Patents Examined by Thaddeus J Plecha
-
Patent number: 12689663Abstract: In one embodiment, an access policy enforcement service receives a user authentication request from an end-user device. The access policy enforcement service identifies a telemetry collection intent from the user authentication request. The access policy enforcement service determines a monitoring policy based on the telemetry collection intent identified from the user authentication request. The access policy enforcement service configures, according to the monitoring policy, one or more telemetry collection agents to collect telemetry for traffic associated with the end-user device.Type: GrantFiled: September 9, 2024Date of Patent: July 21, 2026Assignee: Cisco Technology, Inc.Inventors: Nagendra Kumar Nainar, Carlos M. Pignataro, Rahul Rammanohar, Kondaveeti Lakshmi Ganesh, David John Zacks
-
Patent number: 12682034Abstract: User identity authentication and verification systems, methods, and apparatuses are disclosed, including a mobile computing device configured to receive a verification request from a remote computing system, the verification request including instructions for a user to perform a task for verifying his identity. A task includes scanning a band securely attached to the user's body, the band including an embedded communication device and a tamper indication circuit. In response to performing the scan, the mobile computing device receives, from the embedded communication device, a circuit tamper status and uniquely identifying data encoded within the communication device.Type: GrantFiled: September 9, 2024Date of Patent: July 14, 2026Assignee: T Stamp Inc.Inventors: Gareth Neville Genner, David Michael Grima
-
Patent number: 12683977Abstract: Various embodiments provide systems and methods for providing security in a ZTNA system.Type: GrantFiled: August 28, 2024Date of Patent: July 14, 2026Assignee: Fortinet, Inc.Inventor: Robert A. May
-
Patent number: 12676738Abstract: Provided is a method for threshold secret sharing and reconstruction for multi-compartment, and more particularly, to a method for creating a share and reconstructing a secret in a system constituted by a plurality of compartments. The method for threshold secret sharing for multi-compartments may include: an operation of creating, when at least one second compartment is related toward a first compartment in one direction, an encrypted secret value by using an external share which does not belong to the first compartment, but belongs to the at least one second compartment; an operation of creating a first polynomial for defining the first compartment by using the encrypted secret value; and an operation of creating an internal share of the first compartment by using the first polynomial.Type: GrantFiled: April 25, 2023Date of Patent: July 7, 2026Assignees: Industry-University Cooperation Foundation Hanyang University, LTCware Inc.Inventor: Min Soo Ryu
-
Patent number: 12676763Abstract: Described herein are methods and systems implementing physically unclonable functions (PUFs). An example method includes: inputting a first challenge bit string into a first PUF; capturing a first response bit string from the first PUF; inputting a second challenge bit string into a second PUF; capturing a second response bit string from the second PUF; performing a hash operation on the first response bit string and the second response bit string, the hash operation generating a hashed-response bit string; and storing the first and second challenge bit strings and the hashed-response bit string in a first database.Type: GrantFiled: March 20, 2023Date of Patent: July 7, 2026Assignee: Ohio State Innovation FoundationInventors: Daniel Gauthier, Andrew Joseph Pomerance
-
Patent number: 12677151Abstract: A wireless transmit/receive unit (WTRU) may be configured to receive a key identifier. The key identifier may be associated with a second WTRU. Additionally, or alternatively, the key identifier may include a 5G ProSe remote user key (5GPRUK) identifier (ID). The WTRU may be configured as a WTRU-to-network relay for the second WTRU. The key identifier may be received during a key request procedure. The key request procedure may be performed by the WTRU on behalf of the second WTRU. The WTRU may be configured to send the key identifier to a network function. The key identifier may be sent to the network function to initiate a secondary authentication procedure. The WTRU may be configured to receive an authentication response message from the second WTRU. The WTRU may be configured to receive a response from the network function.Type: GrantFiled: March 24, 2023Date of Patent: July 7, 2026Assignee: InterDigital Patent Holdings, Inc.Inventor: Samir Ferdi
-
Patent number: 12675566Abstract: A processing system includes a memory configured to store encrypted information representing state and control information for a guest virtual machine. The processing system further includes a processor configured to selectively reserve exclusive use of a set of performance monitoring counters by the guest virtual machine during execution of the guest virtual machine based on a state of a first control field accessed from the encrypted information for the guest virtual machine. The processor further is configured to permit or deny use of the set of performance monitoring counters by the guest virtual machine based on a state of a second control field set by a hypervisor and accessed from the decryption of the encrypted information for the guest virtual machine accessed from the memory.Type: GrantFiled: December 29, 2022Date of Patent: July 7, 2026Assignee: Advanced Micro Devices, Inc.Inventors: David Kaplan, Ruchir Dalal
-
Patent number: 12676748Abstract: A system performs digital notarization using a biometric identification service. A signature requesting service receives a request to validate a digital item with a signature for a person. The signature requesting service provides a payload that identifies the digital item and/or the person to an identity service. The identity service obtains one or more digital representations of biometrics for the person, determines an identity for the person, and returns a data structure including the payload and one or more identity attestations regarding the determined identity. The identity service encrypts at least a portion of the data structure using a private encryption key. A public encryption key for the identity service can then be used to decrypt the portion to verify that the data structure was generated by the identity service after determining the identity. In this way, validation can be verified to the full trust level of the identification service.Type: GrantFiled: July 23, 2024Date of Patent: July 7, 2026Inventor: Rob Wisniewski
-
Patent number: 12671678Abstract: Methods, systems, and apparatus, including computer programs encoded on computer storage media, for encoding data on client devices. One of the methods includes obtaining dataset for transmission; dividing the dataset into two subsets according to one or more selection criteria, wherein data items that satisfy the one or more criteria are added to a first subset and the data items that do not satisfy the one or more criteria are added to a second subset, wherein the first subset is smaller than the second subset; encoding the data items of the first subset according to a first encoding technique and encoding the data items of the second subset according to a second encoding technique; applying a local differential privacy (LDP) mechanism to data elements of the first subset and the second subset to generate an LDP message; and transmitting the LDP message to an external recipient.Type: GrantFiled: June 28, 2024Date of Patent: June 30, 2026Assignees: Beijing Zitiao Network Technology Co., Ltd., Lemon Inc.Inventors: Donghang Lu, Bo Jiang, Wanrong Zhang, Jian Du, Qiang Yan
-
Patent number: 12670273Abstract: In one aspect, a computerized method for detecting hiding and data intelligence gathering in a data lake or a cloud warehouse, comprising: implementing a hiding and data intelligence collection analysis phase in the data lake or the cloud warehouse; implementing a discovery process in the data lake or the cloud warehouse; implementing a data gathering process in the data lake or the cloud warehouse; and performing one or more dynamic masking operations to detect a Dynamic Masking column anomalies and to detect one or more atypical commands in the data lake or the cloud warehouse.Type: GrantFiled: July 27, 2023Date of Patent: June 30, 2026Assignee: Theom, Inc.Inventors: Navindra Yadav, Supreeth Hosur Nagesh Rao, Ravi Sankuratri, Danesh Irani, Alok Lalit Wadhwa, Vasil Dochkov Yordanov, Venkateshu Cherukupalli, Yiwei Wang, Zhiwen Zhang, Udayan Pramod Joshi
-
Patent number: 12665755Abstract: A hybrid cryptographic scheme for a network of nodes, in particular an IoT network, composed of a first subset and a second subset of separate nodes, the computing resources of the nodes of the first subset being greater than the computing resources of the nodes of the second subset, the scheme comprising a first functional cryptographic scheme deployed on the first subset of nodes and a second functional cryptographic scheme deployed on the second subset of nodes, a cryptographic primitive at the root of the second cryptographic scheme generating a pair of private and public master keys from a seed, the seed being obtained by a connection cryptographic primitive from at least the private key of an end node of the first subset, the connection cryptographic primitive being a one-way function.Type: GrantFiled: November 21, 2023Date of Patent: June 23, 2026Assignee: COMMISSARIAT À L'ÉNERGIE ATOMIQUE ET AUX ENERGIES ALTERNATIVESInventors: Antoine Loiseau, Doryan Lesaignoux, Mikael Carmona
-
Patent number: 12665750Abstract: A plurality of nodes connected to the plurality of servers that form a broadcasting overlay over a network for performing best effort broadcasting of data through the broadcasting overlay, may receive, from a first computing device of a plurality of computing devices connected to the broadcasting overlay, a first encrypted message and may perform best effort broadcasting of the first encrypted message through the broadcasting overlay to send, in an end-to-end encrypted manner, the first encrypted message to a first service of a plurality of services. The plurality of nodes may also receive, from the plurality of services, a second encrypted message, and may perform best effort broadcasting of the second encrypted message to propagate the second encrypted message through the broadcasting overlay to send, in the end-to-end encrypted manner, the second encrypted message to a second computing device of the plurality of computing devices.Type: GrantFiled: July 9, 2021Date of Patent: June 23, 2026Assignee: SRI InternationalInventor: Karim Eldefrawy
-
Patent number: 12664296Abstract: Apparatus and methods to automatically layer data are provided. An automatic data layering program may receive access to multiple quanta of data. The program may automatically analyze and categorize each quanta of data with a corresponding level of access. The program may transfer each quanta of data so that various data stores may each only have data with the same level of access stored within. The program may receive a request to access data from a user. The program may determine the user's level of access and authorize access to the user to data corresponding with the user's level of access. The program may create a three-dimensional map or display of available data.Type: GrantFiled: May 19, 2023Date of Patent: June 23, 2026Assignee: Bank of America CorporationInventors: Sanjeev Verma, Manu Kurian
-
Patent number: 12645829Abstract: This disclosure provides a user data processing system. A first data processing device in the system generates a first intermediate result, and sends a third intermediate result to a second data processing device. The third intermediate result is obtained from the first intermediate result based on a parameter of a first machine learning model and target historical user data obtained by the first data processing device, and an identifier of the target historical user data is the same as an identifier of historical user data of the second data processing device. The first data processing device further receives a second intermediate result, and updates the parameter of the first machine learning model based on the first intermediate result and the second intermediate result. The second data processing device further updates a parameter of a second machine learning model based on the received third intermediate result and the second intermediate result.Type: GrantFiled: July 4, 2024Date of Patent: June 2, 2026Assignee: HUAWEI TECHNOLOGIES CO., LTD.Inventors: Yunfeng Shao, Bingshuai Li
-
Patent number: 12640919Abstract: A network device may determine that a particular security association (SA) is to be established with a peer network device and that a post-quantum preshared key (PPK) cannot be obtained by the network device. The network device may determine that establishment of quantum-secure SAs is not mandatory for the network device. The network device may generate based on determining that the PPK cannot be obtained by the network device, and based on determining that establishment of quantum-secure SAs is not mandatory for the network device, a pseudo-PPK, and may generate, using the pseudo-PPK, pseudo-PPK authentication information associated with the network device. The network device may generate, using a non-quantum-secure key, non-quantum-secure authentication information associated with the network device.Type: GrantFiled: May 3, 2024Date of Patent: May 26, 2026Assignee: Hewlett Packard Enterprise Development LPInventors: Ranjan Sinha, Priyabrata Saha
-
Patent number: 12634142Abstract: A secure computation system comprises at least five secure computation server apparatuses connected to each other via a network and performs secure computation on a value stored while being secret-shared, and each of the secure computation server apparatuses has a comparative verification part that compares values, which should be the same, received from at least three secure computation server apparatuses and that accepts a received value identical to at least another received value as a correct value.Type: GrantFiled: October 6, 2020Date of Patent: May 19, 2026Assignee: NEC CORPORATIONInventor: Hikaru Tsuchida
-
Patent number: 12634323Abstract: In one aspect, a computerized method for attack generation on a data lake, comprises: for a data lake repository: providing an attack generation mimicry tool; with the attack generation mimicry tool: implementing a reconnaissance phase attack generation; implementing an infiltration phase attack generation on the data lake repository; implementing a hiding and data intelligence collection phase of the attack by hiding from any monitoring or notification system of the data lake repository and surveying the data lake repository to determine what data is worth abusing or exfiltrating from the data lake repository; implementing data gathering phase of the attack that gathers data about other objects, attributes, and relationships in the data lake repository; and implementing the exfiltration of the data or the abuse of the data.Type: GrantFiled: May 29, 2023Date of Patent: May 19, 2026Assignee: Theom, Inc.Inventors: Navindra Yadav, Supreeth Hosur Nagesh Rao, Ravi Kanth Sankuratri, Danesh S. Irani, Alok Lalit Wadhwa, Vasil Dochkov Yordanov, Venkateshu Cherukupalli, Yiwei Wang, Zhiwen Zhang, Udayan Pramod Joshi
-
Patent number: 12627691Abstract: Systems and methods for detecting security anomalies in a computing environment. One example system includes an electronic processor configured to receive, via the communication interface, security data for the computing environment and parse the security data to extract a feature set. The electronic processor is configured to apply noise to the feature set to produce a noised feature set and to produce a reduced noise feature set by processing the noised feature set using a neural network trained to remove noise. The electronic processor is configured to compare the reduced noise feature set to the feature set to determine a success score, select a threshold based on the security data, and determine whether the success score exceeds the threshold. The electronic processor is configured to, responsive to determining that the success score does not exceed the threshold, generate a security event based on the security data.Type: GrantFiled: April 26, 2024Date of Patent: May 12, 2026Assignee: MOTOROLA SOLUTIONS, INC.Inventors: Pranshu Bajpai, Eamon Bracht, Cyril Jazra
-
Patent number: 12592943Abstract: Methods, systems, and computer programs are presented for stitching a meta session with an underlying trail fragmented across multiple distributed sessions. One method includes receiving telemetry signals from entities in a session environment that includes at least one identity of a user engaged with applications via respective meta sessions. An underlying trail for each meta session is determined, where the underlying trail is fragmented across two or more sessions with two or more entities. For a first meta session with a first application for the identity of the user, several operations are performed, including correlating a signal hierarchy based on the telemetry signals; constructing, based on the correlated signal hierarchy, a session hierarchy underlying the first meta session distributed across the one or more entities; determining a posture of the first meta session based on the constructed session hierarchy; and enforcing a security policy based on the determined posture.Type: GrantFiled: September 17, 2024Date of Patent: March 31, 2026Assignee: WideField Security Inc.Inventors: Kartik Kumar Chatnalli Deshpande Sridhar, Abhay Sudhakar Kulkarni, Deepak Swaminathan
-
Patent number: 12587370Abstract: Systems and methods include an IHS (Information Handling System) that is a member of a computing cluster and that is configured to participate in collective management of the cluster, including generating a unique identifier for collective use and identification of the cluster. Cluster management functions of the IHS are configured to determine when the addition of another IHS as a member of the computing cluster requires an update to a cluster identifier that is used to task the computing cluster. When an update to the cluster identifier is required, the cluster management functions generate an updated cluster identifier that is amalgamation of identifiers of each member of the computing cluster and the updated cluster identity is transmitted to cluster members.Type: GrantFiled: January 31, 2024Date of Patent: March 24, 2026Assignee: Dell Products L.P.Inventors: Eugene David Cho, Mukund P. Khatri, Senthil Ponnuswamy