Patents by Inventor Doron Grinstein

Doron Grinstein has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Publication number: 20240121316
    Abstract: A system for cross cloud workload identity virtualization including a program having instructions to route a first network call from a workload in a first cloud computing environment addressed to a first cloud computing environment instance metadata service (IMS) having destination data with an IP address of 169.254.169.254 to a universal IMS (UIMS) different from the first cloud computing environment IMS, route a second network call from the workload addressed to a destination other than the first cloud computing environment IMS to the destination indicated by the second network call, respond to the first network call with credentials valid for accessing a cloud service provided in a second cloud computing environment. The workload can access the cloud service from the first cloud computing environment, and access the cloud service from a third cloud computing environment different from the first cloud computing environment.
    Type: Application
    Filed: December 18, 2023
    Publication date: April 11, 2024
    Inventors: Doron Grinstein, Julian Vassev, Dan Wilson
  • Patent number: 11848998
    Abstract: A system for cross cloud workload identity virtualization including a program having instructions to route a first network call from a workload in a first cloud computing environment addressed to a first cloud computing environment instance metadata service (IMS) having destination data with an IP address of 169.254.169.254 to a universal IMS (UIMS) different from the first cloud computing environment IMS, route a second network call from the workload addressed to a destination other than the first cloud computing environment IMS to the destination indicated by the second network call, respond to the first network call with credentials valid for accessing a cloud service provided in a second cloud computing environment. The workload can access the cloud service from the first cloud computing environment, and access the cloud service from a third cloud computing environment different from the first cloud computing environment.
    Type: Grant
    Filed: July 29, 2020
    Date of Patent: December 19, 2023
    Assignee: CONTROL PLANE CORPORATION
    Inventors: Doron Grinstein, Julian Vassev, Dan Wilson
  • Publication number: 20230145488
    Abstract: A system for cross cloud workload identity virtualization including a program having instructions to route a first network call from a workload in a first cloud computing environment addressed to a first cloud computing environment instance metadata service (IMS) having destination data with an IP address of 169.254.169.254 to a universal IMS (UIMS) different from the first cloud computing environment IMS, route a second network call from the workload addressed to a destination other than the first cloud computing environment IMS to the destination indicated by the second network call, respond to the first network call with credentials valid for accessing a cloud service provided in a second cloud computing environment. The workload can access the cloud service from the first cloud computing environment, and access the cloud service from a third cloud computing environment different from the first cloud computing environment.
    Type: Application
    Filed: January 4, 2023
    Publication date: May 11, 2023
    Inventors: Doron Grinstein, Julian Vassev, Dan Wilson
  • Publication number: 20220038544
    Abstract: A system for cross cloud workload identity virtualization including a program having instructions to route a first network call from a workload in a first cloud computing environment addressed to a first cloud computing environment instance metadata service (IMS) having destination data with an IP address of 169.254.169.254 to a universal IMS (UIMS) different from the first cloud computing environment IMS, route a second network call from the workload addressed to a destination other than the first cloud computing environment IMS to the destination indicated by the second network call, respond to the first network call with credentials valid for accessing a cloud service provided in a second cloud computing environment. The workload can access the cloud service from the first cloud computing environment, and access the cloud service from a third cloud computing environment different from the first cloud computing environment.
    Type: Application
    Filed: July 29, 2020
    Publication date: February 3, 2022
    Inventors: Doron Grinstein, Julian Vassev, Dan Wilson
  • Patent number: 9294466
    Abstract: The subject matter disclosed herein relates to authenticating an identity of users desiring access to an application program and determining whether an authenticated user is authorized to access one or more aspects of the application program.
    Type: Grant
    Filed: February 19, 2015
    Date of Patent: March 22, 2016
    Assignee: Disney Enterprises, Inc.
    Inventor: Doron Grinstein
  • Publication number: 20150180854
    Abstract: The subject matter disclosed herein relates to authenticating an identity of users desiring access to an application program and determining whether an authenticated user is authorized to access one or more aspects of the application program.
    Type: Application
    Filed: February 19, 2015
    Publication date: June 25, 2015
    Inventor: Doron Grinstein
  • Patent number: 8997246
    Abstract: The subject matter disclosed herein relates to authenticating an identity of users desiring access to an application program and determining whether an authenticated user is authorized to access one or more aspects of the application program.
    Type: Grant
    Filed: October 4, 2005
    Date of Patent: March 31, 2015
    Assignee: Disney Enterprises, Inc.
    Inventor: Doron Grinstein
  • Patent number: 8910048
    Abstract: A computing platform constructs an application from source code such that the application detects an attempt to access at least one secured entity of the application. Further, the at least one secured entity is registered with an authorization system by providing metadata that is descriptive of the at least one secured entity to the authorization system so that authorization metadata is generated based upon the metadata and a global unique identifier is assigned to the application and the metadata to identify the application and the metadata. The authorization metadata indicates an access policy to the at least one secured entity.
    Type: Grant
    Filed: November 7, 2011
    Date of Patent: December 9, 2014
    Assignee: Disney Enterprises, Inc.
    Inventor: Doron Grinstein
  • Publication number: 20120117612
    Abstract: A computing platform constructs an application from source code such that the application detects an attempt to access at least one secured entity of the application. Further, the at least one secured entity is registered with an authorization system by providing metadata that is descriptive of the at least one secured entity to the authorization system so that authorization metadata is generated based upon the metadata and a global unique identifier is assigned to the application and the metadata to identify the application and the metadata. The authorization metadata indicates an access policy to the at least one secured entity.
    Type: Application
    Filed: November 7, 2011
    Publication date: May 10, 2012
    Applicant: DISNEY ENTERPRISES, INC.
    Inventor: Doron Grinstein
  • Patent number: 8166404
    Abstract: The subject matter disclosed herein relates to authenticating an identity of users desiring access to an application program and determining whether an authenticated user is authorized to access one or more aspects of the application program.
    Type: Grant
    Filed: October 4, 2005
    Date of Patent: April 24, 2012
    Assignee: Disney Enterprises, Inc.
    Inventor: Doron Grinstein
  • Patent number: 7647625
    Abstract: The subject matter disclosed herein relates to authenticating an identity of users desiring access to an application program and determining whether an authenticated user is authorized to access one or more aspects of the application program.
    Type: Grant
    Filed: October 4, 2005
    Date of Patent: January 12, 2010
    Assignee: Disney Enterprises, Inc.
    Inventor: Doron Grinstein
  • Publication number: 20080263644
    Abstract: Distributed computing systems can exchange authorization information in a manner which alleviates the need for a receiving system to utilize any external systems when making an authorization decision. The trusted authorization provider can digitally sign authorization snippets of information. The requestor sends the digitally signed authorization snippet with the request. Because both computing processes trust the same authorization provider, the servicer of the request is able to grant or deny access in a completely autonomous fashion without having to rely on external resources for authorization. A requesting process can determine the digitally signed authorization snippet corresponding with the request. The servicing process can rely on the digitally signed authorization snippet to perform the authorization.
    Type: Application
    Filed: April 23, 2007
    Publication date: October 23, 2008
    Inventor: Doron Grinstein
  • Publication number: 20080178278
    Abstract: An internal gateway establishes persistent connections to an external gateway through permitted ports and protocols of a firewall. Software on the external gateway and the internal gateway collaborate in order to make available internal, firewall-protected resources to external clients securely and without having to modify network or firewall configurations. Any computing resource such as a web service, web application, or any other network addressable resource residing behind a firewall can be securely exposed in a generic fashion to clients on the external network. No special software is required by clients.
    Type: Application
    Filed: January 22, 2007
    Publication date: July 24, 2008
    Inventors: Doron Grinstein, Eric N. Kotler
  • Publication number: 20070079384
    Abstract: The subject matter disclosed herein relates to authenticating an identity of users desiring access to an application program and determining whether an authenticated user is authorized to access one or more aspects of the application program.
    Type: Application
    Filed: October 4, 2005
    Publication date: April 5, 2007
    Inventor: Doron Grinstein
  • Publication number: 20070079357
    Abstract: The subject matter disclosed herein relates to authenticating an identity of users desiring access to an application program and determining whether an authenticated user is authorized to access one or more aspects of the application program.
    Type: Application
    Filed: October 4, 2005
    Publication date: April 5, 2007
    Inventor: Doron Grinstein
  • Publication number: 20070079369
    Abstract: The subject matter disclosed herein relates to authenticating an identity of users desiring access to an application program and determining whether an authenticated user is authorized to access one or more aspects of the application program.
    Type: Application
    Filed: October 4, 2005
    Publication date: April 5, 2007
    Inventor: Doron Grinstein
  • Publication number: 20070079356
    Abstract: The subject matter disclosed herein relates to authenticating an identity of users desiring access to an application program and determining whether an authenticated user is authorized to access one or more aspects of the application program.
    Type: Application
    Filed: October 4, 2005
    Publication date: April 5, 2007
    Inventor: Doron Grinstein