Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

10501 results about "Computer security" patented technology

Computer security, cybersecurity or information technology security (IT security) is the protection of computer systems from the theft of or damage to their hardware, software, or electronic data, as well as from the disruption or misdirection of the services they provide.

Know your model and know your data systems and methods for transactions

In embodiments, systems and methods for configuring and deploying artificial intelligence driven transacting agents that are permitted to autonomously execute transactions on behalf of the individual or organization and configuring the transacting agent based on the agent configuration instructions and a set of predefined system prompts. The method further includes granting the transacting agent access to a digital wallet associated with the individual or organization and deploying the transacting agent to a public network, such that the transacting agent executes transactions on behalf of the individual or organization via one or more digital marketplaces using the digital wallet to which the transacting agent was granted access. In some embodiments, the transacting agent is granted access to the digital wallet using a consent token. In some embodiments, the method also includes hyper-personalizing and / or fine-tuning the agent.
Owner:STRONG FORCE TX PORTFOLIO 2018 LLC

Handling of certificates by intermediate actors

Handling of certificates by intermediate actors, including: receiving, by a proxy and from a client, a client certificate and a first private key; generating, by the proxy and based on the client certificate and the first private key, an intermediate certificate; generating, by the proxy and in response to a request from the client to connect to a destination, an alternate certificate for the destination; and providing, to the client, a certificate chain comprising the alternate certificate, the intermediate certificate, and the client certificate.
Owner:FORTINET INC

Interactive analysis of multifaceted security threats within a compute environment

Data platforms described herein are configured to monitor a compute environment and facilitate interactive analysis of multifaceted security threats within the compute environment. Such a data platform may determine that one or more assets within the compute environment are possibly being targeted by a multifaceted security threat and present an interactive user interface. The user interface may be configured to display an identifier indicative of the multifaceted security threat, a set of selectable evidence items each associated with a different facet of the multifaceted security threat and assessed based on the monitoring of the compute environment, and a presentation pane for displaying information. As such, the data platform may detect a selection of a particular evidence item from the set of selectable evidence items and, in response to the selection, populate the presentation pane with information related to the particular evidence item. Corresponding methods, systems, and products are also disclosed.
Owner:FORTINET INC

Enhanced quality of service-level security for wireless communications

This disclosure describes systems, methods, and devices for quality of service (QOS)-level security configuration in a packet data unit (PDU) session. A device may identify a first user plane security indication received from an application function of a wireless network; identify a second user plane security indication received from the application function; generate, based on the first user plane security indication, a first security configuration for a first QoS flow of a PDU session; generate, based on the second user plane security indication, a second security configuration for a second QoS flow of the PDU session, the first security configuration different than the second security configuration; decode a first packet received, from the UE, in the first QoS flow using the first security configuration; and decode a second packet received, from the UE, in the second QoS flow using the second security configuration.
Owner:INTEL CORP

Systems and methods for detecting malicious webassembly modules under source code obfuscation

Systems, methods, and frameworks for detecting malicious WebAssembly (Wasm) modules under source code obfuscation are provided. The system is configured to accurately identify malicious behavior in Wasm modules irrespective of the specific malicious functionality and in the presence of source code obfuscation techniques. The detection process leverages a Vision Transformer (ViT) model to classify a Wasm module as benign or malicious, enabling robust identification of threats across diverse attack patterns. The system operates with substantially low runtime overhead on computing resources, making it suitable for integration into real-time web application environments.
Owner:FLORIDA INTERNATIONAL UNIVERSITY

Systems and methods for resolving code vulnerabilities through collaborative agents

Systems and methods for resolving code vulnerabilities through collaborative agents which may include accessing a code base of an identified vulnerability; configuring a plurality of autonomous agents, each comprising a predefined agent role associated with application security remediation process; executing a directed workflow of the plurality of agents, wherein the workflow is a conditional sequence of agent-driven processing steps for generating a proposed resolution to the identified vulnerability; and outputting a candidate resolution for the vulnerability based on results produced by the workflow.
Owner:HARNESS INC

Apparatus and method for secure communication and integration with secure and non-secure root ports

Secure communication provided with secure and non-secure root ports. One embodiment comprises: a plurality of cores; a memory controller to couple to a memory; an interconnect fabric coupled to the plurality of cores and the memory controller; and a root complex to support end-to-end encrypted channels between devices, the root complex comprising: a root port to receive non-posted requests from a requestor device, the root port to associate a first tag value with a non-posted request to indicate whether the non-posted request is received over an end-to-end encrypted channel; and a bridge device to transmit the non-posted request with the first tag value and to subsequently receive a completion message including the first tag value, wherein the root port is to determine whether the completion message is to be encrypted in accordance with the end-to-end encrypted channel based on the first tag value.
Owner:INTEL CORP

Systems and methods for digital asset management

ActiveUS20260023826A1Program/content distribution protectionData sourcePersonal account
In some aspects, a component may generate an identification for a personal account based at least in part on user-asset heuristics, wherein the personal account is heuristically distinguished from an administrative account based at least in part on a number of users associated with an account that is either the personal account or the administrative account. The component may determine an owner identity of the owner associated with the personal account by linking the identification with an identity in a data source based at least in part on one or more heuristically determined identity attributes.
Owner:TENABLE INC

Cyber security protection of electronic communications including detecting topic shifts

PendingUS20260019438A1Securing communicationOutbound communicationElectronic communication
Systems and methods for protecting electronic communications are described. A cyber security appliance may be configured to calculate a topic shift score for a communication by comparing a first lexical profile derived from the communication to a historical lexical profile established for an associated user. This analysis may be performed without using a large language model. The system may also parse communications to extract sensitive data and content from attachments, performing behavioral modeling on the extracted data. Based on the analysis, an autonomous response module may take a variety of mitigation actions. Furthermore, a security mailbox assistant module may perform a secondary, in-depth analysis on user-submitted communications and generate a deterministic report. For outbound communications, a data loss prevention architecture may divert messages for in-line analysis and may include a fail-safe timeout mechanism to ensure service continuity.
Owner:DARKTRACE HLDG LTD

Method and device for sharing host based on multiple input devices and electronic device

The invention discloses a method for sharing a host based on multiple input devices, and belongs to the technical field of computers, and the method comprises the following steps: after a management user logs in a multi-seat configuration tool, creating second seats with the same number as new input devices according to a Udev rule, and enabling the management user to be a user operating the input device corresponding to a first seat of the host; according to a binding instruction sent by the management user, the second seats and the new input devices are bound one by one, and operation users of the input devices corresponding to the second seats are common users; according to a permission configuration instruction sent by the management user, configuring an application window permission for each common user; and sending the binding relationship between the second seat and the new input device and the application window authority to a window manager, so that the window manager manages the application window according to the binding relationship and the application window authority. According to the invention, the problems of disordered management and complex configuration when multiple users share one host window are solved, and more flexible and efficient equipment management experience is provided for the users.
Owner:UNIONTECH SOFTWARE TECH CO LTD

Deterrent mat with spikes

The present disclosure provides a deterrent mat with spikes, which includes a base and a spike assembly. One end of the spike assembly is connected to the base and another end extends to a direction away from the base. The spike assembly at least includes a plurality of first deterrent spikes and a plurality of second deterrent spikes, and the first deterrent spikes and the second deterrent spikes are arranged on a same side. A height of the first deterrent spikes is less than that of the second deterrent spikes, and the first deterrent spikes and the second deterrent spikes are arranged alternately. By staggering the first deterrent spikes and the second deterrent spikes of different heights, the discomfort of animals during their climbing and staying may be effectively increased, thereby improving deterrent effects. The deterrent mat with spikes is simple structured and has good deterrent effects.
Owner:YIWU BEIXIN TECH CO LTD

Access method, device and equipment and computer readable storage medium

The invention discloses an access method, device and equipment and a computer readable storage medium, which are applied to the technical field of computers, and comprise the following steps: loading a consistency label list corresponding to an authorized access consistency domain; when an access request is initiated to a target consistency domain in the shared memory, performing permission verification on the access request through the consistency label list and the target consistency domain; when the permission verification is passed, determining whether an access conflict exists or not through a local access state cache and the type of the access request; if the access conflict exists, a controller arbitration engine is triggered, and the access request is executed according to an arbitration result; and if the access conflict does not exist, executing the access request. According to the method, the consistency label list and the access state cache are formulated for each device, the consistency problem existing when multiple devices access the shared memory in an existing system is solved, and efficient, low-conflict and flexible consistency guarantee can be achieved under the scene that multiple devices concurrently access the shared memory.
Owner:SHANDONG YUNHAI GUOCHUANG CLOUD COMPUTING EQUIP IND INNOVATION CENT CO LTD

Key shard verification for key storage devices

In certain embodiments, verification operations are performed. A first device packaged with a second device may store a first key shard and a second key. The first key shard may be a same key shard as a corresponding key shard stored on the second device, where the second key is different from a corresponding key stored on the second device. Additionally, the first key shard and the corresponding key shard are associated with a user. In connection with a request from a web service, the first device or a computing device may generate a response to the request using the second key by identifying the second key using an identifier of the request. Furthermore, the first device or the computing device may send the response to the web service, where the web service confirms registration of the first key shard based on the response.
Owner:UNIT 410 LLC

Ecommerce messaging systems and methods for implementing in-app stores and order workflows

An ecommerce messaging system described herein comprises one or more ecommerce extension apps that interact with a messaging app. These embodiments leverage the extension core to manage session apps and smart services for using tap-to-message and tap-to-update processes to generate, update, and manage order workflows and in-app stores through branded messages communicated between customer and seller session apps to share message transcripts on devices of the same user groups via the messaging host, empower ecommerce with action-key-based communication, serialize-deserialize processes, and dynamic update propagation, manage return-refund workflows with temporary tables until one-time entity data model updates can be performed for session apps, and configure multi-store shopping systems on sellers' multiple devices using a store-as-a-service model to enable distributors to distribute production copies of assigned stores to authorized publishers to add custom promotions, which will be published together as production copies to their subscribed user groups for multi-store shopping and tracking.
Owner:CHENG JOSEPH C +1

Provisioning of encrypted DNS services

The present specification provides a system and method for determining that an endpoint device has connected to an untrusted external internet protocol (IP) network; and establishing a secure DNS connection from the endpoint device to a trusted DNS server via a proxy, wherein the proxy authenticates the trusted DNS server via a client identity certificate and a server certificate.
Owner:MCAFEE LLC

Lottery ticket vending machine

A lottery ticket vending machine including a ticket collection receptacle of its front door that is configured to receive lottery tickets of different sizes and shapes. The ticket collection receptacle includes a first ticket-receipt section, a second ticket-receipt section, and a third ticket-holding-and-access section. The first ticket-receipt section is configured to receive instant lottery tickets from the bursters. The second ticket-receipt section is configured to receive printed lottery tickets (and / or receipts) from the printer. The third ticket-holding-and-access section is configured to hold the received lottery tickets (and receipts) in a manner that does not block receipt of further tickets (and receipts).
Owner:GTECH CORP

Tamper-resistant end-to-end service data evidence storage method and system

The invention discloses a tamper-resistant end-to-end service data storage method and system, and relates to the technical field of service data storage methods, and the method comprises the steps: initializing a hardware security module and a monotone increasing clock in terminal equipment, building a unique identity identifier of the equipment, and preparing a log environment for recording service data; the method comprises the following steps: collecting current business data and associated meta-information thereof, and constructing input content of current data processing in combination with an equipment identity, a clock value, a data structure template and an abstract value generated by previous business data; hash operation is carried out on the input content to generate an abstract of the business data, the abstract is signed by using a hardware security module to form an equipment side digital signature, and the abstract, the signature and meta-information are written into a log only increasing but not changing and an offline queue; and after the terminal recovers the network connection, generating a unique idempotent key based on the abstract of the service data or the combination of the equipment identity and the clock, and submitting an evidence storage request containing the abstract and the signature to the server.
Owner:北京跃创三品文化科技有限公司

Ai-based malicious activity detection using a threat actor profile

Techniques are described herein that are capable of performing AI-based malicious activity detection using a threat actor profile. An alert is received. The alert indicates that a potentially anomalous event has occurred with regard to an entity. A profile of a threat actor is generated using information that describes behavior of the threat actor. An artificial intelligence (AI) model is triggered to determine whether the threat actor performs a malicious activity with regard to the entity by providing an AI prompt as an input to the AI model. The AI prompt includes the profile of the threat actor and a description of the potentially anomalous event. The AI prompt requests a determination whether the threat actor performs the malicious activity with regard to the entity.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Security protection method for power mobile application based on swan-gap microkernel

The invention relates to an electric power mobile application security protection method based on a swan gap microkernel, which comprises the following steps of: S1, establishing a hardware trust root, and storing a device root key and a certificate chain by utilizing a non-tampering storage area built in a chip; s2, establishing a complete trusted boot chain based on a hardware root of trust, and verifying the integrity and credibility of the next layer by each layer from Bootloader to a swan microkernel and then to an application program; s3, constructing a triple authentication system based on user identity, equipment identity and biological characteristics, and performing user authentication; s4, according to a user authentication result, realizing fine-grained authority control based on an RBAC model and ABAC, and ensuring that authority check can be executed during resource access every time by utilizing an IPC security mechanism of a swan micro kernel; and S5, creating an independent execution environment for each power application according to the process isolation capability of the swan microkernel, and ensuring that memories among the applications cannot be mutually accessed through virtual address space isolation. The reliability of power mobile application safety protection is effectively improved.
Owner:STATE GRID INFORMATION & TELECOMM GRP CO LTD +1

Automated temporary device connectivity

Systems and methods for automated temporary device connectivity include receiving data requesting that a first device be associated with a second device and generating a request for an identifier of the second device to be associated with the first device. This request may be sent to an enterprise system and the second identifier may be received from the enterprise system. Data authorizing the first identifier to be associated with the second identifier for pairing purposes may be generated and stored. An indication may be received that the first device has moved within a threshold range of the second device and commands may be sent to cause the first device and the second device to enter a pairing mode.
Owner:AMAZON TECH INC

Indication of provisioning protocol for credentials to access a non-public network

A method for a user equipment (UE) to obtain security credentials for accessing a non-public network (NPN) is provided. The method comprises sending, to an onboarding network (ON), a registration request that includes an identifier of the UE, and obtaining an indication of a credential provisioning protocol (CPP) used by a provisioning server (PS) for provisioning security credentials to access the NPN. The method further comprises obtaining, from the PS via the ON using the indicated CPP, security credentials for the UE to access the NPN.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Secure provisioning and rotation of certificates for edge devices

A certificate management service (CMS) may securely provision and rotate certificates for edge devices. The CMS may pre-register a unique device ID of an edge device (e.g., provided by the device manufacturer). When the edge device is installed at the client's remote network, it is provisioned with a common bootstrap certificate that allows the edge device to initially establish a secure to connection to a local hub device and to request a client certificate. The CMS receives the request for the client certificate, which includes the unique device ID. Since the unique device ID was pre-registered at the CMS, the CMS authenticates the request for the client certificate. The CMS causes a signed client certificate to be delivered back to the edge device, which may be used by the edge device to establish subsequent secure connections.
Owner:AMAZON TECH INC

Apparatus, methods, and computer programs for protecting sensitive data

There is provided a method, computer program, and an apparatus for a network function service consumer, that causes the apparatus to perform: retrieving, from a first repository function, protected sensitive data; retrieving, from a second network function, at least one encrypted key; decrypting the retrieved at least one encrypted key using a private key associated with the network function service consumer to obtain a respective at least one key; and performing at least one of: decryption of the protected sensitive data using the at least one key to obtain sensitive data or integrity protected sensitive data; or verification of the integrity of the protected sensitive data using the at least one key.
Owner:NOKIA TECHNOLOGIES OY

Analysis and prioritization of vulnerabilities of connected vehicles

An automotive cybersecurity platform receives vulnerability alerts that may impact a connected vehicle. Software components of the connected vehicle are identified and listed. Software components that are affected by a vulnerability are identified using information from a vulnerability alert. An overall risk score of the vulnerability is determined based at least on whether the vulnerability can be triggered, how the vulnerability affects the connected vehicle when the vulnerability is triggered, and an intrinsic risk posed by the vulnerability. Remediation of the vulnerability is prioritized based at least on the overall risk score of the vulnerability.
Owner:VICONE CORP

Intelligently delivering a telephone call with identity attributes

Telephone calls can be intelligently delivered with identity attributes as described herein. In one example, a system can receives communication associated with a caller requesting to make a telephone call to a recipient, where the communication includes a recipient identifier associated with the recipient. The system can determine a terminating telecommunication service provider (TTSP) to which the telephone number is assigned. The system can then determine identification options available at the TTSP, where each identification option can be configured to provide one or more identity attributes associated with the caller to the recipient. The system can select one or more of the identification options based on a predefined policy and modify the communication to include the one or more identity attributes associated with the one or more selected identification options, thereby producing a modified communication. The system can then transmit the modified communication along a call route to the TTSP.
Owner:NUMERACLE INC

Method, device and computer program for cloud-authenticated pairing in wireless communication system, and recording medium therefor

The present disclosure relates to a method, device and computer program for cloud-authenticated pairing in a wireless communication system, and a recording medium therefor. A method for carrying out account-based pairing in a wireless communication system, according to one embodiment of the present disclosure, may comprise the steps in which: a seeker device acquires credential information of a provider device from a server; the seeker device acquires, from the provider device, an advertising packet comprising a hash value which is based on the credential information; and the seeker device establishes a connection with the provider device on the basis of the acquired credential information and the hash value which is based on the acquired credential information.
Owner:INTELLECTUAL DISCOVERY CO LTD

System and method for limiting mobile device functionality in a geographic area

A method and system for limiting mobile device functionality when the mobile device is located in a pre-defined fixed geographic area. The mobile device may receive a local disabling signal from a disabling device, which, when detected by a Device Owner Application resident on the mobile device, limits the mobile device functionality. Alternatively, the system may use GPS based geofencing to determine that the mobile device is in a predefined geographic area, and then transmit instructions to the mobile device, where a Device Owner Application operates to restrict the mobile device functionality. Mobile device functionality may be limited by restricting the mobile device's ability to send and receive text messages, email messages and phone calls; restricting the mobile device's ability to respond to user input; restricting the mobile device's ability to utilize a web browser; and restricting the mobile device's web browser from accessing predetermined web sites.
Owner:CBROS TECHNOLOGIES LLC

Multi-tenant adaptive cooperative defense method and system in hybrid cloud scene

The invention discloses a multi-tenant adaptive cooperative defense method and system in a hybrid cloud scene, and the method comprises the following steps: obtaining a remote credible proof of hardware, verifying the credibility of a tenant agent and the integrity of a code based on the remote credible proof, granting a mark, and detecting cloud information to generate a machine readable portrait containing key parameters; collecting local multi-mode log data coding embedding vectors of tenants, and after privacy processing, calculating that the abnormal confidence exceeds a threshold value by a local model to trigger current limiting or blocking; and constructing a hierarchical federated architecture containing local nodes of tenants, a regional cloud and a global control plane, encrypting aggregation parameters to generate a cross-tenant attack recognition global model and issuing the cross-tenant attack recognition global model to each tenant on the premise that log data is not out of a domain. According to the invention, integrity verification is carried out on the tenant side security agent through the trusted access mechanism, and the tenant portrait is constructed based on the trusted mark, so that the real and verifiable cooperative defense capability among a plurality of tenants is realized, and the cooperative process has dependency.
Owner:BEIJING GUOXIN LANDUN TECH CO LTD

Kit, system and associated method and service for providing a platform to prevent fraudulent financial transactions

A system and associated method and service for providing a platform that enables members to transfer, receive, or otherwise exchange cash in various international denominations and commodities, such as precious metals (e.g., gold, silver, etc.), in a mobile highly secured telecommunications environment. The system is capable of delivering cash instantly between two or more users by allowing the exchange of secure transactions between system and cash dispensing machines (ATMs). Users may pay, receive, exchange, deposit, transfer, pay bills, exchange currency, retrieve cash, deposit cash and create accounts based on the mobile phone number or a system generated code.
Owner:PAYGEO LLC

Method to detect and prevent business email compromise (BEC) attacks associated with new employees

Techniques for an email-security detection system to analyze incoming emails for Business Email Comprise (BEC) attacks of targeted new email users in an enterprise based on peer models of email recipients in an enterprise and the conversation history of recipients. A method is disclosed that includes analyzing an incoming email and identifying one or more recipients of the incoming email in an enterprise network; analyzing contextual information in the incoming email for the email intent, and associating the email with a target recipient; applying a relational model associated with peers of the target recipient for detecting whether the incoming email is a business email compromise (BEC) attack directed to the target recipient; applying a relationship model of other recipients of the incoming email for detecting whether the BEC attack is associated with the target recipient; and determining, whether the incoming email is a BEC attack.
Owner:CISCO TECHNOLOGY INC