Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

7494 results about "Internet privacy" patented technology

Internet privacy involves the right or mandate of personal privacy concerning the storing, repurposing, provision to third parties, and displaying of information pertaining to oneself via the Internet. Internet privacy is a subset of data privacy. Privacy concerns have been articulated from the beginnings of large-scale computer sharing.

Automatically Investigating Security Incidents and Generating Security Incident Reports Using a Large Language Model (LLM)

Automatically investigating security incidents and generating security incident reports using a Large Language Model (LLM). A computerized system receives an incoming Security Alert Message pertaining to a possible security-related incident. The system automatically feeds into the LLM at least: the content of the Security Alert Message; the metadata of the Security Alert Message; context information describing a security domain; and organization context information pertaining to users and machines of that organization. The system automatically prompts the LLM to automatically investigate the Security Alert Message and to automatically generate a detailed Incident Report pertaining to the Security Alert Message.
Owner:VARONIS SYSTEMS INC

Know your model and know your data systems and methods for transactions

In embodiments, systems and methods for configuring and deploying artificial intelligence driven transacting agents that are permitted to autonomously execute transactions on behalf of the individual or organization and configuring the transacting agent based on the agent configuration instructions and a set of predefined system prompts. The method further includes granting the transacting agent access to a digital wallet associated with the individual or organization and deploying the transacting agent to a public network, such that the transacting agent executes transactions on behalf of the individual or organization via one or more digital marketplaces using the digital wallet to which the transacting agent was granted access. In some embodiments, the transacting agent is granted access to the digital wallet using a consent token. In some embodiments, the method also includes hyper-personalizing and / or fine-tuning the agent.
Owner:STRONG FORCE TX PORTFOLIO 2018 LLC

Dynamic digital watermarking system for real-time user activity fingerprinting and unauthorized access tracking

A method is provided for dynamically generating a digital watermark for a data file. The method includes receiving a request to access the data file from a user; dynamically generating an encryption key based on at least one parameter selected from the group consisting of the identity of the user, the time of access, and the mode of access; embedding a digital watermark into the data file using the dynamically generated encryption key, wherein the digital watermark is unique to the request; providing access to the data file with the embedded digital watermark to the user; and storing information related to the encryption key and the parameters used for its generation in a secure database.
Owner:LEPTUDE INC

Network egress access control with untrusted intermediary

A network egress request is received from a container service within a cloud data platform. A cryptographically signed egress policy associated with the network egress request is received by a trusted service controller of the cloud data platform. The network egress request is validated against the cryptographically signed egress policy. Based on the validation, a determination of whether the network egress request complies with the cryptographically signed egress policy is established. Upon validation, the network egress request is granted or denied based on the determination.
Owner:SNOWFLAKE INC

Security and Privacy Preserving Agentic Browser

A computer implemented method for governing risk actions by an artificial intelligence (AI) browser, by classifying a proposed action by the AI browser based on a large language model (LLM) as safe or risky based on AI weights or based on policy rules; initiating a step up authentication flow for a risk action; presenting an action summary and required capabilities to the user for approval; and enforcing user configured spend or scope limits on the risk action.
Owner:TRAN BAO

Handling of certificates by intermediate actors

Handling of certificates by intermediate actors, including: receiving, by a proxy and from a client, a client certificate and a first private key; generating, by the proxy and based on the client certificate and the first private key, an intermediate certificate; generating, by the proxy and in response to a request from the client to connect to a destination, an alternate certificate for the destination; and providing, to the client, a certificate chain comprising the alternate certificate, the intermediate certificate, and the client certificate.
Owner:FORTINET INC

Systems and Methods for Performing Secure Transactions on Blockchain

Systems and methods for securing transactions in accordance with various embodiments of the invention are illustrated. One embodiment includes a method for confirming token ownership rights. The method generates a pre-image value using a random number generator. The method generates an action request that corresponds to an action performed cryptographic token(s). The method derives a commit output based on the pre-image value. The method generates a commit request that obfuscates the action request based on the commit output and submits the commit request to an immutable ledger. The method receives a confirmation when the commit request is approved by the ledger. When a reveal request referencing the commit output is published, the method receives a confirmation of at least one of: the reveal request being published, that the reveal request comprises a reference to the commit output, or that the action request has been approved.
Owner:ARTEMA LABS INC

Secure cryptographic secret bootstrapping in a provider network

Techniques for secure cryptographic secret bootstrapping balance the need to quickly and conveniently restore cryptographic secrets to server computers in the event of an outage with the need for security. Before the outage, a server computer uses a trusted platform module of the server computer to seal an encryption key used to encrypt a secret stored at the server computer. In response to the outage, the server computer restores the secret by using the trusted platform module to unseal the encryption key and then using the unsealed encryption key to decrypt the encrypted secret. The techniques can be used to restore cryptographic secrets rapidly and securely to a cluster of server computers used for cryptographic operations in a provider network without the overhead of safe room procedures.
Owner:AMAZON TECH INC

Personal Assistant with Secure LLM

A method for using a local large language model (LLM) within a user's secure computing environment is disclosed. The LLM operates behind a firewall to prevent transmission of sensitive data, and utilizes an encrypted vector database and artificial intelligence techniques for content retrieval, response generation, and task anticipation. This system can be used on mobile, wearable, vehicle, or IoT devices and offers various services such as health monitoring, financial advice, automated communications handling, and personalized daily activity optimization. It also has the ability to detect fraud, fine-tune responses using augmented user data, assist in negotiations, identify personal interests, and provide health recommendations based on dietary and physical activity data.
Owner:TRAN BAO

Predicting a probability associated with an unexploited vulnerability

A server determines vulnerabilities associated with components of a computing device. The server determines attributes associated with individual vulnerabilities. The server determines a subset of the vulnerabilities that includes unexploited vulnerabilities. The server executes a machine learning model to predict a probability of an exploit being created for a particular unexploited vulnerability in the subset. The server sends to a device: information identifying the particular unexploited vulnerability, particular attributes associated with the particular unexploited vulnerability, and the probability of an exploit being created for the particular unexploited vulnerability.
Owner:RAPID7 INC

Secure device attestation using entitlement tokens

Apparatuses, systems, and techniques for issuing entitlement tokens to a root of trust allowing the root of trust to take certain action(s) with respect to a component that it secures, for example, to affect a change in the software and / or features available to the component it secures. In some embodiments, the entitlement token issuance process may involve receiving an attestation report corresponding to a root of trust of a computing system, wherein the attestation report is cryptographically signed using a private key unique to the root of trust, verifying the attestation report using a public key corresponding to the private key, and based at least upon successful verification of the attestation report, issuing an entitlement token for the root of trust allowing the root of trust to take one or more actions with respect to a system component secured by the root of trust.
Owner:NVIDIA CORP

Personal assistant with secure LLM

A method for using a local large language model (LLM) within a user's secure computing environment is disclosed. The LLM operates behind a firewall to prevent transmission of sensitive data, and utilizes an encrypted vector database and artificial intelligence techniques for content retrieval, response generation, and task anticipation. This system can be used on mobile, wearable, vehicle, or IoT devices and offers various services such as health monitoring, financial advice, automated communications handling, and personalized daily activity optimization. It also has the ability to detect fraud, fine-tune responses using augmented user data, assist in negotiations, identify personal interests, and provide health recommendations based on dietary and physical activity data.
Owner:TRAN BAO

Government affair cloud cross-department data security sharing method and device

The invention provides a government affair cloud cross-department data security sharing method and device, and relates to the technical field of data security. The method comprises the following steps: a main chain of a block chain performs first-level verification on a requester based on a VerifyCredate contract and an access policy white list set by a department to which government affair data belongs; the access strategy is a dynamic attribute base access strategy generated by a department to which the government affair data belongs based on a dynamic attribute encryption technology; under the condition that the first-level verification is passed, generating an access credential, synchronizing the access credential to a side chain of the block chain, generating a zero-knowledge proof by the side chain according to the operation log, and initiating a zero-knowledge proof verification request to the main chain to perform second-level verification; and under the condition that the main chain passes the second-level verification, determining a cross-domain trust score between the government affair data requesting department and the department to which the government affair data belongs based on the digital certificate submitted by the requester by adopting a federal model, and performing third-level verification according to the cross-domain trust score. According to the invention, the data sharing security can be improved.
Owner:CICC DATA (WUHAN) SUPERCOMPUTING TECH CO LTD

Systems and methods for intelligent real-time KYC identity verification using government issued documents and biometric matching

According to various embodiments, a system and method for verifying a user's identity using both document-based and biometric data is disclosed. The system may prompt a user to upload an image of a government-issued identification document and extract user information from the image using optical character recognition (OCR). The system may also extract the embedded face image from the ID and prompt the user to take a real-time selfie while performing one or more randomized actions or poses. A facial recognition engine may compare the extracted ID image to the live selfie to determine a similarity score. Based on this match, along with optional document authenticity checks, the system may confirm the user's identity in real-time for use cases such as account access, onboarding, and regulatory KYC compliance.
Owner:CELLIGENCE INTERNATIONAL LLC

Electronic data security management system and method

The invention provides an electronic data security management system and method. The method comprises the following steps: acquiring an access auditing log; extracting behavior characteristics when the user accesses according to the access audit log, and further determining an intrusion risk index when the edge security node is accessed; generating an adversarial sample of the edge security node in the abnormal access mode, and determining a security policy parameter according to the adversarial sample in combination with a historical real attack sample of the edge security node; and aggregating the intrusion risk index and the security policy parameter into risk linkage information, and updating an on-chain trust certificate of each edge security node according to the risk linkage information and a historical trust value of each edge security node, thereby synchronously updating an access policy of each edge security node. By adopting the scheme of the invention, security management can be performed on the data uploaded by the edge node.
Owner:CHONGQING COLLEGE OF ELECTRONICS ENG

Sidecar Security Pattern for Agent Communications

Systems and methods for securing agent communications in a multi-agent system including deploying an agent to communicate with external servers, instantiating a sidecar security service in communication with the agent and including at least one of a guardrails service, a security layer, an encryption module, and an integrity checker configured to validate resources tools using hash-based verification mechanisms. Communications including messages between the primary and the external servers are intercepted by the sidecar security service, which then performs at least one of filtering the one or more messages by the guardrails service, authenticating one or more server connections by the security layer, encrypting one or more outbound requests by the encryption module, or verifying an integrity of resources and tool definitions by the integrity checker.
Owner:MADISETTI VIJAY

Network security policy generation and distribution

Systems, devices, and techniques are disclosed for network security policy generation and distribution. A security policy written using a Domain Specific Language (DSL) for network security may be received. The security policy may be associated with a service owner and a control plane. A representation of the security policy may be generated from the security policy. A configuration bundle of the service owner may be updated with the representation of the security policy. The security policy may be determined to be approved. A rule set may be generated from the representation of the security policy. A differential between the rule set and a current rule set may be determined. A security component associated with the control plane based on the differential may be configured.
Owner:SALESFORCE INC

Sports betting apparatus and method

An apparatus, including a processor which provides an electronic forum which provides a video or audio broadcast of a sporting event and allows users to communicate with one another, post comments, place a bet or bets, receive information regarding bets available, betting odds, changes in betting odds, or analytics information, or report an instance of suspected game fixing, match fixing, or cheating, before, during, or after, the sporting event; a transmitter, which transmits the electronic forum to a user communication device; and a receiver which receives information transmitted from the user communication device. The processor processes an outcome of a bet on the sporting event and determines if the bet is a winning bet or losing bet. The apparatus generates a report and transmits the report to a computer associated with a sport governing body, governmental entity, gaming facility, analytics provider, social network, financial institution, or escrow agent.
Owner:JOAO RAYMOND ANTHONY

Cryptographic agility

A method for updating a device, including: receiving, by the device, a public one-time signature key; receiving, by the device, a secret encryption key; receiving an encrypted update package and signature from an update provider; verifying the signature using the public one-time signature key; decrypting the encrypted update package using the secret encryption key; and updating the device using the decrypted update package.
Owner:NXP BV

Proxy for Security in Sessions Involving Certificate-Pinned Applications

The disclosed technology teaches a method for security monitoring in TLS or other certificate-pinned sessions by a cloud-based network security system. An endpoint routing client directs sessions through an inspection proxy by secure tunneling. A secure web gateway buffers encrypted packets in a new session with a cloud-based resource, detects a connection access request from a certificate-pinned application, requests and receives key extraction, and forwards keys to the security system. Traffic is buffered for decryption and forwarded without modification until the keys are available. The keys are applied to allow decryption and re-encryption, on a proxy basis, of traffic between the client and a cloud based system. The inspection proxy applies security policies, even to the TLS or other certificate-pinned session.
Owner:NETSKOPE INC

Patient-empowered data management having a secure blockchain architecture with decentralized ownership

A blockchain-based system and method for secure and auditable sharing of medical image studies between providers, patients, and authorized recipients. The system has modules for verifying identities of trusted healthcare providers as issuers of medical data, managing secure storage of medical images and metadata, minting non-fungible tokens (NFTs) representing patient ownership of studies, authenticating patient consent for data sharing, and controlling access to shared data by authorized parties. Issuer registration authenticates healthcare providers permitted to submit studies by verifying credentials against authoritative sources. Secure data management employs cryptographic wallets and smart contracts to ensure only verified issuers can create new medical data NFTs on the blockchain. Automated processing extracts medical data such as image files and metadata upon upload for separate secure storage, with metadata references encrypted in the associated NFT. The system generates patient-controlled wallets for managing ownership of their medical NFTs without separate identity verification. Patient consent for sharing data is authenticated through multi-signature wallets requiring patient approval before minting study NFTs. Controlled access for other parties is gated by cryptographic proofs of authorization without exposing data. The immutable blockchain ledger records all sharing transactions initiated through patient and provider wallets, providing transparency and an auditable trail of how and when medical data is shared or accessed and by whom. The decentralized architecture promotes patient control, security, and accountability in managing sensitive healthcare information.
Owner:MEDIMINT LLC

Techniques for token proximity transactions

Systems and methods are provided to enable a user to conduct a transaction using their credentials stored on a secure server computer (e.g., a computer associated with a partner such as another merchant) by merely presenting their authentication data at a physical location via an auxiliary device. An auxiliary device may be provided for interfacing with a partner's backend server (e.g., the secure server computer). In some embodiments, biometric authentication may provide a mechanism for a true seamless and potentially frictionless (in the case of modalities that do not require physical contact) interaction. Payment can occur without any need for a card, phone, wearable, or any other user device as long as the auxiliary device is able to recognize the user and retrieve a credential that can be linked to that user.
Owner:VISA INTERNATIONAL SERVICE ASSOCIATION

Cross-domain identity authentication and access authorization method, system, equipment and medium

The invention discloses a cross-domain identity authentication and access authorization method, system and device and a medium, and belongs to the field of Internet of Things. According to the method, a unified identity authentication mechanism and a dynamic authority control model are constructed based on a decentralized identifier and a block chain technology. Firstly, an Internet of Things entity submits decentralized identifier information through an identity authentication request; the system generates identity metadata according to the request and records the identity metadata to an identity registry, and meanwhile, constructs a decentration identification document and stores the decentration identification document to a verifiable data registry. And then, the authorizer executes point-to-point trust evaluation based on the identity data and the on-chain traceability information, and generates a verifiable certificate with an encrypted signature. And the verifier completes certificate verification through an intra-domain or cross-domain verification mode, and dynamically grants the authority according to the trust value and the access policy directory. Cross-domain trust migration and dynamic permission adjustment are supported, and the identity authentication security and the access control flexibility in the multi-domain environment of the Internet of Things are improved.
Owner:GCI SCI & TECH +1

Revocable attribute-based encryption method with strategy hiding

The invention discloses a revocable attribute-based encryption method with strategy hiding, which is based on ciphertext strategy attribute encryption, solves the problem that user privacy is leaked due to disclosure of an access strategy, realizes revocation of fine-grained user attribute access authority, and is proved to be completely safe. In a system establishment stage, system parameters are disclosed, a public key and a master key are generated, an authoritative authority authorizes a data user, distributes a private key and generates an AGK tree and an attribute group key, a data owner generates a ciphertext according to the public key, an access structure set by the data owner and a selected secret value, and the ciphertext is transmitted to the data owner. And then hiding the mapping function by using a cuckoo filter, positioning the attribute by a data user through the cuckoo filter, updating a private key by using an attribute group key, and finally decrypting the ciphertext to obtain the wanted information.
Owner:HUAIYIN INSTITUTE OF TECHNOLOGY

Anonymous Internet of Things identity authentication method and device based on anti-quantum computing password

The invention provides an anonymous Internet of Things identity authentication method and device based on an anti-quantum computing password. A key generation device sends a public key to a message sending end and a message receiving end, and sends a private key to an authentication server; the authentication server generates a blind parameter based on the private key, and sends the blind parameter to the message sending end; the message sending end performs blind operation based on the blind parameter, the public key and the to-be-transmitted message to obtain a blind message, and sends the blind message to the authentication server; the authentication server performs post-quantum signature on the blind message based on the private key to obtain a to-be-solved blind signature, and sends the to-be-solved blind signature to the message sending end; the message sending end carries out blind resolution operation on the to-be-resolved blind signature to obtain a target signature; the message sending end sends the to-be-transmitted message and the target signature to a message receiving end; and the message receiving end performs post-quantum verification on the target signature based on the public key, and if verification succeeds, processing is performed based on the to-be-transmitted message. Through the scheme of the invention, the user data security can be improved.
Owner:HANGZHOU HIKVISION DIGITAL TECHNOLOGY CO LTD

Secure conditional transfers of cryptographic key data and / or digital assets

Systems and methods for cryptographic key transfer are disclosed. A system receives an encrypted private key that is encrypted using a private key encryption key. The system receives an encrypted private key encryption key that is encrypted using a trusted contact encryption key. The system receives an indication that a condition is satisfied. The system sends the encrypted private key and the encrypted private key encryption key to a transferee device. The system receives, from the transferee device, a request for a transfer of funds. The request is signed using a private key, the private key having been decrypted from the encrypted private key using the private key encryption key, the private key encryption key having been decrypted from the encrypted private key encryption key using a trusted contact decryption key corresponding to the trusted contact encryption key. The system facilitates the transfer of funds in response to the request.
Owner:BLOCK INC

Return device, return method, and program

To provide a return device or the like that allows a person to receive service provision itself as a return from a local government by making a donation through hometown tax payment.SOLUTION: A return device 10 enables a doner to make a donation to a local government using a donor terminal 30, and in return for the donation, to receive service provision at a store of a service providing return service provider belonging to the local government. The return device includes: a memory processing unit that stores information about the local government and information about the service providing return service provider belonging to the local government; a communication processing unit that receives requests from the donor terminal 30, transmits screen configuration information to the donor terminal 30, and also transmits a payment execution request to an external server; and a control processing unit.SELECTED DRAWING: Figure 2
Owner:MY WAY CO LTD

Private data security sharing method and system based on block chain

The invention provides a privacy data security sharing method and system based on a block chain, and the method comprises the steps: carrying out the encryption and under-chain storage of obtained original privacy data, and generating a data identifier; constructing dynamic access control metadata based on the data identifier, and registering the dynamic access control metadata to the block chain to generate an initial version certificate; generating a new permission policy and derived key parameters in response to the permission change request; submitting an update transaction containing the new permission policy and the derived key parameter to the block chain, and generating an update version certificate; based on the access request, verifying the authority of the visitor through the version updating certificate, and when the verification is passed, generating a decryption parameter based on the derived key parameter and returning the data identifier; and in response to the data update request, generating update encrypted data based on the update version credential, and binding the historical version credential to generate a cross-version association proof. By adopting the method, the privacy data access authority management level can be provided.
Owner:QINGDAO UNIV