Patents by Inventor Hirofumi Ueda
Hirofumi Ueda has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Publication number: 20260170148Abstract: An information presentation device includes an acquisition unit that acquires attack data including an attack technique in a cyberattack test, a search unit that searches for a method for using a security tool correlated with the attack technique, a generation unit that generates an instruction to request presentation of an attack instruction using the method for using the security tool found in the search, and an output unit that outputs attack instruction data including the attack instruction output from a model in response to an input of the instruction.Type: ApplicationFiled: October 27, 2025Publication date: June 18, 2026Applicant: NEC CorporationInventors: Shunichi KINOSHITA, Hirofumi UEDA, Norio YAMAGAKI, Mamoru SAITA
-
Publication number: 20260161633Abstract: Whether the information indicated by a plurality of pieces of text data describing an information security-related event is consistent is determined. An acquisition unit acquires a plurality of pieces of text data describing an information security-related event; an analysis unit analyzes whether information indicated by the pieces of acquired text data is consistent by using information security-related knowledge information; and an output unit outputs information based on an analysis result as to whether the information indicated by the pieces of text data is consistent.Type: ApplicationFiled: October 24, 2025Publication date: June 11, 2026Applicant: NEC CorporationInventors: Mamoru SAITA, Norio YAMAGAKI, Shunichi KINOSHITA, Hirofumi UEDA
-
Publication number: 20260156139Abstract: To provide a virtual model for a communication system, the virtual model being required for specific diagnosis of the security risk of the communication system. An acquisition unit (11) acquires the inspection result of an information security inspection on a device constituting a communication system, an extraction unit (12) extracts, from the inspection result, security inspection information including at least one of first information about a library function used by the constituent device or second information about the presence or absence of access to a file via the library function, and a generation unit (13) generates a virtual model for the communication system by using configuration information for identifying a constituent component of an information communication device and the security inspection information.Type: ApplicationFiled: January 21, 2026Publication date: June 4, 2026Applicant: NEC CorporationInventors: Hirofumi UEDA, Kohei TATARA
-
Publication number: 20260154419Abstract: A diagnostic device according to an aspect of the present disclosure includes: at least one memory storing a set of instructions; and at least one processor configured to execute the set of instructions to: estimate a management impact that is a magnitude of influence on revenue loss resulting due to an attack on a device included in a diagnostic target system based on information on a purpose of the device; identify an entry point device and an attack target device in the device by using information on a configuration of the diagnostic target system and the management impact of the device; detect an attack route through which the attack from the entry point device to the attack target device is capable of being successful; and output information on a diagnostic result indicating the management impact due to the attack on the attack target device through the detected attack route.Type: ApplicationFiled: November 12, 2025Publication date: June 4, 2026Applicant: NEC CorporationInventors: Hirofumi UEDA, Tomohiko Yagyu, Ryo Mizushima, Shunichi Kinoshita
-
Patent number: 12634335Abstract: An attack scenario generating apparatus including: first attack step detection unit executes an attack simulation on a first virtual model obtained from a storage device in which a plurality of virtual models used to represent a target system are stored, and detects a first attack step that satisfies a damage condition with which damage occurs in the first virtual model; an input/output condition extraction unit extracts an input condition or an output condition of the first virtual model from the detected first attack step, or both the input condition and the output condition; a second attack step detection unit executes an attack simulation on a second virtual model obtained from the storage device, and detects a second attack step in which output of the second virtual model satisfies the input condition; and a combination unit combines the first attack step and the second attack step to generate an attack scenario.Type: GrantFiled: June 24, 2021Date of Patent: May 19, 2026Assignee: NEC CORPORATIONInventors: Masafumi Watanabe, Hirofumi Ueda
-
Publication number: 20260133806Abstract: An information management apparatus acquires first evaluation information for at least a first element among a plurality of elements constituting an information system in a first stage, and registers first configuration information corresponding to the first element and the first evaluation information in a database in association; acquires first state information indicating a state of the first element in a second stage other than the first stage, and registers the first configuration information and the first state information in the database in association; and, in response to a display request, displays a plurality of pieces of configuration information respectively corresponding to the plurality of elements in a connection form based on a relationship between the elements, and displays the first configuration information, the first state information, and the first evaluation information in a connection form based on an association in the database.Type: ApplicationFiled: November 15, 2021Publication date: May 14, 2026Applicants: NEC CORPORATION, NIPPON TELEGRAPH AND TELEPHONE CORPORATIONInventors: Kazuaki NAKAJIMA, Hirofumi UEDA, Lo FURUYAMA, Yoshiaki NAKAJIMA, Ryota SATO
-
Publication number: 20260126105Abstract: A power transmission resin gear includes an annular resin part having, on an outer peripheral surface thereof, teeth of a gear. The annular resin part includes an annular inner resin member that covers an outer periphery of a core metal and an annular outer resin member that covers an outer periphery of the annular inner resin member. The annular inner resin member has a plurality of axially downgauged portions arranged at intervals in a circumferential direction. The annular outer resin member has filling portions respectively filling the axially downgauged portions and an axial surface covering portion that is located radially inward of a tooth side of the teeth and covers the filling portions.Type: ApplicationFiled: October 3, 2025Publication date: May 7, 2026Applicants: JTEKT CORPORATION, NAKANISHI METAL WORKS CO., LTD.Inventors: Hirofumi UEDA, Arata KIKUCHI, Taichi YAMAMOTO, Masayoshi NAKAMURA, Yukimasa NAKA
-
Patent number: 12609954Abstract: Generation of an attack scenario to be used for risk analysis of a system to be analyzed is enabled without depending on the technique and the knowledge of a person who creates it. An analysis result acquisition means acquires a risk analysis result of a first risk analysis performed on a system to be analyzed. A condition acquisition means acquires conditions for an attack scenario to be used for a second risk analysis on the basis of an attack scenario table and the risk analysis result. An attack scenario generation means generates an attack scenario to be used for the second risk analysis on the basis of the conditions for the attack scenario acquired by the condition acquisition means.Type: GrantFiled: October 22, 2020Date of Patent: April 21, 2026Assignee: NEC CORPORATIONInventors: Ryo Mizushima, Hirofumi Ueda, Tomohiko Yagyu
-
Patent number: 12574402Abstract: To provide a virtual model for a communication system, the virtual model being required for specific diagnosis of the security risk of the communication system. An acquisition unit (11) acquires the inspection result of an information security inspection on a device constituting a communication system, an extraction unit (12) extracts, from the inspection result, security inspection information including at least one of first information about a library function used by the constituent device or second information about the presence or absence of access to a file via the library function, and a generation unit (13) generates a virtual model for the communication system by using configuration information for identifying a constituent component of an information communication device and the security inspection information.Type: GrantFiled: October 22, 2021Date of Patent: March 10, 2026Assignee: NEC CORPORATIONInventors: Hirofumi Ueda, Kohei Tatara
-
Publication number: 20260067074Abstract: A data distribution system that distributes an encrypted data from a transmitting device to a receiving device via a relay device with support by a key issuing device, wherein the key issuing device is configured to generate public parameters for ElGamal encryption and a secret key for attribute-based encryption, send the public parameters to the transmitting device and keep the secret key; and the transmitting device is configured to encrypt data by the public parameters, create a user defined policy for each data ID, attach the defined policy for the corresponding data ID to the encrypted data and send the encrypted data with the user defined policy to the relay device.Type: ApplicationFiled: August 25, 2025Publication date: March 5, 2026Applicant: NEC CorporationInventors: Nakul GHATE, Hirofumi UEDA, Daichi AOKI
-
Patent number: 12565953Abstract: A fitting nut made of a resin material includes: a hollow, large-diameter tube portion having a female thread formed on its inner peripheral wall; and a small-diameter tube portion that is continuous to the large-diameter tube portion and having a hollow cylindrical shape with a smaller diameter than the large-diameter tube portion. The small-diameter tube portion includes, in the outer peripheral wall thereof, a plurality of engagement grooves that are depressed inwardly in the diameter direction of the small-diameter tube portion and extend along the longitudinal direction that is orthogonal to the diameter direction.Type: GrantFiled: September 21, 2020Date of Patent: March 3, 2026Assignee: SMC CORPORATIONInventors: Yoshitada Doi, Yuzuru Okita, Yoji Niimi, Hirofumi Ueda, Tsugumichi Fujiwara
-
Patent number: 12553553Abstract: A fitting nut made of a resin material includes: a hollow, large-diameter tube portion having a female thread formed on its inner peripheral wall; and a small-diameter tube portion that is continuous to the large-diameter tube portion and having a hollow cylindrical shape with a smaller diameter than the large-diameter tube portion. The small-diameter tube portion includes, in the outer peripheral wall thereof, a plurality of engagement grooves that are depressed inwardly in the diameter direction of the small-diameter tube portion and extend along the longitudinal direction that is orthogonal to the diameter direction.Type: GrantFiled: April 11, 2024Date of Patent: February 17, 2026Assignee: SMC CORPORATIONInventors: Yoshitada Doi, Yuzuru Okita, Yoji Niimi, Hirofumi Ueda, Tsugumichi Fujiwara
-
Patent number: 12314399Abstract: Attack path information includes information about an attack path including at least one attack step including an attack source, an attack destination, and an attack method. Vulnerability specification means refers to the attack path information and thereby specifies vulnerabilities exploitable by an attack on the attack destination in the attack step. In the vulnerability information DB, vulnerabilities and presence/absence of exploit codes for the vulnerabilities are stored and associated with each other. Diagnosis evaluation generation means refers to the vulnerability information DB, and thereby examines whether or not there is an exploit code for the specified vulnerability and generates, for the attack step, a risk diagnosis evaluation including the number of specified vulnerabilities and the presence/absence of the exploit codes therefor. Output means outputs the attack step and the risk diagnosis evaluation while associating them with each other.Type: GrantFiled: September 27, 2019Date of Patent: May 27, 2025Assignee: NEC CORPORATIONInventors: Ryo Mizushima, Hirofumi Ueda, Tomohiko Yagyu
-
Publication number: 20250141910Abstract: To provide a virtual model for a communication system, the virtual model being required for specific diagnosis of the security risk of the communication system. An acquisition unit (11) acquires the inspection result of an information security inspection on a device constituting a communication system, an extraction unit (12) extracts, from the inspection result, security inspection information including at least one of first information about a library function used by the constituent device or second information about the presence or absence of access to a file via the library function, and a generation unit (13) generates a virtual model for the communication system by using configuration information for identifying a constituent component of an information communication device and the security inspection information.Type: ApplicationFiled: October 22, 2021Publication date: May 1, 2025Applicant: NEC CorporationInventors: Hirofumi UEDA, Kohei Tatara
-
Patent number: 12287883Abstract: An analysis unit 6 generates one or more pairs of a start point fact which is a fact representing possibility of the attack in a device that is a start point and an end point fact which is a fact representing possibility of the attack in the device that is an end point, analyzes, for each pair, whether or not it is possible to derive the end point fact from the start point fact, based on facts representing states of the devices generated based on information regarding the device that is the start point and information regarding the device that is the end point, the start point fact, and one or more analysis rules for analyzing the attack, and generates an attack scenario in a case where it is possible to derive the end point fact from the start point fact.Type: GrantFiled: November 15, 2019Date of Patent: April 29, 2025Assignee: NEC CORPORATIONInventors: Yoshinobu Ohta, Hirofumi Ueda, Shunichi Kinoshita, Ryo Mizushima
-
Publication number: 20250119443Abstract: An anomaly cause estimation apparatus includes: an anomaly detection unit converts a data series acquired in a time series from a plurality of components provided in a target system into an anomaly level data series, and detects an anomaly based on the obtained anomaly level data series; and an anomaly propagation estimation unit inputs a target anomaly level data series, extracted from the anomaly level data series, for a period before a point in time at which the anomaly is detected, a target data series corresponding to the target anomaly level data series, and information indicating a causal relationship between the components to an anomaly propagation estimation model, and estimates an anomaly propagation likelihood of the anomaly propagating between the components.Type: ApplicationFiled: June 10, 2021Publication date: April 10, 2025Applicant: NEC CorporationInventors: Shohei MITANI, Hirofumi UEDA
-
Patent number: 12254096Abstract: A comparison means compares a first risk analysis result with a second risk analysis result. The first risk analysis result includes a first risk evaluation value. The second risk analysis result includes a second risk evaluation value. Based on the result of the comparison, a display means displays the first risk evaluation value in such a manner that a first risk evaluation value for which there is a second risk evaluation value, in the second risk analysis result, for an attack step of which an attack destination coincides with an asset included in the first risk analysis result and an attack method coincides with an attack method included in the first risk analysis result can be distinguished from a first risk evaluation value for which there is no such second risk evaluation value.Type: GrantFiled: September 27, 2019Date of Patent: March 18, 2025Assignee: NEC CORPORATIONInventors: Ryo Mizushima, Hirofumi Ueda, Tomohiko Yagyu
-
Publication number: 20250068750Abstract: An analysis apparatus according to an example embodiment of the present disclosure includes at least one memory configured to store instructions; and at least one processor configured to execute the instructions to acquire a data set in which a plurality of combinations of a first pattern of one or more elements indicating an access attribute and an access control action associated with the first pattern are defined, and a second pattern of one or more elements indicating an access attribute, and estimate at least one of an order or magnitude of the degree of influence of the second pattern influencing the action by using the data set and the second pattern.Type: ApplicationFiled: January 26, 2022Publication date: February 27, 2025Applicant: NEC CorporationInventors: Shohei MITANI, Hirofumi Ueda
-
Publication number: 20250063048Abstract: An information processing apparatus according to an example embodiment of the present disclosure includes at least one memory configured to store instructions; and at least one processor configured to execute the instructions to: acquire a data set in which a plurality of combinations of a pattern of a plurality of elements indicating an access attribute and an access control action associated with the pattern of the elements are defined and request a user to input an action associated with a pattern of an element not covered by the data set in a case in which the data set does not cover an action associated with one or more assumed patterns of an element.Type: ApplicationFiled: January 26, 2022Publication date: February 20, 2025Applicant: NEC CorporationInventors: Shohei MITANI, Hirofumi Ueda
-
Publication number: 20240411893Abstract: A determination system according to an aspect of the present disclosure includes: at least one memory storing a set of instructions; and at least one processor configured to execute the set of instructions to: receive a first inspection result that is a result of a first inspection of vulnerability of target software; receive a second inspection result that is a result of a second inspection of vulnerability of the target software; determine validity of the first inspection from undetected vulnerability that is vulnerability detected in the result of the second inspection and not detected in the result of the first inspection; and output a result of determination of the validity.Type: ApplicationFiled: November 9, 2021Publication date: December 12, 2024Applicant: NEC CorporationInventors: Kazuaki NAKAJIMA, Io FURUYAMA, Hirofumi UEDA