with relying parties to which a user is authenticating. Present systems and methods allow cross-platform and cross-device WebAuthn usage. Example systems employ a server-based secure enclave and secure tunnel communication between the browser application or mobile application and the secure enclave server. A user of a service provider of the authenticator system owns the secret authentication key, which is stored in an encrypted vault protected by a user secret and hosted by the service provider. Decrypting the secret key may be based on a key arrangement, where keys from the user, the service provider, and the secure enclave are used to successfully decrypt the secret authentication key within the secure enclave.Type: GrantFiled: January 19, 2024Date of Patent: August 4, 2026Assignee: Dashlane SASInventors: Mohammed Ruhul Islam, Ludovic Widmer, Guillaume Maron, Cyril Leclerc, Corentin Mors, Frédéric Rivain
-
Patent number: 12695599Abstract: A method for using cryptographic keys in a vehicle on-board communication network. The method includes, during an initialization of a vehicle-bound power supply time period of a vehicle: generating at least one cryptographic key by a central electronic control unit for the respectively initialized vehicle-bound power supply time period of the vehicle; transferring the generated at least one cryptographic key by the central electronic control unit using at least one cryptographic algorithm to at least one further electronic control unit in the on-board communication network; using the transferred cryptographic key by at least one electronic control unit for at least one further or for the same cryptographic algorithm for a communication between the electronic control units for the duration of the respective initialized vehicle-bound power supply time period in the on-board communication network.Type: GrantFiled: July 5, 2023Date of Patent: July 28, 2026Assignee: ROBERT BOSCH GMBHInventor: Stefan Heinrich
-
Patent number: 12675557Abstract: A computer-implemented method includes receiving a subscriber-initiated request to remove protected content from a raw media item, detecting a plurality of acoustic features associated with the raw media item, based on the plurality of acoustic features indicating that the raw media item includes the one or more protected media assets, automatically routing the raw media item to an audio sanitization service, separating, in response to the audio sanitization service executing a plurality of audio separation machine learning models, the one or more protected media assets from non-protected portions of the raw media item to generate a plurality of sanitized instances of the raw media item; and returning, as a response to the subscriber-initiated request, the plurality of sanitized instances of the raw media item to prevent unauthorized electronic distribution of the one or more protected media assets within the raw media item.Type: GrantFiled: November 10, 2025Date of Patent: July 7, 2026Assignee: Whitebalance Video CorpInventors: Hariharan Mohanraj, Lorraine Ma, Christopher Landschoot
-
Patent number: 12670257Abstract: Versions of an application program are evaluated to protect a customer from a supply chain attack. The versions of the application program are executed in to identify behaviors exhibited by the versions of the application program, each of the behaviors including activities that perform computer operations. A behavior change is detected by identifying a behavior that is not common to the versions of the application program.Type: GrantFiled: January 8, 2025Date of Patent: June 30, 2026Assignee: VicOne CorporationInventors: Shih-Han Hsu, Wei-Jen Chang, Yao-Tang Chang, Yi-Li Cheng
-
Patent number: 12645765Abstract: A system for secure delivery of data, algorithms, or intellectual property into an untrusted environment utilizes an embedded transcoder within the client computing environment. The embedded transcoder takes advantage of cloud computing functionality to isolate the embedded transcoder from the client application, with a proxy junction between the client application and embedded transcoder. Communication to a provider cloud environment is maintained through a generic authentication appliance system (GAAS) with a client-facing application programming interface (API), with the GAAS also communicating to the customer cloud environment components through the proxy junction. To provide the client application permission to access specific components within the provider application, the API authorizes the client application through tokens activated with public/private keys.Type: GrantFiled: November 19, 2022Date of Patent: June 2, 2026Assignee: LiveRamp, Inc.Inventor: Joseph Shannon Duncan
-
Patent number: 12647399Abstract: Systems and methods are provided for effectuating overlay tunnels between software-defined wide area network (SD-WAN) end-point devices despite the use of IPSec passthrough in one or more network devices, such as modems or routers that exist between the end-point devices. In particular, the Internet Key Exchange (IKE) protocol can be allowed to progress until a modem/router is able to establish an IKE tunnel, after which overlay packets using cloud-managed keys can be allowed to pass through the modem/router. An overlay tunnel may then be established between the end-point devices, and the IKE tunnel can be taken down.Type: GrantFiled: March 21, 2024Date of Patent: June 2, 2026Assignee: Hewlett Packard Enterprise Development LPInventors: Shreekanth Chandranna, Bhagvan Cheeyandira, Gopalakrishnan Gunasekaran
-
Patent number: 12639414Abstract: An apparatus comprises processing circuitry to execute instructions, and decode circuitry to decode the instructions for execution by the processing circuitry. The decode circuitry is responsive to an authentication code generation instruction specifying a first source value to control the processing circuitry to generate an authentication code dependent on the first source value, and store the authentication code to a memory location associated with a store address formed using a value obtained from a register. By providing a single instruction, this reduces register pressure enabling improved performance by avoiding unnecessary load/store operations, and makes compilation of code using the authentication code generation instruction simpler.Type: GrantFiled: June 23, 2021Date of Patent: May 26, 2026Assignee: Arm LimitedInventor: Guy Larri
-
Patent number: 12639433Abstract: A method for protecting against malware when a client computer causes file operations at a server computer, comprising: gathering, by the server computer, information for each file operation performed into an event, the information including at least a identifier and a type of the operation, developing, not by the client computer, an event-level feature vector including at least two features which are numerical data representing an aspect of the gathered information for each event; grouping the event-level feature vectors into a file-level feature vector for each file; supplying, not by the client computer, the file-level feature vectors to a trained machine learning classifier and receiving as an output of the classifier at least one risk score indicating a likelihood of a presence of malware activity; and when malware activity is indicated by an aggregate risk score based on the at least one risk score, initiating incident handling.Type: GrantFiled: June 30, 2023Date of Patent: May 26, 2026Assignee: CTERA Networks Ltd.Inventors: Aron Brand, Doron Sher, Simon Taib
-
Patent number: 12641423Abstract: A network system includes a processor and computer-readable memory. The computer-readable memory is encoded with instructions that, when executed by the processor, cause the network system to register a unique pre-shared key, a user profile, and a network policy. The instructions further associate the unique pre-shared key with the user profile to form a key-user pair, associate the key-user pair with the network policy to form a mapped key-user pair, and provide the unique pre-shared key to a user to connect one or more devices to a wireless network. The unique pre-shared key is used to encrypt and decrypt data transmitted between a connected wireless device and the wireless network.Type: GrantFiled: May 31, 2024Date of Patent: May 26, 2026Assignee: Insight Direct USA, Inc.Inventors: Benjamin Kotvis, Cory Douglas Peterson, Michael James Sciacero
-
System for provisioning authenticated access to resources linked with individual characteristic data
Patent number: 12632520Abstract: A system is provided for provisioning authenticated access to resources linked with individual characteristic data. In particular, the system may comprise an endpoint device associated with a primary user, where the endpoint device stores a resource that is secured using the authentication credentials of the primary user. The endpoint device may have an authentication agent installed thereon that may manage authenticated access to the endpoint device and/or the resources stored thereon. In the event of the primary user's unavailability, a secondary user may attempt to pass the authentication check of the primary user's endpoint device. If a match is found, the authentication agent may grant authorization for the secondary user to access the endpoint device and/or the resources stored thereon.Type: GrantFiled: January 12, 2023Date of Patent: May 19, 2026Assignee: BANK OF AMERICA CORPORATIONInventors: Adam B. Richman, Derryn Bronstein -
Patent number: 12633120Abstract: Examples of the present disclosure describe systems and methods for detecting and preventing digital media piracy. In example aspects, a machine learning model is trained on a dataset related to digital media content. Input data may then be collected by a data collection engine and provided to a multimedia processor. The multimedia processor may extract multimedia features (e.g., audio, visual, etc.) and recognized patterns from the input data and provide the extracted multimedia features to a trained machine learning model. The trained machine learning model may compare the extracted features to the model, and a confidence value may be generated. The confidence value may be compared to a confidence threshold. If the confidence value is equal to or exceeds the confidence threshold, then the input data may be classified as pirated digital media. Remedial action response(s) may subsequently be deployed to thwart the piracy of the digital media.Type: GrantFiled: July 17, 2019Date of Patent: May 19, 2026Assignee: NAGRASTAR, LLCInventors: Benjamin Brian Ellis, Diego Gonzalez
-
Patent number: 12634274Abstract: Methods, systems, and devices for secure endpoint authentication credential control are described. An endpoint agent may receive an indication from an operating system of an endpoint device that the operating has received authentication credentials from a user. The endpoint agent may be housed in the endpoint device, and may detect a change between the received set of authentication credentials and a previous version of authentication credentials. Based on this detection, the endpoint agent may transmit the received authentication credentials to a central server. The central server may transmit the authentication credentials to an information technology (IT) resource which requires user authentication prior to granting access to a user.Type: GrantFiled: November 21, 2023Date of Patent: May 19, 2026Assignee: JumpCloud, Inc.Inventors: Rajat Bhargava, Peter Gengler, Jacob Beck, Greg Keller, Tae Kim
-
Patent number: 12619783Abstract: Provided is an automatic pseudonymization technique recommendation method using artificial intelligence, including receiving a training dataset including a plurality of pieces of data including a column name, a data type, a pseudonymization technique recommendation, adding, a data type vector obtained from the data type to a word vector obtained corresponding to the column name to obtain a numeric vector, and labeling the numeric vector with the pseudonymization technique recommendation to generate a plurality of pieces of training data, training a first learning model using the plurality of pieces of training data so that the first learning model outputs a pseudonymization technique recommendation in response to an input of the numeric vector, obtaining a numeric vector corresponding to each column of the dataset to be pseudonymized, and inputting the numeric vector obtained into the trained first learning model to obtain a pseudonymization technique recommendation for each column of the dataset.Type: GrantFiled: August 22, 2024Date of Patent: May 5, 2026Assignee: EASYCERTI INC.Inventors: Gi Chang Shim, Yong Kyu Park
-
Patent number: 12621543Abstract: A method for managing transmission of a multimedia content protected against copying, referred to as the protected content, from a reader terminal to a rendering device via a communication link with a view to a rendition on the rendering device. The reader terminal includes a first protective module. The method includes verifying presence on the rendering device of a second protective module compatible with the first protective module, and, in the negative case, transmitting, via the communication link, a request to render an unprotected content instead of the protected content.Type: GrantFiled: May 11, 2022Date of Patent: May 5, 2026Inventors: Mathieu Rivoalen, Hervé Marchand