Patents by Inventor Or MORAN

Or MORAN has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 12659307
    Abstract: Some embodiments provide or utilize technology which increases the security of network authentication operations, such as Kerberos operations, New Technology LAN Manager operations, or other network authentication operations which utilize security tickets or security tokens or both. In some embodiments, a user machine (also known as a client machine) receives an authentication data structure (ADS) which includes one or more security tickets or security tokens or both. Embodiments constrain the ADS according to at least one security requirement, such as a volatile-memory-only constraint, a secured-memory-only constraint, or a multilayer encryption constraint. Embodiments also transmit the ADS from the machine as a part of performing the network authentication service. Some embodiments inhibit virtual memory, or memory dumping, or both. Some embodiments bind the ADS to the user machine, and some embodiments limit ADS usage counts.
    Type: Grant
    Filed: June 28, 2024
    Date of Patent: June 16, 2026
    Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
    Inventors: Sinead O'Donovan, Avraham Carmon, Ashish Jain, Shahzad Ahmed Khalid, Mordhai Gendelman, Or Moran, Navyatha Beesetti
  • Publication number: 20260006018
    Abstract: Some embodiments provide or utilize technology which increases the security of network authentication operations, such as Kerberos operations, New Technology LAN Manager operations, or other network authentication operations which utilize security tickets or security tokens or both. In some embodiments, a user machine (also known as a client machine) receives an authentication data structure (ADS) which includes one or more security tickets or security tokens or both. Embodiments constrain the ADS according to at least one security requirement, such as a volatile-memory-only constraint, a secured-memory-only constraint, or a multilayer encryption constraint. Embodiments also transmit the ADS from the machine as a part of performing the network authentication service. Some embodiments inhibit virtual memory, or memory dumping, or both. Some embodiments bind the ADS to the user machine, and some embodiments limit ADS usage counts.
    Type: Application
    Filed: June 28, 2024
    Publication date: January 1, 2026
    Inventors: Sinead O’DONOVAN, Avraham CARMON, Ashish JAIN, Shahzad Ahmed KHALID, Mordhai GENDELMAN, Or MORAN, Navyatha BEESETTI
  • Publication number: 20250233895
    Abstract: Techniques are described herein that are capable of using a requestor identity to enforce a security policy on a network connection that conforms to a shared-access communication protocol. A request to create the network connection to a network resource is received. The network connection is associated with the requestor identity, which identifies a requesting entity associated with the request, by associating the request with the requestor identity and further by associating the network connection with the request. A determination is made whether the requesting entity is authorized to access the network resource based at least in part on a permission that is indicated by the security policy. Based at least in part on the permission indicating that the requesting entity is authorized to access the network resource, the network connection to the network resource is created.
    Type: Application
    Filed: April 4, 2025
    Publication date: July 17, 2025
    Inventors: Or MORAN, Vladimir PERELMAN, Meital BEN DAVID
  • Patent number: 12363064
    Abstract: A computing system is configured to perform zero-trust domain name resolution. The computing system includes applications coupled to a zero-trust client. The zero-trust client is configured to receive requests for IP addresses corresponding to endpoint identifiers for internet connected endpoints. The zero-trust client includes a synthetic DNS service configured to identify synthetic IP addresses for the endpoint identifiers. The zero-trust client provides the synthetic IP addresses for the endpoint identifiers to the applications. The zero-trust client sends data traffic from the applications to a zero-trust service with the synthetic IP addresses where corresponding synthetic IP addresses are correlated to the endpoint identifiers at the zero-trust service.
    Type: Grant
    Filed: January 18, 2024
    Date of Patent: July 15, 2025
    Assignee: Microsoft Technology Licensing, LLC
    Inventors: Ashish Jain, Mordhai Gendelman, Or Moran, Omer Kattan, Yair Tor, Ronen Shmuel Goldsmith, Liraz Barak
  • Publication number: 20250168147
    Abstract: Filesystem driver software can receive a file access request indicating that an application process is requesting to access a target file in a filesystem, Network filter driver software can receive a connection establishment request indicating that the application process running on the processing apparatus is requesting to establish a connection over a network with a target endpoint. According to the present disclosure, one or both of: a) the filesystem driver software is configured to grant or deny the file access request in dependence on state information from the network filter driver software, and/or b) the network filter driver software is configured to grant or deny the connection establishment request in dependence on state information from the filesystem driver software.
    Type: Application
    Filed: December 11, 2024
    Publication date: May 22, 2025
    Inventors: Daniel LACHINO, Vladimir PERELMAN, Or MORAN
  • Patent number: 12294615
    Abstract: Techniques are described herein that are capable of using a requestor identity to enforce a security policy on a network connection that conforms to a shared-access communication protocol. A request to create the network connection to a network resource is received. The network connection is associated with the requestor identity, which identifies a requesting entity associated with the request, by associating the request with the requestor identity and further by associating the network connection with the request. A determination is made whether the requesting entity is authorized to access the network resource based at least in part on a permission that is indicated by the security policy. Based at least in part on the permission indicating that the requesting entity is authorized to access the network resource, the network connection to the network resource is created.
    Type: Grant
    Filed: June 22, 2022
    Date of Patent: May 6, 2025
    Assignee: Microsoft Technology Licensing, LLC
    Inventors: Or Moran, Vladimir Perelman, Meital Ben David
  • Publication number: 20240250929
    Abstract: A computing system is configured to perform zero-trust domain name resolution. The computing system includes applications coupled to a zero-trust client. The zero-trust client is configured to receive requests for IP addresses corresponding to endpoint identifiers for internet connected endpoints. The zero-trust client includes a synthetic DNS service configured to identify synthetic IP addresses for the endpoint identifiers. The zero-trust client provides the synthetic IP addresses for the endpoint identifiers to the applications. The zero-trust client sends data traffic from the applications to a zero-trust service with the synthetic IP addresses where corresponding synthetic IP addresses are correlated to the endpoint identifiers at the zero-trust service.
    Type: Application
    Filed: January 18, 2024
    Publication date: July 25, 2024
    Inventors: Ashish JAIN, Mordhai GENDELMAN, Or MORAN, Omer KATTAN, Yair TOR, Ronen Shmuel GOLDSMITH, Liraz BARAK
  • Patent number: 11943195
    Abstract: A computing system is configured to perform zero-trust domain name resolution. The computing system includes applications coupled to a zero-trust client. The zero-trust client is configured to receive requests for IP addresses corresponding to endpoint identifiers for internet connected endpoints. The zero-trust client includes a synthetic DNS service configured to identify synthetic IP addresses for the endpoint identifiers. The zero-trust client provides the synthetic IP addresses for the endpoint identifiers to the applications. The zero-trust client sends data traffic from the applications to a zero-trust service with the synthetic IP addresses and sends corresponding endpoint identifiers to the zero-trust service in a fashion that allows the synthetic IP addresses to be correlated to the endpoint identifiers at the zero-trust service.
    Type: Grant
    Filed: January 20, 2023
    Date of Patent: March 26, 2024
    Assignee: Microsoft Technology Licensing, LLC
    Inventors: Ashish Jain, Mordhai Gendelman, Or Moran, Omer Kattan, Yair Tor, Ronen Shmuel Goldsmith, Liraz Barak
  • Publication number: 20230421608
    Abstract: Techniques are described herein that are capable of using a requestor identity to enforce a security policy on a network connection that conforms to a shared-access communication protocol. A request to create the network connection to a network resource is received. The network connection is associated with the requestor identity, which identifies a requesting entity associated with the request, by associating the request with the requestor identity and further by associating the network connection with the request. A determination is made whether the requesting entity is authorized to access the network resource based at least in part on a permission that is indicated by the security policy. Based at least in part on the permission indicating that the requesting entity is authorized to access the network resource, the network connection to the network resource is created.
    Type: Application
    Filed: June 22, 2022
    Publication date: December 28, 2023
    Inventors: Or MORAN, Vladimir PERELMAN, Meital BEN DAVID