IP Library Granted Patent US 12,651,073
Granted Patent B2
US 12,651,073 · App. 18/483,964 · Granted Jun 9, 2026

One or more devices providing improved security for any database including distributed applications and smart contracts

Inventors: Omar Alibrahim (Yarmouk, KW); Majid Ahmed Malaika (Riyadh, SA); Timothy Rude (Front Royal, VA)
Assignee: omPROTECT LLC
G06F21/577G06F9/45558G06F21/10G06F2009/45587G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,651,073
App. No.
18/483,964
Granted
Jun 9, 2026
Kind
B2
Abstract

One or more devices providing improved security for any database including a smart contract or distributed application executing on a virtual machine. Embodiments provide monitoring and incident response for execution of the smart contract or distributed application running on a blockchain, or any other distributed ledger technology. An aspect of some embodiments is detection of anomalies when executing the smart contract or distributed application in real-time. Embodiments may immediately respond to the detected anomalies, e.g., by switching control to a human operator, a reactive machine, or a machine learning operator. In an embodiment, operator response may include i) freezing execution, ii) resuming execution, or iii) reverting execution. Accordingly, in the event of an erroneous or fraudulent transaction, the operator machine may revert the smart contract or distributed application to a previously valid state, thereby preventing loss of digital assets or funds allocated to the smart contract or distributed application.

Claims (30)

1 . One or more devices providing improved pre-execution security for a smart contract or distributed application executing on a virtual machine, the one or more devices including one or more network interfaces, one or more processors, and one or more memories including instructions that upon execution by the one or more processors cause the one or more devices to perform operations comprising:

receiving, via the one or more network interfaces, a transaction initiated by a caller with the smart contract or distributed application of the virtual machine;

examining contents of the transaction to determine, using a plurality of stored security enforcement files stored in the one or more memories, whether the contents of the transaction include attributes satisfying a plurality of criteria for access to the smart contract or distributed application;

rejecting the transaction to the smart contract or distributed application upon determining that the contents of the transaction do not include the attributes satisfying the plurality of criteria; and

transmitting, via the one or more network interfaces, the transaction to the smart contract or distributed application upon determining that the contents of the transaction do include the attributes satisfying the plurality of criteria,

wherein examining the contents of the transaction includes applying one or more regular-expression patterns stored in the security enforcement files to validate formats of transaction fields.

2 . The one or more devices of claim 1 , wherein the plurality of stored security enforcement files include a whitelist of acceptable formats of contents of the transaction.

3 . The one or more devices of claim 1 , wherein the plurality of stored security enforcement files includes a whitelist of caller addresses.

4 . The one or more devices of claim 3 , wherein the examining of the contents of the transaction to determine whether the contents of the transaction include attributes satisfying the plurality of criteria further includes determining, by referring to the whitelist of caller addresses, whether an address of the caller is whitelisted for objects specific to the smart contract or distributed application.

5 . The one or more devices of claim 3 , wherein the examining of the contents of the transaction to determine whether the contents of the transaction include attributes satisfying the plurality of criteria further includes determining, by referring to the whitelist of caller addresses, whether the caller has been granted execution privileges.

6 . One or more devices providing improved during-execution security for a smart contract or distributed application executing on a virtual machine, the one or more devices including one or more network interfaces, one or more processors, and one or more memories including instructions that upon execution by the one or more processors cause the one or more devices to perform operations comprising:

receiving an instance of about real-time information regarding a state of the virtual machine during execution of the smart contract or distributed application;

examining the instance of about real-time information to determine, using a rules engine stored in the one or more memories, whether an anomaly is present within the instance of about real-time information;

freezing the execution of the smart contract or distributed application upon determining that the anomaly is present within the instance of about real-time information; and

sending a resume command to continue the execution of the smart contract or distributed application upon determining that the anomaly is not present within the instance of about real-time information, or upon receiving a resume instruction,

wherein the instance of about real-time information comprises a snapshot of the virtual machine including storage, memory, stack, and register data.

7 . The one or more devices of claim 6 , wherein an output alert is generated upon the determining that the anomaly is present within the instance of about real-time information, and awaits a response.

8 . The one or more devices of claim 7 , wherein the output alert results in a resume selection causing the one or more devices to forward the resume selection to the virtual machine to resume the execution of the smart contract or distributed application.

9 . The one or more devices of claim 7 , wherein the output alert results in a freeze selection causing the one or more devices to continue the operation of freezing the execution of the smart contract.

10 . The one or more devices of claim 7 , wherein the output alert results in a revert selection causing the one or more devices to forward the revert selection to the virtual machine to revert the execution of the smart contract or distributed application.

11 . The one or more devices of claim 6 , wherein the operations further comprise:

receiving, via the one or more network interfaces, a transaction initiated by a caller with the smart contract or distributed application of the virtual machine;

examining contents of the transaction to determine, using a plurality of stored security enforcement files stored in the one or more memories, whether the contents of the transaction include attributes satisfying a plurality of criteria for access to the smart contract or distributed application;

rejecting the transaction to the smart contract or distributed application upon determining that the contents of the transaction do not include the attributes satisfying the plurality of criteria; and

transmitting, via the one or more network interfaces, the transaction to the smart contract or distributed application upon determining that the contents of the transaction do include the attributes satisfying the plurality of criteria.

12 . The one or more devices of claim 11 , wherein an output alert is generated upon the determining that the anomaly is present within the instance of about real-time information, and awaits a response.

13 . The one or more devices of claim 7 , wherein the response to the output alert is generated by one or more separate devices that include a readable memory and that are in communication with the one or more devices.

14 . The one or more devices of claim 13 , wherein the one or more separate devices comprise a human-operated computing device.

15 . The one or more devices of claim 13 , wherein the one or more separate devices comprise a reactive computing device.

16 . The one or more devices of claim 13 , wherein the one or more separate devices comprise a machine-learning-operated device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 13, 2023
From: ALIBRAHIM, OMAR; MALAIKA, MAJID AHMED; RUDE, TIMOTHY
To: OMPROTECT LLC
Reel/Frame 065210/0440 →
Continuity (2)
Provisional Application 63379041 · Oct 11, 2022
Related Publication 20240119161A1 · Apr 11, 2024
References Cited (7)
US 10367645B2 · Dechu · 2019 [cited by examiner]
US 20180115425A1 · Dechu · 2018 [cited by examiner]
US 20180218364A1 · Cantrell · 2018 [cited by examiner]
US 20190306173A1 · Reddy · 2019 [cited by examiner]
US 20200082025A1 · Zhou · 2020 [cited by examiner]
US 20200204557A1 · Singh · 2020 [cited by examiner]
US 20220263896A1 · Shah · 2022 [cited by examiner]