Patents by Inventor Ali SAJJAD

Ali SAJJAD has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Publication number: 20260205447
    Abstract: A computer-implemented method of encrypting internet of things (IoT) device data communications is disclosed. The method involves transmitting network data having a predetermined pattern of network packets from a network apparatus to the IoT device. Network response behaviour of the IoT device to the network data is analysed to ascertain one or more performance characteristics of the IoT device. An encryption algorithm for the data communications is selected based on the ascertained one or more performance characteristics. The data communications are then encrypted using the selected encryption algorithm.
    Type: Application
    Filed: December 8, 2023
    Publication date: July 16, 2026
    Inventors: Ali SAJJAD, Fadi EL-MOUSSA
  • Patent number: 12519716
    Abstract: An aspect of the disclosure relates to a computer-implemented method of operating a software-defined network, the method comprising: initialising a plurality of paths through a data plane for traffic associated with a category of applications and/or services; selecting one of the plurality of paths to be an initial operational path; routing traffic associated with the category of applications and/or services via the initial operational path; subsequently obtaining data indicating that a trigger event has occurred; and responsive thereto: selecting a different one of the plurality of paths to be a replacement operational path; and routing traffic associated with the category of applications and/or services via the replacement operational path. Further aspects relate to a data processing system, a computer program, a computer-readable data carrier, and a data carrier signal.
    Type: Grant
    Filed: August 23, 2022
    Date of Patent: January 6, 2026
    Assignee: BRITISH TELECOMMUNICATIONS public limited company
    Inventors: Behnam Azvine, Ali Sajjad
  • Patent number: 12438717
    Abstract: A method and distributed system for exclusively sharing data between a data provider and one or more selected data recipients is disclosed. Known systems for exclusively sharing data with one or more selected data recipients involve the encryption of the data at a central storage service and limiting use of one or more centrally stored decryption keys to decrypt the data in accordance with an access control list maintained by the remote storage service provider. Ensuring robustness of key management in such systems requires the expenditure of a great deal of resource. This problem is addressed by a combination of two co-operating facilities in the disclosed distributed data sharing system. Firstly, a symmetric key exchange facility is provided which enables each data provider to exclusively derive 182 dedicated key encryption keys with respective selected data clients.
    Type: Grant
    Filed: June 16, 2022
    Date of Patent: October 7, 2025
    Assignee: BRITISH TELECOMMUNICATIONS public limited company
    Inventors: Ali Sajjad, Mamun Abu-Tair, Syed Muhammad Unsub Zia
  • Patent number: 12425193
    Abstract: There is provided a computer implemented method for accessing a resource at a computing device, as well as for controlling access to a resource by a computing device. The computing device receives a policy indicating a set of conditions under which access to the resource is permitted, determines whether each of the conditions are initially present based on an output of one or more sensors of the device, and monitors the one or more sensors to detect a change in the presence of one or more of the conditions. In response to detecting the change in the presence of one or more of the conditions, the computing device determines whether each of the conditions are present. In response to determining that each of the conditions is present, access to the resource is enabled. If at least one of the conditions is not present, access to the resource is prevented.
    Type: Grant
    Filed: September 11, 2020
    Date of Patent: September 23, 2025
    Assignee: British Telecommunications Public Limited Company
    Inventors: Ali Sajjad, Gery Ducatel, Gabriele Gelardi
  • Patent number: 12314362
    Abstract: Computer implemented methods for enrolling a user as an authenticated user of a computing device and for authenticating a user of a computing device are provided. The methods make use of behavioral biometrics to determine a set of shares that represent a secret credential according to a secret sharing scheme. The set of shares is initially determined when the user is enrolled based on typical measurements of the user's behavioral biometrics and authentication data indicating how to generate the set of shares from a user's behavioral biometrics is generated. When authenticating the user, the computing device can generate the set of shares based on the authentication data and measurements of the current user's behavioral biometrics. The computing device can use the generated set of shares to recreate a copy of the secret credential with which to authenticate the user.
    Type: Grant
    Filed: June 16, 2020
    Date of Patent: May 27, 2025
    Assignee: BRITISH TELECOMMUNICATIONS PUBLIC LIMITED COMPANY
    Inventors: Gabriele Gelardi, Ali Sajjad, Gery Ducatel
  • Publication number: 20250133015
    Abstract: An aspect of the disclosure relates to a computer-implemented method of operating a software-defined network, the method comprising: initialising a plurality of paths through a data plane for traffic associated with a category of applications and/or services; selecting one of the plurality of paths to be an initial operational path; routing traffic associated with the category of applications and/or services via the initial operational path; subsequently obtaining data indicating that a trigger event has occurred; and responsive thereto: selecting a different one of the plurality of paths to be a replacement operational path; and routing traffic associated with the category of applications and/or services via the replacement operational path. Further aspects relate to a data processing system, a computer program, a computer-readable data carrier, and a data carrier signal.
    Type: Application
    Filed: August 23, 2022
    Publication date: April 24, 2025
    Inventors: Behnam AZVINE, Ali SAJJAD
  • Patent number: 12278826
    Abstract: A computer-implemented method of operating a software-defined network, the method comprising: obtaining specifications of a plurality of data plane elements which together form a path through a data plane suitable for carrying traffic associated with a category of applications and/or services; determining, based on the specifications, which one or more of a plurality of security profiles the path is capable of complying with; selecting one of the one or more security profiles to be an initial security profile; routing traffic associated with the category of applications and/or services via the path in compliance with the initial security profile; subsequently obtaining an alert that network performance conditions have worsened; and responsive thereto: selecting a different one of the plurality of security profiles, that is less resource-intensive than the initial security profile, to be a replacement security profile; and routing traffic associated with the category of applications and/or services in complian
    Type: Grant
    Filed: August 23, 2022
    Date of Patent: April 15, 2025
    Assignee: BRITISH TELECOMMUNICATIONS PUBLIC LIMITED COMPANY
    Inventors: Behnam Azvine, Ali Sajjad
  • Publication number: 20250111053
    Abstract: Attestation method for verifying the integrity of an attester device by an attestation proxy (AP): sending a trusted platform module (TPM) quote request message directly to a virtual TPM (vTPM) uniquely associated with the attester device, to prompt the vTPM to: produce a set of platform configuration register (PCR) values based on measurements requested and received by the vTPM directly from the attester device, then send a TPM quote comprising the set of PCR values directly to the AP; the attestation method further comprising the AP: receiving the TPM quote; sending the TPM quote to a remote relying party (RP) to prompt the RP to: verify the TPM quote is as expected, then return a remote attestation indicator to the AP; receiving the remote attestation indicator; and producing an attestation result based on the remote attestation indicator, wherein the attestation result is negative when the remote attestation indicator is negative.
    Type: Application
    Filed: November 21, 2022
    Publication date: April 3, 2025
    Inventors: Ali SAJJAD, Syed ZIA, Jamshed MEMON, Mamun ABU-TAIR
  • Publication number: 20250061236
    Abstract: A method comprising an attestation proxy (AP): sending a trusted platform module (TPM) quote request message directly to a virtual TPM (vTPM) uniquely associated with an attester device, to prompt the vTPM to: produce a set of platform configuration register (PCR) values based on measurements requested and received by the vTPM directly from the attester device, then send a TPM quote comprising the set of PCR values directly to the AP; the attestation method further comprising the AP: receiving the TPM quote; retrieving, from a local copy of a distributed ledger (DL), a latest set of PCR values recorded for the attester device; comparing that set of PCR values retrieved from the local copy of the DL with the set of PCR values received in the TPM quote to generate a local attestation indicator; and producing an attestation result based on the local attestation indicator.
    Type: Application
    Filed: November 21, 2022
    Publication date: February 20, 2025
    Inventors: Ali SAJJAD, Syed ZIA, Jamshed MEMON, Mamun ABU-TAIR
  • Publication number: 20240275802
    Abstract: A computer-implemented method of operating a software-defined network, the method comprising: obtaining specifications of a plurality of data plane elements which together form a path through a data plane suitable for carrying traffic associated with a category of applications and/or services; determining, based on the specifications, which one or more of a plurality of security profiles the path is capable of complying with; selecting one of the one or more security profiles to be an initial security profile; routing traffic associated with the category of applications and/or services via the path in compliance with the initial security profile; subsequently obtaining an alert that network performance conditions have worsened; and responsive thereto: selecting a different one of the plurality of security profiles, that is less resource-intensive than the initial security profile, to be a replacement security profile; and routing traffic associated with the category of applications and/or services in complian
    Type: Application
    Filed: August 23, 2022
    Publication date: August 15, 2024
    Inventors: Behnam AZVINE, Ali SAJJAD
  • Publication number: 20240235832
    Abstract: A method and distributed system for exclusively sharing data between a data provider and one or more selected data recipients is disclosed. Known systems for exclusively sharing data with one or more selected data recipients involve the encryption of the data at a central storage service and limiting use of one or more centrally stored decryption keys to decrypt the data in accordance with an access control list maintained by the remote storage service provider. Ensuring robustness of key management in such systems requires the expenditure of a great deal of resource. This problem is addressed by a combination of two co-operating facilities in the disclosed distributed data sharing system. Firstly, a symmetric key exchange facility is provided which enables each data provider to exclusively derive 182 dedicated key encryption keys with respective selected data clients. Secondly, a device controlled by the data provider is arranged to encrypt the data using a data encryption key and.
    Type: Application
    Filed: June 16, 2022
    Publication date: July 11, 2024
    Inventors: Ali SAJJAD, Mamun ABU-TAIR, Syed Muhammad Unsub ZIA
  • Publication number: 20240086241
    Abstract: A method of selecting an algorithm from a plurality of candidate algorithms for use by a processor-controlled device to perform an application. A respective value for one or more resource characteristics of the device is obtained. Based on the one or more values, one or more analogous reference devices having similar resource characteristics to the device are identified. One or more reference performance values for execution of each of the plurality of candidate algorithms on each of the analogous reference devices are obtained. The algorithm is selected based on the one or more reference performance values.
    Type: Application
    Filed: March 16, 2022
    Publication date: March 14, 2024
    Inventor: Ali SAJJAD
  • Publication number: 20220376902
    Abstract: There is provided a computer implemented method for accessing a resource at a computing device, as well as for controlling access to a resource by a computing device. The computing device receives a policy indicating a set of conditions under which access to the resource is permitted, determines whether each of the conditions are initially present based on an output of one or more sensors of the device, and monitors the one or more sensors to detect a change in the presence of one or more of the conditions. In response to detecting the change in the presence of one or more of the conditions, the computing device determines whether each of the conditions are present. In response to determining that each of the conditions is present, access to the resource is enabled. If at least one of the conditions is not present, access to the resource is prevented.
    Type: Application
    Filed: September 11, 2020
    Publication date: November 24, 2022
    Inventors: Ali SAJJAD, Gery DUCATEL, Gabriele GELARDI
  • Patent number: 11474847
    Abstract: A computer implemented method of converting a serialized virtual machine (VM) for a source virtualized computing environment, the serialized VM being stored in a data file having also metadata for instantiating the serialized VM in the source environment, the method including supplementing the data file with a software adapter including a plurality of executable disk image converters, each disk image converter being suitable for converting the serialized VM between disparate virtualized computing environments; a plurality of metadata mappings, each metadata mapping defining how the metadata is converted between disparate virtual computing environments; and executable code for effecting a conversion by executing an appropriate disk image converter and performing an appropriate metadata conversion to convert the data file for a target virtualized computing environment, such that the supplemented data file is operable to self-convert between the source virtualized computing environment and the target virtualized
    Type: Grant
    Filed: December 3, 2018
    Date of Patent: October 18, 2022
    Assignee: British Telecommunications Public Limited Company
    Inventors: Ali Sajjad, Fadi El-Moussa
  • Patent number: 11461460
    Abstract: A computer implemented method of securing an application executing in a software container deployed in a computer system includes providing access to the application selectively in accordance with access control rules by sharing an encryption key with authorized accessors.
    Type: Grant
    Filed: December 3, 2018
    Date of Patent: October 4, 2022
    Assignee: British Telecommunications Public Limited Company
    Inventors: Fadi El-Moussa, Ali Sajjad
  • Patent number: 11451387
    Abstract: A computer implemented method of generating cryptographic keys for a plurality of hardware security modules (HSMs), the method including generating a plurality of cryptographic keys for use by the HSMs in providing cryptography functions, wherein the cryptographic keys are generated based on numerical data generated by a hardware random number generator; and storing the generated cryptographic keys in a secure key store, such that a key in the key store utilized by an HSM is flagged as utilized to prevent other HSMs utilizing the same key, so as to provide a rate of generation and storage of the cryptographic keys unconstrained by the resources of any HSM.
    Type: Grant
    Filed: May 2, 2019
    Date of Patent: September 20, 2022
    Assignee: BRITISH TELECOMMUNICATIONS PUBLIC LIMITED COMPANY
    Inventors: Joshua Daniel, Ali Sajjad
  • Publication number: 20220261466
    Abstract: Computer implemented methods for enrolling a user as an authenticated user of a computing device and for authenticating a user of a computing device are provided. The methods make use of behavioral biometrics to determine a set of shares that represent a secret credential according to a secret sharing scheme. The set of shares is initially determined when the user is enrolled based on typical measurements of the user's behavioral biometrics and authentication data indicating how to generate the set of shares from a user's behavioral biometrics is generated. When authenticating the user, the computing device can generate the set of shares based on the authentication data and measurements of the current user's behavioral biometrics. The computing device can use the generated set of shares to recreate a copy of the secret credential with which to authenticate the user.
    Type: Application
    Filed: June 16, 2020
    Publication date: August 18, 2022
    Inventors: Gabriele GELARDI, Ali Sajjad, Gery DUCATEL
  • Patent number: 11411726
    Abstract: A computer implemented method of generating cryptographic keys for a hardware security module (HSM), the method including generating a plurality of cryptographic keys and storing the cryptographic keys for use by the HSM in providing cryptography functions, wherein the cryptographic keys are generated based on numerical data generated by a hardware random number generator, such that a rate of generation of the cryptographic keys unconstrained by the resources of the HSM, wherein the hardware random number generator operates based on a plurality of statistically random entropy data sources originating from natural phenomena so as to increase a degree of randomness of the numerical data.
    Type: Grant
    Filed: May 2, 2019
    Date of Patent: August 9, 2022
    Assignee: BRITISH TELECOMMUNICATIONS PUBLIC LIMITED COMPANY
    Inventors: Joshua Daniel, Ali Sajjad
  • Publication number: 20220159020
    Abstract: There is provided a computer implemented method, computer system and computer program for protecting a network. The method comprises: gathering traffic data for the network; identifying a set of loT devices in the network based on the output from a machine learning model for classifying loT devices using features extracted from the traffic data that are indicative of an loT device; and causing one or more predetermined actions to be taken in respect of the set of loT devices to protect the network.
    Type: Application
    Filed: March 3, 2020
    Publication date: May 19, 2022
    Inventors: Xiao-Si WANG, Ali SAJJAD
  • Publication number: 20210218564
    Abstract: A computer implemented method of generating cryptographic keys for a plurality of hardware security modules (HSMs), the method including generating a plurality of cryptographic keys for use by the HSMs in providing cryptography functions, wherein the cryptographic keys are generated based on numerical data generated by a hardware random number generator; and storing the generated cryptographic keys in a secure key store, such that a key in the key store utilized by an HSM is flagged as utilized to prevent other HSMs utilizing the same key, so as to provide a rate of generation and storage of the cryptographic keys unconstrained by the resources of any HSM.
    Type: Application
    Filed: May 2, 2019
    Publication date: July 15, 2021
    Inventors: Joshua DANIEL, Ali SAJJAD