Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

8643 results about "Internet privacy" patented technology

Internet privacy involves the right or mandate of personal privacy concerning the storing, repurposing, provision to third parties, and displaying of information pertaining to oneself via the Internet. Internet privacy is a subset of data privacy. Privacy concerns have been articulated from the beginnings of large-scale computer sharing.

Automatically Investigating Security Incidents and Generating Security Incident Reports Using a Large Language Model (LLM)

Automatically investigating security incidents and generating security incident reports using a Large Language Model (LLM). A computerized system receives an incoming Security Alert Message pertaining to a possible security-related incident. The system automatically feeds into the LLM at least: the content of the Security Alert Message; the metadata of the Security Alert Message; context information describing a security domain; and organization context information pertaining to users and machines of that organization. The system automatically prompts the LLM to automatically investigate the Security Alert Message and to automatically generate a detailed Incident Report pertaining to the Security Alert Message.
Owner:VARONIS SYSTEMS INC

Know your model and know your data systems and methods for transactions

In embodiments, systems and methods for configuring and deploying artificial intelligence driven transacting agents that are permitted to autonomously execute transactions on behalf of the individual or organization and configuring the transacting agent based on the agent configuration instructions and a set of predefined system prompts. The method further includes granting the transacting agent access to a digital wallet associated with the individual or organization and deploying the transacting agent to a public network, such that the transacting agent executes transactions on behalf of the individual or organization via one or more digital marketplaces using the digital wallet to which the transacting agent was granted access. In some embodiments, the transacting agent is granted access to the digital wallet using a consent token. In some embodiments, the method also includes hyper-personalizing and / or fine-tuning the agent.
Owner:STRONG FORCE TX PORTFOLIO 2018 LLC

Dynamic digital watermarking system for real-time user activity fingerprinting and unauthorized access tracking

A method is provided for dynamically generating a digital watermark for a data file. The method includes receiving a request to access the data file from a user; dynamically generating an encryption key based on at least one parameter selected from the group consisting of the identity of the user, the time of access, and the mode of access; embedding a digital watermark into the data file using the dynamically generated encryption key, wherein the digital watermark is unique to the request; providing access to the data file with the embedded digital watermark to the user; and storing information related to the encryption key and the parameters used for its generation in a secure database.
Owner:LEPTUDE INC

Authentication and authorization for localized services

The present disclosure provides technologies and techniques related to enabling access to localized services. The present disclosure provides mechanisms for authentication and authorization for enabling a non-public network (NPN) to act as a hosting network for providing access to localized services. Additionally, the present disclosure provides mechanisms for enabling user equipment (UE) to discover, select and access an NPN acting as a hosting network to receive localized services. Furthermore, the present disclosure provides mechanisms for enabling access to localized services via a specific hosting network.
Owner:INTEL PRODUCTS IP LLC

Network egress access control with untrusted intermediary

A network egress request is received from a container service within a cloud data platform. A cryptographically signed egress policy associated with the network egress request is received by a trusted service controller of the cloud data platform. The network egress request is validated against the cryptographically signed egress policy. Based on the validation, a determination of whether the network egress request complies with the cryptographically signed egress policy is established. Upon validation, the network egress request is granted or denied based on the determination.
Owner:SNOWFLAKE INC

Security and Privacy Preserving Agentic Browser

A computer implemented method for governing risk actions by an artificial intelligence (AI) browser, by classifying a proposed action by the AI browser based on a large language model (LLM) as safe or risky based on AI weights or based on policy rules; initiating a step up authentication flow for a risk action; presenting an action summary and required capabilities to the user for approval; and enforcing user configured spend or scope limits on the risk action.
Owner:TRAN BAO

Method for generating identity and access management policy recommendations

One variation of a method includes: accessing a first policy associated with a computer network; extracting a first entitlement from the first policy, the first entitlement granting permission to a first identity in the set of identities to access a first resource according to a first access level; accessing a first set of event data representing a first access attempt associated with the first resource by the first identity during a first time period, the first access attempt characterized by a second access level; detecting a deviation between the second access level and the first access level defined in the first entitlement; generating a second policy representing a second entitlement granting permission to the first identity to access the first resource according to the second access level in response to the deviation; and serving the second policy to an operator via an interface.
Owner:ALSO KNOWN AS INC

Providing an alternative access network indication to a client device in a wireless local area network roaming federation

Presented herein are techniques associated with providing an alternative network indication to a client device in a wireless local area network (WLAN) roaming federation. In one example a method is provided that may include obtaining access network information for each of a plurality of access networks that neighbor a first access network through connection of a client device with the first access network involving a first identity provider profile; determining an alternative access network with which the client device is recommended to seek connection or an alternative identity provider profiles with which the client device is recommended to connect to the first access network; and enabling the client device to initiate a connection with the alternative access network or to re-initiate a connection with the first access network utilizing the alternative identity provider profile.
Owner:CISCO TECHNOLOGY INC

Intent-based policy configuration using natural language

Techniques are described for providing a natural language network security policy assistant for allowing a network administrator to implement network security policies using natural language security policy requests. A natural language request can be received by a user and can be translated using Artificial Intelligence into one or more security policy clauses. If the natural language security policy request leads to ambiguities with regard to intended security policies, one or more clarifying questions can be generated as natural language questions and sent to the user for clarification. One or more security policies can be implemented based on the one or more security policy clauses generated in response to the natural language security policy request and / or the natural language response to the clarifying questions.
Owner:CISCO TECHNOLOGY INC

Methods and systems for facilitating single sign-on and passwordless sign-on

Computer-implemented methods and systems for facilitating single sign-on (SSO) and passwordless sign-on to a web service provider are provided. A client device authorized for SSO or passwordless sign-on generates and stores a device-specific key that it uses to encrypt a credential bundle containing key(s) necessary to access a cryptographically protected resource provided by the web service provider. The encrypted credential bundle is stored by the web service provider and provided to the authorized client device upon a successful authentication via SSO or passwordless sign-on. The authorized device uses the locally stored device-specific key to decrypt the encrypted credential bundle received from the web service provider to obtain the key(s) necessary to access the cryptographically protected resource.
Owner:AGILEBITS INC DBA 1PASSWORD

Handling of certificates by intermediate actors

Handling of certificates by intermediate actors, including: receiving, by a proxy and from a client, a client certificate and a first private key; generating, by the proxy and based on the client certificate and the first private key, an intermediate certificate; generating, by the proxy and in response to a request from the client to connect to a destination, an alternate certificate for the destination; and providing, to the client, a certificate chain comprising the alternate certificate, the intermediate certificate, and the client certificate.
Owner:FORTINET INC

Systems and Methods for Performing Secure Transactions on Blockchain

Systems and methods for securing transactions in accordance with various embodiments of the invention are illustrated. One embodiment includes a method for confirming token ownership rights. The method generates a pre-image value using a random number generator. The method generates an action request that corresponds to an action performed cryptographic token(s). The method derives a commit output based on the pre-image value. The method generates a commit request that obfuscates the action request based on the commit output and submits the commit request to an immutable ledger. The method receives a confirmation when the commit request is approved by the ledger. When a reveal request referencing the commit output is published, the method receives a confirmation of at least one of: the reveal request being published, that the reveal request comprises a reference to the commit output, or that the action request has been approved.
Owner:ARTEMA LABS INC

Multi-class network security threat perception and active and passive cooperative response processing system and method

The invention discloses a multi-class network security threat perception and active and passive cooperative response processing system and method, and the system comprises a multi-class threat perception module which is used for perceiving a plurality of security threats existing in a network environment, and transmitting an obtained security event to a threat information association module; the threat information association module is used for analyzing and integrating various security events and extracting threat information from the security events; the attack graph-based threat path analysis module is used for mining vulnerability information in a network system, describing a network topology structure and an operation state, constructing an attack graph and obtaining active defense nodes in combination with a currently occurring security event and an analysis result of the attack graph; and the strategy generation module generates a corresponding response processing strategy according to the threat information and the property and the emergency degree of the security event, and generates an active defense strategy in combination with the active defense node, thereby realizing active defense and advanced deployment and control of potential threats. According to the invention, network security threats can be timely and effectively found and coped with.
Owner:CHINA ELECTRONICS TECH CYBER SECURITY CO LTD +2

Secure cryptographic secret bootstrapping in a provider network

Techniques for secure cryptographic secret bootstrapping balance the need to quickly and conveniently restore cryptographic secrets to server computers in the event of an outage with the need for security. Before the outage, a server computer uses a trusted platform module of the server computer to seal an encryption key used to encrypt a secret stored at the server computer. In response to the outage, the server computer restores the secret by using the trusted platform module to unseal the encryption key and then using the unsealed encryption key to decrypt the encrypted secret. The techniques can be used to restore cryptographic secrets rapidly and securely to a cluster of server computers used for cryptographic operations in a provider network without the overhead of safe room procedures.
Owner:AMAZON TECH INC

Personal Assistant with Secure LLM

A method for using a local large language model (LLM) within a user's secure computing environment is disclosed. The LLM operates behind a firewall to prevent transmission of sensitive data, and utilizes an encrypted vector database and artificial intelligence techniques for content retrieval, response generation, and task anticipation. This system can be used on mobile, wearable, vehicle, or IoT devices and offers various services such as health monitoring, financial advice, automated communications handling, and personalized daily activity optimization. It also has the ability to detect fraud, fine-tune responses using augmented user data, assist in negotiations, identify personal interests, and provide health recommendations based on dietary and physical activity data.
Owner:TRAN BAO

Enabling cellular based zero trust network access

PendingUS20250203367A1Security arrangementGeneric Bootstrapping ArchitectureInternet privacy
A method performed by a user equipment to establish a secured connection with an application entity in an enterprise network. The method comprises sending an establishment request to a secure access secure edge (SASE) entity: receiving an establishment response from the application entity if the SASE entity determines to allow the establishment request and authorizes Generic Bootstrapping Architecture / Authenticated Key Management for Application (GBA / AKMA) platform to share a session key with the application entity; and establishing a connection with the application entity based on the session key.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Method for improving IT security in a network

Method and apparatus for protecting computer resources from malicious attack including baseline sentinels and warrior sentinels. Baseline sentinels are deployed on a network serving only as decoys and containing no company data. When any attempt to communicate with a baseline sentinel is detected, a host of warrior sentinels (also containing no company data) are deployed to act as additional decoys, diminishing the chance that a malicious attack will reach a valuable computer resource and collecting information on the malicious attacker. Once the malicious attack stops or is defeated, the warrior sentinels are retired and the system resets to baseline sentinels.
Owner:SENTINEL FORGE TECHNOLOGIES LLC

Predicting a probability associated with an unexploited vulnerability

A server determines vulnerabilities associated with components of a computing device. The server determines attributes associated with individual vulnerabilities. The server determines a subset of the vulnerabilities that includes unexploited vulnerabilities. The server executes a machine learning model to predict a probability of an exploit being created for a particular unexploited vulnerability in the subset. The server sends to a device: information identifying the particular unexploited vulnerability, particular attributes associated with the particular unexploited vulnerability, and the probability of an exploit being created for the particular unexploited vulnerability.
Owner:RAPID7 INC

Systems and methods for generating and utilizing temporary digital wallet

A computer may generate a temporary digital wallet containing one or more anonymous payment tokens and transmit the temporary digital wallet to a user device of a user. When the user provides an anonymous payment token of the one or more anonymous payment tokens to a point of sale (POS) system, the computer may receive from the POS system or other systems connected thereto, a request to authorize payment for the anonymous payment token. The request to authorize payment may also include an amount to be paid by the user to the POS system. Using the anonymous payment token, the computer may retrieve a user account and determine that the user account has sufficient funds for the transaction. Based upon the determination that the user account has sufficient funds, the computer may transmit an authorization confirmation back to the POS system or any other system that the authorization request originated from.
Owner:UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)

Identifying denial-of-service attacks

A computer-implemented method of identifying a denial-of-service attack during a threshold signature scheme, wherein each participant has respective shares of first and second shared secrets, wherein the method is performed by a first participant of the group and comprises: calculating a first target share; calculating a target value based on the first target share and a first predetermined amount of other target shares; calculating a target public key corresponding to the target value; calculating a first verification share based on the first share of the first shared secret and a public key corresponding to the second shared secret; calculating a verification public key based on at least the first verification share and a second predetermined amount of other verification shares; and determining whether at least one other participant is attempting a denial-of-service attack based on whether the verification public key matches the target public key.
Owner:NCHAIN LICENSING AG

Establishing a trust relationship between a peripheral device and a server

A method of authorizing a computer mouse to perform a particular action may include receiving, by a network device, a request associated with a particular action to be performed by a computer mouse. The request may be digitally signed using a private device key of the computer mouse. The method may include validating, by the network device, the digitally signed request using a public device key previously provided by the computer mouse. The method may include generating a response to the request. The response may indicate whether the computer mouse is authorized to perform the particular action associated with the trusted request. The method may include sending the response to a client device associated with the computer mouse.
Owner:LOGITECH EUROPE SA

Authorization of Consumer Network Functions

Embodiments include methods performed by a service consumer network function (NF) of a communication network. Such methods include sending, to a network repository function (NRF) of the communication network, a request for an access token for notifications from a service producer NF of the communication network. The request includes a list of alternative notification endpoints. Such methods also include receiving, from the NRF, an access token for the notifications from the service producer NF. The access token includes the list of alternative notification endpoints. Such methods also include sending, to the service producer NF, a subscription request for the notifications. The subscription request includes the received access token, a primary notification endpoint, and binding information usable for selecting an alternative notification endpoint from the list. Other embodiments include complementary methods performed by NRFs and service producer NFs, as well as network nodes / functions that perform such methods.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Secure device attestation using entitlement tokens

Apparatuses, systems, and techniques for issuing entitlement tokens to a root of trust allowing the root of trust to take certain action(s) with respect to a component that it secures, for example, to affect a change in the software and / or features available to the component it secures. In some embodiments, the entitlement token issuance process may involve receiving an attestation report corresponding to a root of trust of a computing system, wherein the attestation report is cryptographically signed using a private key unique to the root of trust, verifying the attestation report using a public key corresponding to the private key, and based at least upon successful verification of the attestation report, issuing an entitlement token for the root of trust allowing the root of trust to take one or more actions with respect to a system component secured by the root of trust.
Owner:NVIDIA CORP

Personal assistant with secure LLM

A method for using a local large language model (LLM) within a user's secure computing environment is disclosed. The LLM operates behind a firewall to prevent transmission of sensitive data, and utilizes an encrypted vector database and artificial intelligence techniques for content retrieval, response generation, and task anticipation. This system can be used on mobile, wearable, vehicle, or IoT devices and offers various services such as health monitoring, financial advice, automated communications handling, and personalized daily activity optimization. It also has the ability to detect fraud, fine-tune responses using augmented user data, assist in negotiations, identify personal interests, and provide health recommendations based on dietary and physical activity data.
Owner:TRAN BAO

IoT security policy on a firewall

Techniques for enforcing policies on Internet of Things (IoT) device communications are disclosed. Information associated with a network communication of an IoT device is received. The received information is used to determine a device profile, including a device type, to associate with the IoT device. A recommended security policy to be applied to the IoT device by a security appliance is generated.
Owner:PALO ALTO NETWORKS INC

Government affair cloud cross-department data security sharing method and device

The invention provides a government affair cloud cross-department data security sharing method and device, and relates to the technical field of data security. The method comprises the following steps: a main chain of a block chain performs first-level verification on a requester based on a VerifyCredate contract and an access policy white list set by a department to which government affair data belongs; the access strategy is a dynamic attribute base access strategy generated by a department to which the government affair data belongs based on a dynamic attribute encryption technology; under the condition that the first-level verification is passed, generating an access credential, synchronizing the access credential to a side chain of the block chain, generating a zero-knowledge proof by the side chain according to the operation log, and initiating a zero-knowledge proof verification request to the main chain to perform second-level verification; and under the condition that the main chain passes the second-level verification, determining a cross-domain trust score between the government affair data requesting department and the department to which the government affair data belongs based on the digital certificate submitted by the requester by adopting a federal model, and performing third-level verification according to the cross-domain trust score. According to the invention, the data sharing security can be improved.
Owner:CICC DATA (WUHAN) SUPERCOMPUTING TECH CO LTD

Compromised endpoint credentials interceptor

Real-time monitoring and alerting of breached security credentials for server-based endpoints is described herein. In various embodiments, a software component (that intercepts outgoing network traffic from a computing device) or a server-based breach monitoring component may receive a request for endpoint data. Credential data may be included in the request. The endpoint and / or the credential data may be compared to credential data linked to a list of compromised endpoints. An alert may be generated for the client device when both a match is detected with credential data of a breach object on the list of compromised endpoints and the breach time field of the breach object is after a previous credentials change for the endpoint. Access to the endpoint may be blocked and / or a change password mechanism may also be displayed to change the user credentials prior to revisiting the endpoint.
Owner:LOOKOUT INC

Password authentication using cryptographic key handle-based authentication records

A process includes receiving credentials associated with a request to access a computer platform. The credentials include a password and a user identification. The process includes determining a key handle and a reference cryptographic digest corresponding to the user identification. The process includes determining a second cryptographic digest corresponding to the user identification. Determining the second cryptographic digest includes providing the key handle and the password to a security processor of the computer platform and initiating an operation by the security processor to apply a keyed-hashing function to the password based on a cryptographic key corresponding to the key handle to provide the second cryptographic digest. The security processor stores the cryptographic key. The process includes regulating access to the computer platform based on a comparison of the second cryptographic digest to the reference cryptographic digest.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP