IP Library › Granted Patent US 12,568,107
Granted Patent B2
US 12,568,107 · App. 18/129,514 · Granted Mar 3, 2026

Method to reduce users from falling victim of ransomware

Inventors: Eric R Kern (Chapel Hill, NC); Robert Furda (Bratislava, SK); MD Kamrul Hasan (Romansville, PA); Mahesh Bharadwaj (Melbourne, AU)
Assignee: Lenovo Enterprise Solutions (Singapore) Pte. Ltd.
H04L63/1433H04L63/083H04L63/102H04L63/105H04L63/1425H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,568,107
App. No.
18/129,514
Granted
Mar 3, 2026
Kind
B2
Abstract

A method and computer program product to reduce users from falling victim of ransomware is disclosed. The method includes periodically administering, by a processor, a security awareness test to a user and generating a security awareness score based on user performance. The security awareness test assesses knowledge of the user with respect to ransomware and cybersecurity protocols of a computer system. The method includes monitoring compliance of the user with the ransomware and cybersecurity protocols and updating the security awareness score in response to changes to the performance and/or compliance. The updated security awareness score is embedded into a security chip of a hardware device of the computer system.

Claims (28)

1 . A method, comprising:

periodically administering, by a processor, a security awareness test to a user, wherein the security awareness test assesses knowledge of the user with respect to ransomware and cybersecurity protocols of a computer system;

generating, by a processor, a security awareness score for the user based on performance of the user on the security awareness test;

monitoring, by a processor, compliance of the user with the ransomware and cybersecurity protocols during use of the computer system;

updating, by a processor, the security awareness score in response to changes to the performance of the user on the security awareness test and/or the compliance with ransomware and cybersecurity protocols during computer system use; and

embedding, by a processor, the updated security awareness score of the user into a security chip of a hardware device of the computer system, wherein the hardware device communicates with the processor to deny the user access to at least a portion of the computer system based on the updated security awareness score falling below a score threshold.

2 . The method of claim 1 , wherein the security awareness test further assesses knowledge of the user with respect to cybercrime awareness and virus awareness.

3 . The method of claim 1 , further comprising prompting, by the processor, the user to obtain further training in response to that the user is denied access to the at least a portion of the computer system.

4 . The method of claim 1 , further comprising generating, by the processor, the security awareness test, wherein the security awareness test comprises a written component and a live action component.

5 . The method of claim 1 , further comprising determining a required level of access to enable access to the at least a portion of the computer system.

6 . The method of claim 5 , further comprising verifying that a user level of access corresponds to the required level of access.

7 . The method of claim 6 , further comprising automatically updating, by the processor, the user level of access in response to the updated security awareness score.

8 . The method of claim 6 , wherein embedding the updated security awareness score into the security chip further comprises embedding the user level of access into the security chip.

9 . The method of claim 1 , wherein periodically administering the security awareness test comprises periodically administering the security awareness test to the user in response to a request from the user to access the computer system.

10 . The method of claim 1 , wherein denying the user access to the at least a portion of the computer system comprises:

receiving, by a processor, a request from the user to access the computer system;

querying, by the processor, the user for authentication credentials to validate a user identity, the authentication credentials comprising a username and a password;

validating, by the processor, the user identity based on the authentication credentials;

accessing, by the processor, the updated security awareness score of the user;

comparing, by the processor, the security awareness score to a score threshold required for access to the computer system; and

denying, by the processor, the user access to the at least a portion of the computer system in response to the security awareness score does not meet the score threshold.

11 . The method of claim 1 , further comprising automatically decreasing the security awareness score of the user on one of a periodic basis or a random basis to by an amount sufficient to prevent the user from accessing at least a portion of the computing system, and further comprising administering an additional security awareness test to the user to allow the user an opportunity to regain access to the at least a portion of the computer system.

12 . A computer program product comprising a non-transitory computer readable storage medium storing code, the code being configured to be executable by a processor to perform operations comprising:

periodically administering a security awareness test to a user, wherein the security awareness test assesses knowledge of the user with respect to ransomware and cybersecurity protocols of a computer system;

generating a security awareness score for the user based on performance of the user on the security awareness test;

monitoring compliance of the user with the ransomware and cybersecurity protocols during use of the computer system;

updating the security awareness score in response to changes to the performance of the user on the security awareness test and/or the compliance with ransomware and cybersecurity protocols during computer system use; and

embedding the updated security awareness score for the user into a security chip of a hardware device of the computer system, wherein the hardware device communicates with the processor to deny the user access to at least a portion of the computer system based on the updated security awareness score falling below a score threshold.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 8, 2024
From: LENOVO GLOBAL TECHNOLOGY (UNITED STATES) INC.
To: LENOVO ENTERPRISE SOLUTIONS (SINGAPORE) PTE LTD.
Reel/Frame 067929/0952 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 4, 2023
From: KERN, ERIC R; FURDA, ROBERT; HASAN, MD KAMRUL; BHARADWAJ, MAHESH
To: LENOVO GLOBAL TECHNOLOGY (UNITED STATES) INC.
Reel/Frame 063216/0850 →
Continuity (1)
Related Publication 20240333745A1 · Oct 3, 2024
References Cited (40)
US 9438613B1 · Paithane · 2016 [cited by examiner]
US 10469525B2 · Hittel · 2019 [cited by examiner]
US 10776484B2 · Nagata · 2020 [cited by examiner]
US 10868820B2 · Sites · 2020 [cited by examiner]
US 11349855B1 · Amit · 2022 [cited by examiner]
US 11803792B2 · Makhija · 2023 [cited by examiner]
US 20110265162A1 · Alavandar · 2011 [cited by examiner]
US 20170244740A1 · Mahabir · 2017 [cited by examiner]
US 20180034835A1 · Iwanir · 2018 [cited by examiner]
US 20180152402A1 · Tsou · 2018 [cited by examiner]
US 20180205754A1 · North · 2018 [cited by examiner]
US 20180278647A1 · Gabaev · 2018 [cited by examiner]
US 20180288080A1 · Keller · 2018 [cited by examiner]
US 20180365439A1 · Milman · 2018 [cited by examiner]
US 20190052664A1 · Kibler · 2019 [cited by examiner]
US 20200177612A1 · Kras · 2020 [cited by examiner]
US 20200177614A1 · Burns · 2020 [cited by examiner]
US 20200220892A1 · Gibson · 2020 [cited by examiner]
US 20200267183A1 · Vishwanath · 2020 [cited by examiner]
US 20200285737A1 · Kraus · 2020 [cited by examiner]
US 20200287917A1 · Sites · 2020 [cited by examiner]
US 20210006584A1 · Basballe Sorensen · 2021 [cited by examiner]
US 20210064758A1 · Zettel, II · 2021 [cited by examiner]
US 20210084049A1 · Kartoun et al. · 2021 [cited by applicant]
US 20210126944A1 · Lesperance · 2021 [cited by examiner]
US 20210232472A1 · Nagaraj · 2021 [cited by examiner]
US 20220060499A1 · Huda · 2022 [cited by examiner]
US 20220131900A1 · Karin · 2022 [cited by examiner]
US 20220150265A1 · Marett · 2022 [cited by examiner]
US 20220210171A1 · Grossman · 2022 [cited by examiner]
US 20220345485A1 · Kras · 2022 [cited by examiner]
US 20230098508A1 · Mishra · 2023 [cited by examiner]
US 20230325632A1 · Kasmani · 2023 [cited by examiner]
US 20230344860A1 · Agranonik · 2023 [cited by examiner]
US 20240143761A1 · Veprinsky · 2024 [cited by examiner]
US 20240144275A1 · Ammatanda · 2024 [cited by examiner]
US 20240289489A1 · Ezrielev · 2024 [cited by examiner]
Troesch et al., “Machine Learning for Network Intrusion Detection”, Final Report for CS 229, Fall 2014, pp. 1-5. [cited by applicant]
Dwoskin, “Facebook is rating the trustworthiness of its users on a scale from zero to 1”, The Washington Post, Aug. 21, 2018, pp. 1-3. [cited by applicant]
“The security ratings, response, and resilience company.”, SecurityScorecard, date website was accessed Nov. 29, 2022, pp. 1-7. [cited by applicant]