Patents by Inventor Jeromy Scott Statia
Jeromy Scott Statia has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 12375475Abstract: Confining lateral traversal within a network. An authorization request identifies a credential, a protected first resource, and an identifier of a protected second resource for which authorization is requested. A lateral traversal policy associated with the second resource is identified, which constrains access to the second resource to only resources that belong to a subset of resources including the second resource. When it is determined that the credential is configured for access to the second resource, and when it is determined that the first resource belongs to the subset of resources including the second resource, an authorization token is issued, which authorizes the credential to access the second resource via the first resource. Alternatively, when it is determined that the credential is granted access to the second resource, and when it is determined that the first resource is outside of the particular subset of resources, the authorization request is denied.Type: GrantFiled: October 12, 2022Date of Patent: July 29, 2025Assignee: Microsoft Technology Licensing, LLCInventors: Jeromy Scott Statia, Jeffrey Ryan Bacon, Darrin Earl Curtis, Aaron Richard Davis, Douglas Anthony Rasler, Elizabeth Anne Phippen, Satish Devan, Bum Su Jung, Daniel James Dawson, George Kenneth Ringer
-
Patent number: 12149639Abstract: The present disclosure relates to systems, methods, and computer-readable media for enhancing security of communications between instances of clients and servers while enabling rotation of server certificates (e.g., X.509 certificates). The systems described herein involve updating a client list of server certificates (e.g., a certificate thumbprint) without reconfiguring or re-installing a client and/or server application, starting a new session (e.g., a hypertext transfer protocol secure (HTTPS) session), or deploying new code. The systems described herein may passively or actively update a client list of certificates to enable a client to security verify an identity of a server instance in a non-invasive way that boosts security from man-in-the-middle types of attacks.Type: GrantFiled: March 3, 2023Date of Patent: November 19, 2024Assignee: Microsoft Technology Licensing, LLCInventors: Jeromy Scott Statia, Chunsheng Yang, Priyanka Vilas Deo, Elizabeth Anne Phippen, Bradley Scott Turner
-
Publication number: 20240267373Abstract: Confining lateral traversal within a network. An authorization request identifies a credential, a protected first resource, and an identifier of a protected second resource for which authorization is requested. A lateral traversal policy associated with the second resource is identified, which constrains access to the second resource to only resources that belong to a subset of resources including the second resource. When it is determined that the credential is configured for access to the second resource, and when it is determined that the first resource belongs to the subset of resources including the second resource, an authorization token is issued, which authorizes the credential to access the second resource via the first resource. Alternatively, when it is determined that the credential is granted access to the second resource, and when it is determined that the first resource is outside of the particular subset of resources, the authorization request is denied.Type: ApplicationFiled: October 12, 2022Publication date: August 8, 2024Inventors: Jeromy Scott STATIA, Jeffrey Ryan BACON, Darrin Earl CURTIS, Aaron Richard DAVIS, Douglas Anthony RASLER, Elizabeth Anne PHIPPEN, Satish DEVAN, Bum Su JUNG, Daniel James DAWSON, George Kenneth RINGER
-
Publication number: 20230208655Abstract: The present disclosure relates to systems, methods, and computer-readable media for enhancing security of communications between instances of clients and servers while enabling rotation of server certificates (e.g., X.509 certificates). The systems described herein involve updating a client list of server certificates (e.g., a certificate thumbprint) without reconfiguring or re-installing a client and/or server application, starting a new session (e.g., a hypertext transfer protocol secure (HTTPS) session), or deploying new code. The systems described herein may passively or actively update a client list of certificates to enable a client to security verify an identity of a server instance in a non-invasive way that boosts security from man-in-the-middle types of attacks.Type: ApplicationFiled: March 3, 2023Publication date: June 29, 2023Inventors: Jeromy Scott STATIA, Chunsheng YANG, Priyanka Vilas DEO, Elizabeth Anne PHIPPEN, Bradley Scott TURNER
-
Patent number: 11601289Abstract: The present disclosure relates to systems, methods, and computer-readable media for enhancing security of communications between instances of clients and servers while enabling rotation of server certificates (e.g., X.509 certificates). The systems described herein involve updating a client list of server certificates (e.g., a certificate thumbprint) without reconfiguring or re-installing a client and/or server application, starting a new session (e.g., a hypertext transfer protocol secure (HTTPS) session), or deploying new code. The systems described herein may passively or actively update a client list of certificates to enable a client to security verify an identity of a server instance in a non-invasive way that boosts security from man-in-the-middle types of attacks.Type: GrantFiled: January 7, 2020Date of Patent: March 7, 2023Assignee: Microsoft Technology Licensing, LLCInventors: Jeromy Scott Statia, Chunsheng Yang, Priyanka Vilas Deo, Elizabeth Anne Phippen, Bradley Scott Turner
-
Patent number: 11063950Abstract: A system discloses providing secure remote desktop session host experience to a user for a selected application while controlling the user's access to non-core functionalities of the selected application. An implementation of the system disclosed herein identifies a non-core functionality of an application running on a server, flags the executable files, shared object library files, and the registration keys necessary for the non-core functionality of the application, and disables the application's access to the identified executable files, the identified shared object library files, and the identified registration keys.Type: GrantFiled: June 9, 2016Date of Patent: July 13, 2021Assignee: Microsoft Technology Licensing, LLCInventors: George Ringer, Jeromy Scott Statia, Dayne Allen Thompson
-
Publication number: 20210211307Abstract: The present disclosure relates to systems, methods, and computer-readable media for enhancing security of communications between instances of clients and servers while enabling rotation of server certificates (e.g., X.509 certificates). The systems described herein involve updating a client list of server certificates (e.g., a certificate thumbprint) without reconfiguring or re-installing a client and/or server application, starting a new session (e.g., a hypertext transfer protocol secure (HTTPS) session), or deploying new code. The systems described herein may passively or actively update a client list of certificates to enable a client to security verify an identity of a server instance in a non-invasive way that boosts security from man-in-the-middle types of attacks.Type: ApplicationFiled: January 7, 2020Publication date: July 8, 2021Inventors: Jeromy Scott STATIA, Chunsheng YANG, Priyanka Vilas DEO, Elizabeth Anne PHIPPEN, Bradley Scott TURNER
-
Patent number: 10372484Abstract: Examples related to secure computing systems are disclosed. In one example, a method includes, at a local agent computing device, sending to a remote work scheduling computing device a work context of the local agent computing device, the work context describing a set of work that the local agent is configured to execute, and polling a remote work depository for work compatible with the work context. The method further includes receiving a response from the remote work depository identifying a job within the work context, the job being requested by a computing device other than the remote work scheduling computing device, and executing the job.Type: GrantFiled: June 27, 2016Date of Patent: August 6, 2019Assignee: MICROSOFT TECHNOLOGY LICENSING, LLCInventors: Jeromy Scott Statia, Brad Turner, George Ringer, Alexandr Tcherniakhovski
-
Publication number: 20170371702Abstract: Examples related to secure computing systems are disclosed. In one example, a method includes, at a local agent computing device, sending to a remote work scheduling computing device a work context of the local agent computing device, the work context describing a set of work that the local agent is configured to execute, and polling a remote work depository for work compatible with the work context. The method further includes receiving a response from the remote work depository identifying a job within the work context, the job being requested by a computing device other than the remote work scheduling computing device, and executing the job.Type: ApplicationFiled: June 27, 2016Publication date: December 28, 2017Applicant: Microsoft Technology Licensing, LLCInventors: Jeromy Scott Statia, Brad Turner, George Ringer, Alexandr Tcherniakhovski
-
Publication number: 20170359348Abstract: A system discloses providing secure remote desktop session host experience to a user for a selected application while controlling the user's access to non-core functionalities of the selected application. An implementation of the system disclosed herein identifies a non-core functionality of an application running on a server, flags the executable files, shared object library files, and the registration keys necessary for the non-core functionality of the application, and disables the application's access to the identified executable files, the identified shared object library files, and the identified registration keys.Type: ApplicationFiled: June 9, 2016Publication date: December 14, 2017Inventors: George Ringer, Jeromy Scott Statia, Dayne Allen Thompson