Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

645 results about "Electronic mail" patented technology

Electronic mail. n. (Communications & Information) the transmission and distribution of messages, information, facsimiles of documents, etc, from one computer terminal to another.

Data analysis pipeline engine in a data intelligence system

Methods, systems, and computer storage media for providing a data analysis pipeline using a data analysis pipeline engine in a data intelligence system are described. A data analysis pipeline refers to a structured sequence of data processing steps that support transforming raw data into meaningful insights or actionable outcomes. The data analysis pipeline engine is an unsupervised learning pipeline based on clustering, topic modeling, and Large Language Models (LLMs). For example, the data analysis pipeline can use advanced machine learning techniques to automatically categorize emails into semantically similar clusters, enabling the data intelligence system to quickly identify and prioritize potentially high-risk emails for further investigation. The data analysis pipeline employs AI agents for context-aware graph induction relevance assessment. The AI agents employ induction and deduction loops to build and refine a data feature hypergraph (e.g., vulnerability hypergraph) that encompasses identified relevant data providing a holistic view of a contextual landscape.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Automatic Performance of Access Review Utilizing a Large Language Model (LLM)

Computerized systems and methods for automated Access Permissions Review in an organization. A method includes: (a) receiving a textual description of an Access Review Policy; (b) constructing a trigger for automatically initiating an Access Review process; (c) automatically collecting organizational data that pertains to: (i) roles and positions of users, (ii) user-specific characteristics, (iii) email messages sent and received by users, (iv) description of events in which users had accessed elements of the Organizational Resource. Upon a triggering of the trigger, the method provides to a fine-tuned Large Language Model (LLM), the Access Review Policy and augmentation data from the organizational data, and a prompt instructing the LLM to generate a proposal to revoke, modify, add or maintain the Access Permissions of a particular user, and further instructing the LLM to generate output that describes reasoning and supporting evidence for the proposal.
Owner:VARONIS SYSTEMS INC

Ai agent interfaces and controls for email and other electronic communications

Systems and methods are provided for managing AI (Artificial Intelligence) agents interactions with electronic communications that are displayed at an electronic communications interface, such as an email interface. The systems parse electronic communications to determine whether they correspond to new or existing requests and actions to be performed when responding to the request(s). The systems also generate notifications identifying the set of actions with visual identifiers that visually distinguish the set of actions based on whether they have been completed or not and whether they need authorization to be completed. The systems also display selectable controls for controlling how the AI agent performs the actions.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Deep search using large language models

Systems and methods are provided for implementing deep search functionality using large language models (“LLMs”). In various examples, a computing system uses at least one LLM to generate intents based on a user query, to generate alternative queries based on a selected or identified primary intent, and to generate a relevance score for each search result that is obtained from a search utility (e.g., an Internet search engine, a file storage search utility, an email search utility, or a document storage search utility) in response to a primary query (corresponding to the primary intent) and the generated alternative queries being entered into the search utility. The search results from the search utility are sorted based on the corresponding generated relevance scores, and the sorted search results are caused to be displayed to the user as a deep search response to the user query.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

System and method for communication validation and multi-attribute trust scoring through cross-network intelligence correlation

A system and method for privacy-preserving communication validation and multi-attribute trust scoring is disclosed. The system analyzes communication metadata to determine pattern legitimacy by comparing current communication patterns against relationship fingerprints without accessing communication content. The system validates relationship context between communicating parties using interaction graph analysis and historical communication data. Cross-network intelligence correlation compares current patterns against aggregated patterns across voice, email, and messaging services, creating a self-strengthening security framework that recognizes emerging threat patterns while validating legitimate communication behaviors. The system generates comprehensive multi-attribute trust assessments comprising individual trust attribute scores including engagement rate, reliability index, channel preference, temporal pattern, and behavioral pattern, combined into overall trust levels. Trust context is displayed through a user interface presenting simplified, intuitive, and actionable information with progressive disclosure capabilities, enabling informed user decisions while preserving privacy. Communication processing actions provide users with appropriate engagement options tailored to specific trust assessment results.
Owner:ICA AI INC

Hybrid operating system search

The disclosed techniques provide improved methods of operating system (OS) search. Users are enabled to search for documents, emails, presentations, content they entered into a web form, meetings they participated in, and other interactions they had with their computing device. To accomplish this, screenshots are periodically captured and indexed. Machine learning models are used to infer embeddings for visual elements of the screenshots and / or text extracted from the screenshots. A full text index of a relational database may also be populated with text extracted from the screenshots. The embeddings and full text index may then be used to retrieve screenshots in response to a user history query. For example, screenshots of embeddings within a defined distance of an embedding of the user history query may be selected. Query results from different embedding indices and relational databases may be ordered by applying different weights to different kinds of search scores.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

System and method for limiting mobile device functionality in a geographic area

A method and system for limiting mobile device functionality when the mobile device is located in a pre-defined fixed geographic area. The mobile device may receive a local disabling signal from a disabling device, which, when detected by a Device Owner Application resident on the mobile device, limits the mobile device functionality. Alternatively, the system may use GPS based geofencing to determine that the mobile device is in a predefined geographic area, and then transmit instructions to the mobile device, where a Device Owner Application operates to restrict the mobile device functionality. Mobile device functionality may be limited by restricting the mobile device's ability to send and receive text messages, email messages and phone calls; restricting the mobile device's ability to respond to user input; restricting the mobile device's ability to utilize a web browser; and restricting the mobile device's web browser from accessing predetermined web sites.
Owner:CBROS TECHNOLOGIES LLC

Representing an email inbox as a customizable database

The system obtains messages including multiple properties, such as a sender, a receiver, and content. The system creates a database to store the messages and presents the database in a user interface including a table including rows and columns. The database can be customized by including a custom column among the multiple columns. The system customizes the user interface by creating custom views of the database. The system receives an indication to create a view of the multiple messages, where the indication to create the view includes a criterion to select a subset of messages from the messages. The system creates the view including multiple layouts configured to visually provide important information associated with the subset of messages.
Owner:NOTION LABS INC

Method to detect and prevent business email compromise (BEC) attacks associated with new employees

Techniques for an email-security detection system to analyze incoming emails for Business Email Comprise (BEC) attacks of targeted new email users in an enterprise based on peer models of email recipients in an enterprise and the conversation history of recipients. A method is disclosed that includes analyzing an incoming email and identifying one or more recipients of the incoming email in an enterprise network; analyzing contextual information in the incoming email for the email intent, and associating the email with a target recipient; applying a relational model associated with peers of the target recipient for detecting whether the incoming email is a business email compromise (BEC) attack directed to the target recipient; applying a relationship model of other recipients of the incoming email for detecting whether the BEC attack is associated with the target recipient; and determining, whether the incoming email is a BEC attack.
Owner:CISCO TECHNOLOGY INC

Autonomous generation of task completion narratives

A task management system detects condition(s) are satisfied with respect to task record(s), and triggers action(s) at least in part by substituting information from the task record(s) into placeholder(s) of user-modifiable template(s) to prompt large language model(s) for generating narrative(s) about how the condition(s) were satisfied. The triggered action(s) retrieve information from identified task record(s), substitute value(s) from the record(s) into the placeholder(s) of the user-modifiable template(s), and trigger(s) call(s) to large language model(s) to generate task completion narrative(s) or other narrative(s) for the task record(s). The narrative(s) may be stored in narrative field(s) of the record(s) for use in displaying the narrative(s) on a user interface, email notification, or other message.
Owner:ORACLE INT CORP

System and Method for Managing Information Compliance and Relevance Using Autonomous Artificial Intelligence (AI) Agents in Data Transfer and Communication Environments

System and method for managing information compliance and relevance using autonomous artificial intelligence (AI) agents in data transfer and communication environments. Some embodiments may include a core orchestration engine with multiple autonomous AI agents configured to manage and evaluate the compliance and relevance of information in communication and data transfer environments. The system may use weighted metrics to assess if information and actions comply with regulations and are pertinent to recipients, monitor email and data transfer, ensure regulatory compliance, and enhance information and knowledge sharing within organizations. The system may use semantic embeddings, part-of-speech analysis, and language models to extract and apply regulatory rules efficiently. These features may significantly reduce search space, computational overhead, and manual effort while improving security and accuracy.
Owner:ONEILL ALLEN

Context-based deep mail password strength measurement method

The invention provides a context-based deep mail password strength measurement method, which comprises the following steps of: introducing user context information such as an e-mail, a name and a birthday on a basic password measurement model framework, and realizing information fusion through a multi-head self-attention mechanism; and a password sequence probability calculation model is constructed in combination with a character-level long-short-term memory network (LSTM). An evaluation system taking guess times as a core index is established to quantify the performance difference of different models under the condition that whether user context information exists or not. Experiments show that the method can more truly reflect the cracking capability of an attacker when the attacker masters the context information of the user.
Owner:SHENYANG AEROSPACE UNIVERSITY

Analytical AI Auto-Locking Apparatus, System, and Method for Preventing Unauthorized File Access

Cybercriminals are using advanced techniques to access information not only inside a company network but outside of a company network in the ecosystem of company communications with customers, suppliers, partners, and professional advisors. There are many ways cybercriminals gain access to this information, often by compromising email accounts, archives, and document management systems outside of a company's own control and / or outside of their control to manage security of those external accounts. This invention provides an apparatus that will proactively detect when a cybercriminal has accessed or is attempting to access a document attached to an email, a document stored in a repository, a link to an e-signature transaction, a link to a file download (“Files”), and pre-emptively auto-lock the attempted-to-be-eavesdropped on Files and alert the File owner of a high risk information breach in progress, even if that breach is outside their network or information perimeter.
Owner:KHAN ZAFAR

Automated Detection and Management System for Unauthorized External Service Accounts Using Large Language Models and Email Analysis

The present invention is a system and method to help with resolving the pervasive issue of unauthorized external service accounts and subscriptions created by employees within an organization. The present invention seeks to provide users with a system that strategically analyzes organizational email communications, which serve as a rich data source for identifying unauthorized external accounts and services. The system accesses each email account under an organizational domain, wherein each email is cleared of unnecessary content. Additionally, an LLM analysis performs various cross checks, and an AI integrity check verifies all LLM responses. Finally, the system and method documents and report all findings to the organization.
Owner:WALDO SECURITY LLC

Internet of things appliance providing extended-capability messaging

Operating effectively in an increasingly prolific Internet of Things environment, one needs the ability to message, whether device status, actions taken, recommendations for actions or other information to those with a need to know and support responses to actionable messages. Texts and e-mail are limited; they can neither provide other outputs, be targeted in intelligent fashion nor selectively relayed or contain execution instructions for target devices. The present invention is an Extended-Capability Messaging Appliance (ECMA) that communicates with other IoT devices that provides these capabilities and can include AI. ECMA and non-ECMA AI elements can constitute a Hybrid AI Backbone. The Hybrid AI Integrator receives results from multiple A elements and develops one or more conclusions. An ECMA may be configured as a Body-Area Network for individuals or a Business-Area Network for industry and other commercial applications with an AI Agent called BANDIT that processes requests from a user.
Owner:KINNECTED AL INC

Sharing structured views of email messages between users

The system obtains multiple views associated with a first multiplicity of messages, where a view among the multiple views includes a criterion, a visual appearance, and an action. The criterion defines a message to include in the view, and the action is configured to trigger automatically when the message is included in the view. The system applies the view to the second multiplicity of messages by: selecting a subset of messages among the second multiplicity of messages according to the criterion; presenting the subset of messages to the user according to the visual appearance associated with the view; and performing the action on the subset of messages.
Owner:NOTION LABS INC

Method for evaluating and discovering phishing attempts in an email

PCT designated stageWO2025226915A1Securing communicationElectronic mailPhishing detection
A method of rating a phishing email's human phishing detection difficulty includes identifying cues in content of the email tending to indicate that the email is a phishing email; assigning weights to identified cues; assessing a relative severity based on the weighted cues; determining an overall human detection difficulty of the email based on the relative severity of the weighted cues and a total number of the identified cues determining a target audience for the phishing email; determining a plurality of sub-groups of the target audience; and determining a plurality of respective premise alignments of the email by characterizing respective pertinences of a message premise of the email with respect to each respective sub-group of the target audience; wherein the step of determining an overall human detection difficulty of the email is additionally based on the respective premise alignments of the email.
Owner:THE GOVERNMENT OF THE UNITED STATES OF AMERICA AS REPRESENTED BY THE SECRETARY DEPARTMENT OF HEALTH & HUMAN SERVICES

Guided dynamic construction of large language model (LLM) prompts

Example solutions for reducing the likelihood of hallucinations by large language models (LLMs) and improving the relevance of generated text are disclosed. A set of multiple of machine learning (ML) models, each custom-trained to identify a different specific topic within text, dynamically generate multiple topic-specific prompts from a received email in an email thread. A user, responding to the prompts, produces material that is used in conjunction with customer relations management (CRM) data and enterprise suite data (e.g., calendar / schedule information) to dynamically generate an LLM prompt. An LLM, using the prompt, generates output text suitable for a business correspondence, such as a reply email, to the sender of the email. The combination of the responses to the multiple topic-specific prompts and the CRM and enterprise suite data in the LLM prompt both ensures relevance of the reply correspondence and minimizes the risk of hallucinations.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

System and method for pre-emptive detection of email impersonation and man-in-the-middle attacks using ai-driven telemetry and data leak prevention remediation

Disclosed is a system and method for pre-emptive detection, attribution, and reversal of outbound data leaks and impersonation-based attacks occurring beyond traditional enterprise endpoint security boundaries. An outbound instrumentation gateway may insert telemetry identifiers into outbound electronic communications, enabling persistent tracking of message interactions within external or third-party domains. A RAPTORAI analytics engine may process metadata collected from these interactions using a multi-stage artificial-intelligence pipeline that combines predictive anomaly modeling and large-language-model (LLM) attribution. When anomalous or malicious behavior is detected, a Double DLP remediation engine may be activated, which is capable of pausing, auto-locking, or revoking message access after transmission but before compromise. A PRE-Crime telemetry layer provides visibility into early-stage reconnaissance activities by threat actors operating beyond the endpoint, thereby reducing mean time to detect (MTTD) and mean time to respond (MTTR) to effectively zero. Administrative dashboards present live analytics of third-party risks, reconnaissance indicators, and auto-remediation events.
Owner:KHAN ZAFAR

Knowledge informatics auto reviewer for quality control of reporting

An auto reviewer system designed to execute required rule checks, extract information of interest to human reviewers, and generate a final report with the results. The auto reviewer system operates by checking that an order satisfies a pre-defined set of conditions and raising a flag for each condition not satisfied. The flags considered pertinent to a user's understanding of the final report are then combined into order notes, and the order notes are automatically entered into the internal note fields of the corresponding orders in one or more workbenches. Additionally, flags raised that correspond to order issues requiring manual intervention trigger automatic support request notifications such as emails, which are sent to a user to be resolved. If an order has no issues requiring manual intervention, then the note generated for that order includes a complete statement and is passed for final report generation.
Owner:OMNISEQ INC

Email security system for blocking and responding to targeted email attacks, and operation method thereof

An operation method of an email security system comprises the steps of: configuring security threat information synchronization data by synchronizing targeted email security threat information configured by performing a targeted email security threat inspection on an inbound mail with targeted email security threat information configured by performing a targeted email security threat inspection on an outbound mail; performing a targeted email security threat inspection corresponding to a new inbound mail or a new outbound mail using the security threat information synchronization data; and performing a targeted email security threat response process according to the targeted email security threat inspection of the new inbound mail or the new outbound mail.
Owner:KIWONTECH

Method and system for transferring funds between a financial institution and an e-wallet within an interbank network

There is provided a method to transfer funds from a user's financial institution account to an electronic wallet (e-wallet). The e-wallet is provided by an e-wallet provider. The method includes obtaining a message addressed to an email address from an interbank network. The message includes the email address and a transaction identifier (ID). The method further includes obtaining an e-wallet ID associated with the e-wallet. The transaction ID is provided to the interbank network and a hash salt of a security question is obtained from the interbank network. The hash salt of the security question, the security answer and the e-wallet ID are provided to cause the interbank network to authenticate the transaction and the amount of funds is transferred from the account at the financial institution to the e-wallet provider and an e-wallet balance of the e-wallet is updated.
Owner:ZHU ZHAOYU +2

Tying access / redaction to authentication levels

A media is created. The media may be a document, an image, a video file, an audio file, a real-time communication session, an email, a chat session, and / or the like. The media is associated with a plurality of authentication levels. For example, the media may use a first authentication level that requires a username / password and a second authentication level that requires a fingerprint scan of a user. The media is created based on a security process according to the plurality of authentication levels. For example, the security process may be an encryption process and / or a tokenization process. The media is divided into a plurality of sections based on the plurality of authentication levels. The security process is applied to the plurality of sections based on the plurality of authentication levels.
Owner:MICRO FOCUS LLC

Message processing using language models

A representation of an email application includes a message view comprising a plurality of email messages. In response to receiving an indication that a new email message has been received, a prompt is generated for input to a large language model (LLM). The prompt is usable to cause the LLM to analyze content of the new email message and determine a priority of the new email message. The priority is localized to a context based at least in part by a recipient and sender of the new email message.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Management of Connector Services and Connected Artificial Intelligence Agents for Message Senders

Systems and methods are described for a connected AI agent for managed multidimensional search based on an electronic message and management policies. A messaging application at a client device can send a new electronic message, such as an email, to a connector service. An attachment can be ingested and stored in a vector database. Then one or more artificial intelligence (“AI”) agents can be selected for responding to the body of the email, such as a query in the body. The responses can be formatted and sent to multiple parties, such as a sending user of the electronic message and a recipient that was copied or also sent the new electronic message. The AI agents can use different AI models, prompts, and vector databases depending on user permissions. This allows for building up vector databases with relevant content items and answering user questions based on those vector databases.
Owner:AIRIA LLC

Ai-driven direct mapping of machine-executable directives

PendingUS20260122113A1Securing communicationOperational systemContinuous feedback
Systems and methods translate and govern directives across heterogeneous platforms. In some embodiments, directives are normalized into a common intermediate representation (CIR) for validation, conflict handling, and deployment. In other embodiments, a direct semantic mapping engine converts source directives directly into target-native, machine-executable directives without a CIR and without normalization, consulting a platform capability database and synthesizing target-compatible scripts, profiles, workflows, or rules where native primitives are absent. Ephemeral triggers (e.g., time window, incident, risk, posture, geofence) cause generation and atomic activation of temporary directives that supersede baseline directives for a defined scope and interval, with withdrawal on expiry to restore the baseline. Adapters actuate across families including cloud control planes, operating systems (Windows / macOS / Linux), IoT / OT, Kubernetes, identity, email / DLP, browser, and SaaS / social platforms. Both approaches share validation, simulation, and governance / deployment engines supporting approvals, audit logging, staged rollout, rollback, and continuous feedback.
Owner:HACKSEAL CORP

Secure payment method

Methods, systems and software designs are disclosed that may be used to enable simple, safe and secure transfers of digital assets such as cryptocurrencies, fungible tokens, and non-fungible tokens (NFTs) from a transferor to a recipient through a payment channel established by a smart contract on a blockchain. Transfers are enacted by the recipient presenting a voucher to the smart contract, said voucher being digitally signed by the transferor and transmitted to the recipient at a prior date and time. The voucher may be transmitted through an out-of-band channel, for example, through email, or a messenger application, and may take the form of a quick-response code (QR code), a base 64 encoded string, a hexadecimal string or some other representation. The smart contract may impose limitations on a minimum and / or maximum amount that may be transferred, and on a time period in which the voucher may be redeemed.
Owner:CHEQS GLOBAL LTD

Automated threat hunting

Embodiments perform automated threat hunting in computing environments. A threat hunt plan is obtained to guide collection of candidate evidence items from evidence sources. Portions of candidate evidence items are discarded based on relevance scores, and evidence items are determined from non-discarded portions. Threat indicators associated with the evidence items are identified based on criteria in the threat hunt plan. Threat profiles are obtained based on the evidence items and threat indicators such that threat profiles include threat assessment metrics and are included in a report. Collection agents may interface with system logs, network traffic captures, endpoints, databases, email services, or user activity records to gather evidence items based on time ranges, filtering criteria, or sampling rates.
Owner:DROPZONE AI INC

Detection and prevention of external fraud

Techniques for detecting instances of external fraud by monitoring digital activities that are performed with accounts associated with an enterprise are disclosed. In one example, a threat detection platform determines the likelihood that an incoming email is indicative of external fraud based on the context and content of the incoming email. To understand the risk posed by an incoming email, the threat detection platform may seek to determine not only whether the sender normally communicates with the recipient, but also whether the topic is one normally discussed by the sender and recipient. In this way, the threat detection platform can establish whether the incoming email deviates from past emails exchanged between the sender and recipient.
Owner:ABNORMAL AI INC