Patents by Inventor Nishanth Chandran
Nishanth Chandran has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Publication number: 20260189370Abstract: An access control system is disclosed for controlling access to a resource. A request is received by a location attribute policy (LAP) server to access an encrypted resource. The LAP server accesses a resource policy that identifies requirements for granting access to the encrypted resource, such as a list of attributes of the requestor that are required and a dynamic attribute requirement of the requestor. The LAP server receives a cryptographic proof from the computing device that the requestor possesses the attributes and validates the proof based at least on information obtained from a trusted ledger. Once the proof is validated, the LAP server provides a shared secret associated with the dynamic attribute requirement to a decryption algorithm. The decryption algorithm uses the dynamic attribute shared secret in combination with one or more attribute shared secrets from the requestor to generate a decryption key for the encrypted resource.Type: ApplicationFiled: February 19, 2026Publication date: July 2, 2026Inventors: Ramarathnam VENKATESAN, Nishanth CHANDRAN, Ganesh ANANTHANARAYANAN, Panagiotis ANTONOPOULOS, Srinath T.V. SETTY, Daniel John CARROLL, JR., Kiran MUTHABATULLA, Yuanchao SHU, Sanjeev MEHROTRA
-
Patent number: 12647277Abstract: Data diode systems and methods are disclosed herein for enhancing data security. Encrypted data transmitted from a first node (e.g., an entity coupled to a network) is received. The data transmitted is encrypted with a public key associated with a second node (e.g., the node to which to which the encrypted data is transmitted). The encrypted data is decrypted with a private key associated with the second node to generate decrypted data. A determination is made whether a digital signature in the decrypted data corresponds to a ledger entry mapped to the first node in a first set of ledger entries. The first node is verified to be a trusted entity based on the digital signature having been determined to correspond to the ledger entry. Based on the verification, the transmission of the encrypted data from the first node is determined to be a permissible data transmission.Type: GrantFiled: May 31, 2023Date of Patent: June 2, 2026Assignee: MICROSOFT TECHNOLOGY LICENSING, LLCInventors: Ramarathnam Venkatesan, Nishanth Chandran, Panagiotis Antonopoulos, Christoph Berlin, Michael James Zwilling
-
Patent number: 12602497Abstract: Verifiable attribute maps that maintain references to identities and attribute information associated with the identities are disclosed. A verifiable attribute map is maintained by a ledger database that provides tamper-resistant/evident capabilities for tables (comprising the map) thereof. For instance, when a materialized view of the database is generated, the database provides a digest representative of a state thereof to computing devices that access the map for the attribute information. When the database receives a request from a device to access the map, the digest is received along therewith. The database is validated based on the digest to determine whether the database has been tampered with since the provision of the digest. Responsive to a successful validation, the database provides access in accordance with the request. When attribute information in the map is updated, the database subsequently generates a new digest, which is provided to the computing device.Type: GrantFiled: September 23, 2022Date of Patent: April 14, 2026Assignee: MICROSOFT TECHNOLOGY LICENSING, LLCInventors: Ramarathnam Venkatesan, Srinath T. V. Setty, Nishanth Chandran, Panagiotis Antonopoulos
-
Patent number: 12580740Abstract: An access control system is disclosed for controlling access to a resource. A request is received by a location attribute policy (LAP) server to access an encrypted resource. The LAP server accesses a resource policy that identifies requirements for granting access to the encrypted resource, such as a list of attributes of the requestor that are required and a dynamic attribute requirement of the requestor. The LAP server receives a cryptographic proof from the computing device that the requestor possesses the attributes and validates the proof based at least on information obtained from a trusted ledger. Once the proof is validated, the LAP server provides a shared secret associated with the dynamic attribute requirement to a decryption algorithm. The decryption algorithm uses the dynamic attribute shared secret in combination with one or more attribute shared secrets from the requestor to generate a decryption key for the encrypted resource.Type: GrantFiled: October 10, 2022Date of Patent: March 17, 2026Assignee: MICROSOFT TECHNOLOGY LICENSING, LLCInventors: Ramarathnam Venkatesan, Nishanth Chandran, Ganesh Ananthanarayanan, Panagiotis Antonopoulos, Srinath T. V. Setty, Daniel John Carroll, Jr., Kiran Muthabatulla, Yuanchao Shu, Sanjeev Mehrotra
-
Publication number: 20250323777Abstract: The technology described herein is related to a hybrid neural network that divides operations of a neural network layer between a server and a client device. In an aspect, one or more liner operations of a neural network layer are performed on the client, while non-linear operations, such as an activation function, are performed on the server. In an aspect, the technology described herein maintains network security by encrypting portions of the client-side components. The encrypted portions may be learned values, which may also be described as learned parameters. In aspects, homomorphic encryption is used.Type: ApplicationFiled: April 15, 2024Publication date: October 16, 2025Inventors: Yehonathan Refael Kalim, Adam Hakim, Nishanth Chandran
-
Patent number: 12445415Abstract: Embodiments described herein are directed to a verifiable identity map that maintains identities and public keys associated with the identities. The map is maintained by a ledger database that provides tamper-resistant/evident capabilities for tables (comprising the map) thereof. For instance, when a materialized view of the database is generated, the database provides a digest representative of a state thereof to computing devices that access the map for the keys. When the database receives a request from a device to access the map, the digest is received along therewith. The database is validated based on the digest to determine whether the database has been tampered with since the provision of the digest. Responsive to a successful validation, the database provides access in accordance with the request. When a key in the map is updated, the database subsequently generates a new digest, which is provided to the computing device.Type: GrantFiled: August 11, 2022Date of Patent: October 14, 2025Assignee: MICROSOFT TECHNOLOGY LICENSING, LLCInventors: Ramarathnam Venkatesan, Nishanth Chandran, Srinath Setty, Panagiotis Antonopoulos, Satyanarayana Venkata Lokam
-
Patent number: 12438883Abstract: An entity is enabled to access encrypted resources in response to verifying access criteria of a region-based security policy is met. For example, a resource request to access an encrypted resource is received from an entity. A determination that the encrypted resource is assigned to a first region and is protected by a region-based security policy is made. A proof of a region attribute indicating that the entity possesses the region attribute is received from the entity, the region attribute indicates the entity is associated with the first region. An encrypted version of the region attribute is obtained from a ledger database. The resource request is validated based at least on the encrypted attribute and the proof of the region attribute. A verification is made that an access criteria of the region-based security policy is met. The entity is provided access to the encrypted resource.Type: GrantFiled: May 17, 2023Date of Patent: October 7, 2025Assignee: MICROSOFT TECHNOLOGY LICENSING, LLCInventors: Ramarathnam Venkatesan, Nishanth Chandran, Srinath T. V. Setty, Christoph Berlin, Ulrich Homann, Michael James Zwilling
-
Publication number: 20250303994Abstract: Disclosed herein are systems and methods for detecting a vehicle collision. A computing device can determine a vehicle event based on inertial sensor data and speed from at least one sensor in a housing inside a cabin of a vehicle, and classify the vehicle event as a collision event or a non-collision event based on the inertial sensor data, the speed, and vehicle class data of the vehicle. The computing device can classify an event subclass of the collision event or the non-collision event based on the inertial sensor data, the speed, and the vehicle class data of the vehicle. The computing device can generate a notification based on the event subclass.Type: ApplicationFiled: May 26, 2023Publication date: October 2, 2025Applicant: NETRADYNE, INC.Inventors: Anirban Nag, Nishanth Chandran, Pratik Verma, Jijo Jose, Borhan Vasli
-
Publication number: 20250300992Abstract: An entity is enabled to access encrypted resources in response to verifying access criteria of a region-based security policy is met. For example, a resource request to access an encrypted resource is received from an entity. A determination that the encrypted resource is assigned to a first region and is protected by a region-based security policy is made. A proof of a region attribute indicating that the entity possesses the region attribute is received from the entity, the region attribute indicates the entity is associated with the first region. An encrypted version of the region attribute is obtained from a ledger database. The resource request is validated based at least on the encrypted attribute and the proof of the region attribute. A verification is made that an access criteria of the region-based security policy is met. The entity is provided access to the encrypted resource.Type: ApplicationFiled: June 6, 2025Publication date: September 25, 2025Inventors: Ramarathnam VENKATESAN, Nishanth CHANDRAN, Srinath T.V. SETTY, Christoph BERLIN, Ulrich HOMANN, Michael James ZWILLING
-
Publication number: 20250291947Abstract: Embodiments described herein enable at least one of a plurality of entities to access data protected by a security policy in response to validating respective digital access requests from the entities. The respective digital access requests are received, each comprising a proof. For each request, an encrypted secret share is obtained from a respective ledger database. Each request is validated based at least on the respective encrypted secret share and the proof, without decrypting the respective encrypted secret share. In response to validating all of the requests, a verification that an access criteria of a security policy is met is made. If so, at least one of the entities is provided with access to data protected by the security policy. In an aspect, embodiments enable a blind subpoena to be performed. In another aspect, embodiments enable the at least one entity to access the data for an isolated purpose.Type: ApplicationFiled: May 30, 2025Publication date: September 18, 2025Inventors: Ramarathnam VENKATESAN, Nishanth CHANDRAN, Panagiotis ANTONOPOULOS, Srinath T.V. SETTY, Basil CHERIAN, Daniel John CARROLL, JR., Jason Sydney BARNWELL
-
Patent number: 12395331Abstract: A decryption key is recovered that is utilized to decrypt an encrypted resource. One or more location attribute policy (LAP) servers determine whether a user attempting to access a resource has the necessary attributes to access the resource and is in a valid location in which the user is required to be to access the resource. The attributes and location are defined by a policy assigned to the resource. To verify that the user has the required attributes, the LAP server(s) request a cryptographic proof from the user that proves that the user has the required attributes. Upon validating the proof, a first portion of the decryption key is released. The LAP server(s) release a second portion of the decryption key after verifying that the user is in the required location. The LAP server(s) generate the decryption key based on the released portions.Type: GrantFiled: September 13, 2022Date of Patent: August 19, 2025Assignee: MICROSOFT TECHNOLOGY LICENSING, LLCInventors: Ramarathnam Venkatesan, Nishanth Chandran
-
Patent number: 12393720Abstract: Embodiments described herein enable at least one of a plurality of entities to access data protected by a security policy in response to validating respective digital access requests from the entities. The respective digital access requests are received, each comprising a proof. For each request, an encrypted secret share is obtained from a respective ledger database. Each request is validated based at least on the respective encrypted secret share and the proof, without decrypting the respective encrypted secret share. In response to validating all of the requests, a verification that an access criteria of a security policy is met is made. If so, at least one of the entities is provided with access to data protected by the security policy. In an aspect, embodiments enable a blind subpoena to be performed. In another aspect, embodiments enable the at least one entity to access the data for an isolated purpose.Type: GrantFiled: October 7, 2022Date of Patent: August 19, 2025Assignee: MICROSOFT TECHNOLOGY LICENSING, LLCInventors: Ramarathnam Venkatesan, Nishanth Chandran, Panagiotis Antonopoulos, Srinath T. V. Setty, Basil Cherian, Daniel John Carroll, Jr., Jason Sydney Barnwell
-
Patent number: 12346830Abstract: A secure inference over Deep Neural Networks (DNNs) using secure two-party computation to perform privacy-preserving machine learning. The secure inference uses a particular type of comparison that can be used as a building block for various layers in the DNN including, for example, ReLU activations and divisions. The comparison securely computes a Boolean share of a bit representing whether input value x is less than input value y, where x is held by a user of the DNN, and where y is held by a provider of the DNN. Each party computing system parses their input into leaf strings of multiple bits. This is much more efficient than if the leaf strings were individual bits. Accordingly, the secure inference described herein is more readily adapted for using in complex DNNs.Type: GrantFiled: October 30, 2020Date of Patent: July 1, 2025Assignee: Microsoft Technology Licensing, LLCInventors: Nishanth Chandran, Divya Gupta, Aseem Rastogi, Rahul Sharma, Nishant Kumar, Mayank Rathee, Deevashwer Rathee
-
Publication number: 20250193159Abstract: A verifiable identity map maintains identities and public keys associated with the identities. The map is maintained by a ledger database that provides tamper-resistant/evident capabilities for tables (comprising the map) thereof. For instance, when a materialized view of the database is generated, the database provides a digest representative of a state thereof to computing devices that access the map for the keys. When the database receives a request from a device to access the map, the digest is received along therewith. The database is validated based on the digest to determine whether the database has been tampered with since the provision of the digest. Responsive to a successful validation, the database provides access in accordance with the request. When a key in the map is updated, the database subsequently generates a new digest, which is provided to the computing device.Type: ApplicationFiled: February 12, 2025Publication date: June 12, 2025Inventors: Ramarathnam VENKATESAN, Nishanth CHANDRAN, Srinath SETTY, Panagiotis ANTONOPOULOS, Satyanarayana Venkata LOKAM
-
Publication number: 20250037072Abstract: The present disclosure relates to methods and systems that preserve privacy in a secure multi-party computation (MPC) framework in multi-agent reinforcement learning (MARL). The methods and systems use a secure MPC framework that allows for direct computation on encrypted data and enables parties to learn from others while keeping their own information private. The methods and systems provide a learning mechanism that carries out floating point operations in a privacy-preserving manner.Type: ApplicationFiled: September 26, 2023Publication date: January 30, 2025Inventors: Peeyush KUMAR, Ananta MUKHERJEE, Boling YANG, Nishanth CHANDRAN, Divya GUPTA
-
Publication number: 20240406002Abstract: Data diode systems and methods are disclosed herein for enhancing data security. Encrypted data transmitted from a first node (e.g., an entity coupled to a network) is received. The data transmitted is encrypted with a public key associated with a second node (e.g., the node to which to which the encrypted data is transmitted). The encrypted data is decrypted with a private key associated with the second node to generate decrypted data. A determination is made whether a digital signature in the decrypted data corresponds to a ledger entry mapped to the first node in a first set of ledger entries. The first node is verified to be a trusted entity based on the digital signature having been determined to correspond to the ledger entry. Based on the verification, the transmission of the encrypted data from the first node is determined to be a permissible data transmission.Type: ApplicationFiled: May 31, 2023Publication date: December 5, 2024Inventors: Ramarathnam VENKATESAN, Nishanth CHANDRAN, Panagiotis ANTONOPOULOS, Christoph BERLIN, Michael James ZWILLING
-
Publication number: 20240388589Abstract: An entity is enabled to access encrypted resources in response to verifying access criteria of a region-based security policy is met. For example, a resource request to access an encrypted resource is received from an entity. A determination that the encrypted resource is assigned to a first region and is protected by a region-based security policy is made. A proof of a region attribute indicating that the entity possesses the region attribute is received from the entity, the region attribute indicates the entity is associated with the first region. An encrypted version of the region attribute is obtained from a ledger database. The resource request is validated based at least on the encrypted attribute and the proof of the region attribute. A verification is made that an access criteria of the region-based security policy is met. The entity is provided access to the encrypted resource.Type: ApplicationFiled: May 17, 2023Publication date: November 21, 2024Inventors: Ramarathnam VENKATESAN, Nishanth CHANDRAN, Srinath T. V. SETTY, Christoph BERLIN, Ulrich HOMANN, Michael James ZWILLING
-
Publication number: 20240121081Abstract: An access control system is disclosed for controlling access to a resource. A request is received by a location attribute policy (LAP) server to access an encrypted resource. The LAP server accesses a resource policy that identifies requirements for granting access to the encrypted resource, such as a list of attributes of the requestor that are required and a dynamic attribute requirement of the requestor. The LAP server receives a cryptographic proof from the computing device that the requestor possesses the attributes and validates the proof based at least on information obtained from a trusted ledger. Once the proof is validated, the LAP server provides a shared secret associated with the dynamic attribute requirement to a decryption algorithm. The decryption algorithm uses the dynamic attribute shared secret in combination with one or more attribute shared secrets from the requestor to generate a decryption key for the encrypted resource.Type: ApplicationFiled: October 10, 2022Publication date: April 11, 2024Inventors: Ramarathnam VENKATESAN, Nishanth CHANDRAN, Ganesh ANANTHANARAYANAN, Panagiotis ANTONOPOULOS, Srinath T.V. SETTY, Daniel John CARROLL, JR., Kiran MUTHABATULLA, Yuanchao SHU, Sanjeev MEHROTRA
-
Publication number: 20240119168Abstract: Embodiments described herein enable at least one of a plurality of entities to access data protected by a security policy in response to validating respective digital access requests from the entities. The respective digital access requests are received, each comprising a proof. For each request, an encrypted secret share is obtained from a respective ledger database. Each request is validated based at least on the respective encrypted secret share and the proof, without decrypting the respective encrypted secret share. In response to validating all of the requests, a verification that an access criteria of a security policy is met is made. If so, at least one of the entities is provided with access to data protected by the security policy. In an aspect, embodiments enable a blind subpoena to be performed. In another aspect, embodiments enable the at least one entity to access the data for an isolated purpose.Type: ApplicationFiled: October 7, 2022Publication date: April 11, 2024Inventors: Ramarathnam VENKATESAN, Nishanth CHANDRAN, Panagiotis ANTONOPOULOS, Srinath T.V. SETTY, Basil CHERIAN, Daniel John CARROLL, JR., Jason Sydney BARNWELL
-
Publication number: 20240104229Abstract: Verifiable attribute maps that maintain references to identities and attribute information associated with the identities are disclosed. A verifiable attribute map is maintained by a ledger database that provides tamper-resistant/evident capabilities for tables (comprising the map) thereof. For instance, when a materialized view of the database is generated, the database provides a digest representative of a state thereof to computing devices that access the map for the attribute information. When the database receives a request from a device to access the map, the digest is received along therewith. The database is validated based on the digest to determine whether the database has been tampered with since the provision of the digest. Responsive to a successful validation, the database provides access in accordance with the request. When attribute information in the map is updated, the database subsequently generates a new digest, which is provided to the computing device.Type: ApplicationFiled: September 23, 2022Publication date: March 28, 2024Inventors: Ramarathnam VENKATESAN, Srinath T. V. Setty, Nishanth CHANDRAN, Panagiotis ANTONOPOULOS