Patents by Inventor Ali SAJJAD
Ali SAJJAD has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Publication number: 20260205447Abstract: A computer-implemented method of encrypting internet of things (IoT) device data communications is disclosed. The method involves transmitting network data having a predetermined pattern of network packets from a network apparatus to the IoT device. Network response behaviour of the IoT device to the network data is analysed to ascertain one or more performance characteristics of the IoT device. An encryption algorithm for the data communications is selected based on the ascertained one or more performance characteristics. The data communications are then encrypted using the selected encryption algorithm.Type: ApplicationFiled: December 8, 2023Publication date: July 16, 2026Inventors: Ali SAJJAD, Fadi EL-MOUSSA
-
Patent number: 12519716Abstract: An aspect of the disclosure relates to a computer-implemented method of operating a software-defined network, the method comprising: initialising a plurality of paths through a data plane for traffic associated with a category of applications and/or services; selecting one of the plurality of paths to be an initial operational path; routing traffic associated with the category of applications and/or services via the initial operational path; subsequently obtaining data indicating that a trigger event has occurred; and responsive thereto: selecting a different one of the plurality of paths to be a replacement operational path; and routing traffic associated with the category of applications and/or services via the replacement operational path. Further aspects relate to a data processing system, a computer program, a computer-readable data carrier, and a data carrier signal.Type: GrantFiled: August 23, 2022Date of Patent: January 6, 2026Assignee: BRITISH TELECOMMUNICATIONS public limited companyInventors: Behnam Azvine, Ali Sajjad
-
Patent number: 12438717Abstract: A method and distributed system for exclusively sharing data between a data provider and one or more selected data recipients is disclosed. Known systems for exclusively sharing data with one or more selected data recipients involve the encryption of the data at a central storage service and limiting use of one or more centrally stored decryption keys to decrypt the data in accordance with an access control list maintained by the remote storage service provider. Ensuring robustness of key management in such systems requires the expenditure of a great deal of resource. This problem is addressed by a combination of two co-operating facilities in the disclosed distributed data sharing system. Firstly, a symmetric key exchange facility is provided which enables each data provider to exclusively derive 182 dedicated key encryption keys with respective selected data clients.Type: GrantFiled: June 16, 2022Date of Patent: October 7, 2025Assignee: BRITISH TELECOMMUNICATIONS public limited companyInventors: Ali Sajjad, Mamun Abu-Tair, Syed Muhammad Unsub Zia
-
Patent number: 12425193Abstract: There is provided a computer implemented method for accessing a resource at a computing device, as well as for controlling access to a resource by a computing device. The computing device receives a policy indicating a set of conditions under which access to the resource is permitted, determines whether each of the conditions are initially present based on an output of one or more sensors of the device, and monitors the one or more sensors to detect a change in the presence of one or more of the conditions. In response to detecting the change in the presence of one or more of the conditions, the computing device determines whether each of the conditions are present. In response to determining that each of the conditions is present, access to the resource is enabled. If at least one of the conditions is not present, access to the resource is prevented.Type: GrantFiled: September 11, 2020Date of Patent: September 23, 2025Assignee: British Telecommunications Public Limited CompanyInventors: Ali Sajjad, Gery Ducatel, Gabriele Gelardi
-
Patent number: 12314362Abstract: Computer implemented methods for enrolling a user as an authenticated user of a computing device and for authenticating a user of a computing device are provided. The methods make use of behavioral biometrics to determine a set of shares that represent a secret credential according to a secret sharing scheme. The set of shares is initially determined when the user is enrolled based on typical measurements of the user's behavioral biometrics and authentication data indicating how to generate the set of shares from a user's behavioral biometrics is generated. When authenticating the user, the computing device can generate the set of shares based on the authentication data and measurements of the current user's behavioral biometrics. The computing device can use the generated set of shares to recreate a copy of the secret credential with which to authenticate the user.Type: GrantFiled: June 16, 2020Date of Patent: May 27, 2025Assignee: BRITISH TELECOMMUNICATIONS PUBLIC LIMITED COMPANYInventors: Gabriele Gelardi, Ali Sajjad, Gery Ducatel
-
Publication number: 20250133015Abstract: An aspect of the disclosure relates to a computer-implemented method of operating a software-defined network, the method comprising: initialising a plurality of paths through a data plane for traffic associated with a category of applications and/or services; selecting one of the plurality of paths to be an initial operational path; routing traffic associated with the category of applications and/or services via the initial operational path; subsequently obtaining data indicating that a trigger event has occurred; and responsive thereto: selecting a different one of the plurality of paths to be a replacement operational path; and routing traffic associated with the category of applications and/or services via the replacement operational path. Further aspects relate to a data processing system, a computer program, a computer-readable data carrier, and a data carrier signal.Type: ApplicationFiled: August 23, 2022Publication date: April 24, 2025Inventors: Behnam AZVINE, Ali SAJJAD
-
Patent number: 12278826Abstract: A computer-implemented method of operating a software-defined network, the method comprising: obtaining specifications of a plurality of data plane elements which together form a path through a data plane suitable for carrying traffic associated with a category of applications and/or services; determining, based on the specifications, which one or more of a plurality of security profiles the path is capable of complying with; selecting one of the one or more security profiles to be an initial security profile; routing traffic associated with the category of applications and/or services via the path in compliance with the initial security profile; subsequently obtaining an alert that network performance conditions have worsened; and responsive thereto: selecting a different one of the plurality of security profiles, that is less resource-intensive than the initial security profile, to be a replacement security profile; and routing traffic associated with the category of applications and/or services in complianType: GrantFiled: August 23, 2022Date of Patent: April 15, 2025Assignee: BRITISH TELECOMMUNICATIONS PUBLIC LIMITED COMPANYInventors: Behnam Azvine, Ali Sajjad
-
Publication number: 20250111053Abstract: Attestation method for verifying the integrity of an attester device by an attestation proxy (AP): sending a trusted platform module (TPM) quote request message directly to a virtual TPM (vTPM) uniquely associated with the attester device, to prompt the vTPM to: produce a set of platform configuration register (PCR) values based on measurements requested and received by the vTPM directly from the attester device, then send a TPM quote comprising the set of PCR values directly to the AP; the attestation method further comprising the AP: receiving the TPM quote; sending the TPM quote to a remote relying party (RP) to prompt the RP to: verify the TPM quote is as expected, then return a remote attestation indicator to the AP; receiving the remote attestation indicator; and producing an attestation result based on the remote attestation indicator, wherein the attestation result is negative when the remote attestation indicator is negative.Type: ApplicationFiled: November 21, 2022Publication date: April 3, 2025Inventors: Ali SAJJAD, Syed ZIA, Jamshed MEMON, Mamun ABU-TAIR
-
Publication number: 20250061236Abstract: A method comprising an attestation proxy (AP): sending a trusted platform module (TPM) quote request message directly to a virtual TPM (vTPM) uniquely associated with an attester device, to prompt the vTPM to: produce a set of platform configuration register (PCR) values based on measurements requested and received by the vTPM directly from the attester device, then send a TPM quote comprising the set of PCR values directly to the AP; the attestation method further comprising the AP: receiving the TPM quote; retrieving, from a local copy of a distributed ledger (DL), a latest set of PCR values recorded for the attester device; comparing that set of PCR values retrieved from the local copy of the DL with the set of PCR values received in the TPM quote to generate a local attestation indicator; and producing an attestation result based on the local attestation indicator.Type: ApplicationFiled: November 21, 2022Publication date: February 20, 2025Inventors: Ali SAJJAD, Syed ZIA, Jamshed MEMON, Mamun ABU-TAIR
-
Publication number: 20240275802Abstract: A computer-implemented method of operating a software-defined network, the method comprising: obtaining specifications of a plurality of data plane elements which together form a path through a data plane suitable for carrying traffic associated with a category of applications and/or services; determining, based on the specifications, which one or more of a plurality of security profiles the path is capable of complying with; selecting one of the one or more security profiles to be an initial security profile; routing traffic associated with the category of applications and/or services via the path in compliance with the initial security profile; subsequently obtaining an alert that network performance conditions have worsened; and responsive thereto: selecting a different one of the plurality of security profiles, that is less resource-intensive than the initial security profile, to be a replacement security profile; and routing traffic associated with the category of applications and/or services in complianType: ApplicationFiled: August 23, 2022Publication date: August 15, 2024Inventors: Behnam AZVINE, Ali SAJJAD
-
Publication number: 20240235832Abstract: A method and distributed system for exclusively sharing data between a data provider and one or more selected data recipients is disclosed. Known systems for exclusively sharing data with one or more selected data recipients involve the encryption of the data at a central storage service and limiting use of one or more centrally stored decryption keys to decrypt the data in accordance with an access control list maintained by the remote storage service provider. Ensuring robustness of key management in such systems requires the expenditure of a great deal of resource. This problem is addressed by a combination of two co-operating facilities in the disclosed distributed data sharing system. Firstly, a symmetric key exchange facility is provided which enables each data provider to exclusively derive 182 dedicated key encryption keys with respective selected data clients. Secondly, a device controlled by the data provider is arranged to encrypt the data using a data encryption key and.Type: ApplicationFiled: June 16, 2022Publication date: July 11, 2024Inventors: Ali SAJJAD, Mamun ABU-TAIR, Syed Muhammad Unsub ZIA
-
Publication number: 20240086241Abstract: A method of selecting an algorithm from a plurality of candidate algorithms for use by a processor-controlled device to perform an application. A respective value for one or more resource characteristics of the device is obtained. Based on the one or more values, one or more analogous reference devices having similar resource characteristics to the device are identified. One or more reference performance values for execution of each of the plurality of candidate algorithms on each of the analogous reference devices are obtained. The algorithm is selected based on the one or more reference performance values.Type: ApplicationFiled: March 16, 2022Publication date: March 14, 2024Inventor: Ali SAJJAD
-
Publication number: 20220376902Abstract: There is provided a computer implemented method for accessing a resource at a computing device, as well as for controlling access to a resource by a computing device. The computing device receives a policy indicating a set of conditions under which access to the resource is permitted, determines whether each of the conditions are initially present based on an output of one or more sensors of the device, and monitors the one or more sensors to detect a change in the presence of one or more of the conditions. In response to detecting the change in the presence of one or more of the conditions, the computing device determines whether each of the conditions are present. In response to determining that each of the conditions is present, access to the resource is enabled. If at least one of the conditions is not present, access to the resource is prevented.Type: ApplicationFiled: September 11, 2020Publication date: November 24, 2022Inventors: Ali SAJJAD, Gery DUCATEL, Gabriele GELARDI
-
Patent number: 11474847Abstract: A computer implemented method of converting a serialized virtual machine (VM) for a source virtualized computing environment, the serialized VM being stored in a data file having also metadata for instantiating the serialized VM in the source environment, the method including supplementing the data file with a software adapter including a plurality of executable disk image converters, each disk image converter being suitable for converting the serialized VM between disparate virtualized computing environments; a plurality of metadata mappings, each metadata mapping defining how the metadata is converted between disparate virtual computing environments; and executable code for effecting a conversion by executing an appropriate disk image converter and performing an appropriate metadata conversion to convert the data file for a target virtualized computing environment, such that the supplemented data file is operable to self-convert between the source virtualized computing environment and the target virtualizedType: GrantFiled: December 3, 2018Date of Patent: October 18, 2022Assignee: British Telecommunications Public Limited CompanyInventors: Ali Sajjad, Fadi El-Moussa
-
Patent number: 11461460Abstract: A computer implemented method of securing an application executing in a software container deployed in a computer system includes providing access to the application selectively in accordance with access control rules by sharing an encryption key with authorized accessors.Type: GrantFiled: December 3, 2018Date of Patent: October 4, 2022Assignee: British Telecommunications Public Limited CompanyInventors: Fadi El-Moussa, Ali Sajjad
-
Patent number: 11451387Abstract: A computer implemented method of generating cryptographic keys for a plurality of hardware security modules (HSMs), the method including generating a plurality of cryptographic keys for use by the HSMs in providing cryptography functions, wherein the cryptographic keys are generated based on numerical data generated by a hardware random number generator; and storing the generated cryptographic keys in a secure key store, such that a key in the key store utilized by an HSM is flagged as utilized to prevent other HSMs utilizing the same key, so as to provide a rate of generation and storage of the cryptographic keys unconstrained by the resources of any HSM.Type: GrantFiled: May 2, 2019Date of Patent: September 20, 2022Assignee: BRITISH TELECOMMUNICATIONS PUBLIC LIMITED COMPANYInventors: Joshua Daniel, Ali Sajjad
-
Publication number: 20220261466Abstract: Computer implemented methods for enrolling a user as an authenticated user of a computing device and for authenticating a user of a computing device are provided. The methods make use of behavioral biometrics to determine a set of shares that represent a secret credential according to a secret sharing scheme. The set of shares is initially determined when the user is enrolled based on typical measurements of the user's behavioral biometrics and authentication data indicating how to generate the set of shares from a user's behavioral biometrics is generated. When authenticating the user, the computing device can generate the set of shares based on the authentication data and measurements of the current user's behavioral biometrics. The computing device can use the generated set of shares to recreate a copy of the secret credential with which to authenticate the user.Type: ApplicationFiled: June 16, 2020Publication date: August 18, 2022Inventors: Gabriele GELARDI, Ali Sajjad, Gery DUCATEL
-
Patent number: 11411726Abstract: A computer implemented method of generating cryptographic keys for a hardware security module (HSM), the method including generating a plurality of cryptographic keys and storing the cryptographic keys for use by the HSM in providing cryptography functions, wherein the cryptographic keys are generated based on numerical data generated by a hardware random number generator, such that a rate of generation of the cryptographic keys unconstrained by the resources of the HSM, wherein the hardware random number generator operates based on a plurality of statistically random entropy data sources originating from natural phenomena so as to increase a degree of randomness of the numerical data.Type: GrantFiled: May 2, 2019Date of Patent: August 9, 2022Assignee: BRITISH TELECOMMUNICATIONS PUBLIC LIMITED COMPANYInventors: Joshua Daniel, Ali Sajjad
-
Publication number: 20220159020Abstract: There is provided a computer implemented method, computer system and computer program for protecting a network. The method comprises: gathering traffic data for the network; identifying a set of loT devices in the network based on the output from a machine learning model for classifying loT devices using features extracted from the traffic data that are indicative of an loT device; and causing one or more predetermined actions to be taken in respect of the set of loT devices to protect the network.Type: ApplicationFiled: March 3, 2020Publication date: May 19, 2022Inventors: Xiao-Si WANG, Ali SAJJAD
-
Publication number: 20210218564Abstract: A computer implemented method of generating cryptographic keys for a plurality of hardware security modules (HSMs), the method including generating a plurality of cryptographic keys for use by the HSMs in providing cryptography functions, wherein the cryptographic keys are generated based on numerical data generated by a hardware random number generator; and storing the generated cryptographic keys in a secure key store, such that a key in the key store utilized by an HSM is flagged as utilized to prevent other HSMs utilizing the same key, so as to provide a rate of generation and storage of the cryptographic keys unconstrained by the resources of any HSM.Type: ApplicationFiled: May 2, 2019Publication date: July 15, 2021Inventors: Joshua DANIEL, Ali SAJJAD