Patents by Inventor Orr SROUR
Orr SROUR has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 12596822Abstract: A memory where video content is stored for access by processing components in a display pipeline is divided into different categories or groupings, each different category or grouping corresponding to a different security level. Access, by the processing components in the display pipeline, to the video content stored in the different categories or groupings is restricted in different ways so that access to video content stored in the highest security categories or groupings is more restricted and more secure than access to the video content stored in a less secure categories or groupings. Video content is received and a security level corresponding to video content is identified. The video content is written into a memory category or grouping, of the plurality of different categories or groupings corresponding to a plurality of different security levels, based upon the security level corresponding to the video content.Type: GrantFiled: May 25, 2023Date of Patent: April 7, 2026Assignee: MICROSOFT TECHNOLOGY LICENSING, LLCInventors: Ori Laslo, Orr Srour, Matthew Morris, Steve M. Pronovost, Glenn F. Evans, Vadim Makhervaks
-
Publication number: 20250350584Abstract: The technology described herein builds an encrypted computational graph for deployment to a client device. The encrypted computational graph includes a machine-learning model's components (e.g., weights and biases) with instructions to perform various operations to allow the particular machine learning model to make an inference. A runtime environment operating on the client device may help execute the encrypted computational graph. The runtime environment may be able to facilitate execution without being able to decrypt the encrypted machine model data. Instead, the model data is only descripted within trusted execution environments of processors at the hardware level. The encrypted computational graph may be built on a client-by-client basis to create a unique computational graph for a specific client device. At the very least, the encryption may be specific to a trusted execution environment of a specific device.Type: ApplicationFiled: May 10, 2024Publication date: November 13, 2025Inventors: Netanel HADAD, Orr SROUR, Nadav Shlomo BEN-AMRAM
-
Publication number: 20250208818Abstract: A method for securely providing a remote desktop session includes receiving, at a user device, an encrypted video stream that includes graphics content of the remote desktop session and that is characterized by a frame rate that is variable. The method further provides for reducing variability in the frame rate of the encrypted video stream by duplicating select encrypted frames of the video stream and inserting the duplicated encrypted frames into the video stream. The method additionally provides for delivering the video stream to a local application configured to generate control signals that cause a graphics processing unit (GPU) of the user machine to render the video stream to a display of the user machine.Type: ApplicationFiled: December 20, 2023Publication date: June 26, 2025Inventors: Assaf BAR NESS, Idan WOLF, Orr SROUR
-
Publication number: 20250193236Abstract: Phishing protection utilizes a security identifier displayed in association with secure content. The identifier may be displayed separately for comparison. A security identifier may be generated by a user interface, local source, or remote source. Users may visually and/or physically confirm identifiers. An identifier may be a character string or QR code. Phishing attempts may be monitored, detected, and alerted during and outside a secure session. A device may modify images from a first computing device to a display monitor. A device interface may receive a first image from the first computing device. A detector may monitor the first image for counterfeit information. An alert generator may generate a security alert for counterfeit information. A combiner may combine with the first image, in response to a secure session, a secure image associated with a secure identifier and, in response to the detector detecting counterfeit secure information, the security alert.Type: ApplicationFiled: February 28, 2024Publication date: June 12, 2025Inventors: Netanel HADAD, Orr SROUR, Assaf BAR - NESS
-
Patent number: 12260004Abstract: Methods, systems, apparatuses, and computer program products are provided herein for rendering secured content. For instance, a computing device may be utilized to view content that is to be displayed via a display device coupled thereto. However, rather than rendering the content, the computing device generates and/or provides a graphical representation of the content to a rendering device coupled between the computing device and the display device. The rendering device analyzes the graphical representation to determine characteristics of the graphical representation, characteristics of a display region of an application window in which the content is to be rendered, and a network address at which the actual content is located. The rendering device retrieves the content using the network address and renders the retrieved content over the display region of the application window in accordance with the characteristics determined for the graphical representation and the display region of the application window.Type: GrantFiled: February 15, 2022Date of Patent: March 25, 2025Assignee: MICROSOFT TECHNOLOGY LICENSING, LLCInventors: Orr Srour, Vadim Makhervaks
-
Patent number: 12204746Abstract: Systems, methods, and instrumentalities are described herein related to a secured stylus. A secure connection is established between a digitizer processor in a computing device and a remote server providing virtual desktop infrastructure (VDI). A digitizer interposer implemented in the computing device, the server, and/or between them receives raw or encrypted digitizer input that bypasses the operating system (OS) and processor of the computing device. Digitizer signal processing, normally performed by the OS, is performed on one or more servers. An edge server provides haptic feedback to a stylus and/or generates display of temporary digital ink as created while a cloud server completes digital ink processing and generates video for display by the computing device. A secure connection between a graphics processing unit (GPU) and the server protects secure connection video by encryption bypassing the OS and processor of the user computing device.Type: GrantFiled: November 22, 2023Date of Patent: January 21, 2025Assignee: MICROSOFT TECHNOLOGY LICENSING, LLCInventors: Shoham Dekel, Assaf Bar-Ness, Orr Srour
-
Publication number: 20240394388Abstract: A memory where video content is stored for access by processing components in a display pipeline is divided into different categories or groupings, each different category or grouping corresponding to a different security level. Access, by the processing components in the display pipeline, to the video content stored in the different categories or groupings is restricted in different ways so that access to video content stored in the highest security categories or groupings is more restricted and more secure than access to the video content stored in a less secure categories or groupings. Video content is received and a security level corresponding to video content is identified. The video content is written into a memory category or grouping, of the plurality of different categories or groupings corresponding to a plurality of different security levels, based upon the security level corresponding to the video content.Type: ApplicationFiled: May 25, 2023Publication date: November 28, 2024Inventors: Ori LASLO, Orr SROUR, Matthew MORRIS, Steve M. PRONOVOST, Glenn F. EVANS, Vadim MAKHERVAKS
-
Publication number: 20240319866Abstract: Systems, methods, and instrumentalities are described herein related to a secured stylus. A secure connection is established between a digitizer processor in a computing device and a remote server providing virtual desktop infrastructure (VDI). A digitizer interposer implemented in the computing device, the server, and/or between them receives raw or encrypted digitizer input that bypasses the operating system (OS) and processor of the computing device. Digitizer signal processing, normally performed by the OS, is performed on one or more servers. An edge server provides haptic feedback to a stylus and/or generates display of temporary digital ink as created while a cloud server completes digital ink processing and generates video for display by the computing device. A secure connection between a graphics processing unit (GPU) and the server protects secure connection video by encryption bypassing the OS and processor of the user computing device.Type: ApplicationFiled: November 22, 2023Publication date: September 26, 2024Inventors: Shoham DEKEL, Assaf BAR-NESS, Orr SROUR
-
Publication number: 20240265071Abstract: Methods and systems are described which facilitate protecting a virtual desktop infrastructure (VDI) session. A first communication channel is established between a first cryptographic element and a VDI service. The first cryptographic element decrypts a video stream from the VDI service and overlays the decrypted video stream on a user's display. A second communication channel is established between a second cryptographic element and the VDI service. The second cryptographic element encrypts input received at a user's input device and sends the encrypted input to the cloud VDI service.Type: ApplicationFiled: April 3, 2023Publication date: August 8, 2024Inventors: Orr SROUR, Ori LASLO, Ashish GUPTA, Vadim MAKHERVAKS, Andrew Lee JENKS, Samuel John WENKER
-
Publication number: 20240265072Abstract: Methods and systems are described which facilitate protecting a virtual desktop infrastructure (VDI) session. A first communication channel is established between a DRM component and a VDI service. The DRM component decrypts a video stream from the VDI service and overlays the decrypted video stream on a user's display. A second communication channel is established between an inputs protection component and the VDI service. The inputs protection component encrypts input received at a user's input device and sends the encrypted input to the cloud VDI service.Type: ApplicationFiled: April 3, 2023Publication date: August 8, 2024Inventors: Orr SROUR, Ori LASLO, Ashish GUPTA, Vadim MAKHERVAKS, Andrew Lee JENKS, Samuel John WENKER
-
Patent number: 12047363Abstract: A method enabling recovery of a terminated client-to-cloud processing sessions includes writing at least some data of cloud-based processing session between a cloud based server and a client device to the client device. Responsive to satisfaction of a session termination condition, the stored data is encrypted such that it can be recovered using suitable decryption techniques when the client-to-cloud-connection is subsequently re-established.Type: GrantFiled: May 19, 2021Date of Patent: July 23, 2024Assignee: Microsoft Technology Licensing, LLCInventors: Yotam Livny, Orr Srour, Amir Zyskind
-
Patent number: 11868608Abstract: Systems, methods, and instrumentalities are described herein related to a secured stylus. A secure connection is established between a digitizer processor in a computing device and a remote server providing virtual desktop infrastructure (VDI). A digitizer interposer implemented in the computing device, the server, and/or between them receives raw or encrypted digitizer input that bypasses the operating system (OS) and processor of the computing device. Digitizer signal processing, normally performed by the OS, is performed on one or more servers. An edge server provides haptic feedback to a stylus and/or generates display of temporary digital ink as created while a cloud server completes digital ink processing and generates video for display by the computing device. A secure connection between a graphics processing unit (GPU) and the server protects secure connection video by encryption bypassing the OS and processor of the user computing device.Type: GrantFiled: March 20, 2023Date of Patent: January 9, 2024Assignee: MICROSOFT TECHNOLOGY LICENSING, LLCInventors: Shoham Dekel, Assaf Bar-Ness, Orr Srour
-
Publication number: 20230259656Abstract: Methods, systems, apparatuses, and computer program products are provided herein for rendering secured content. For instance, a computing device may be utilized to view content that is to be displayed via a display device coupled thereto. However, rather than rendering the content, the computing device generates and/or provides a graphical representation of the content to a rendering device coupled between the computing device and the display device. The rendering device analyzes the graphical representation to determine characteristics of the graphical representation, characteristics of a display region of an application window in which the content is to be rendered, and a network address at which the actual content is located. The rendering device retrieves the content using the network address and renders the retrieved content over the display region of the application window in accordance with the characteristics determined for the graphical representation and the display region of the application window.Type: ApplicationFiled: February 15, 2022Publication date: August 17, 2023Inventors: Orr SROUR, Vadim MAKHERVAKS
-
Publication number: 20220377060Abstract: A method enabling recovery of a terminated client-to-cloud processing sessions includes writing at least some data of cloud-based processing session between a cloud based server and a client device to the client device. Responsive to satisfaction of a session termination condition, the stored data is encrypted such that it can be recovered using suitable decryption techniques when the client-to-cloud-connection is subsequently re-established.Type: ApplicationFiled: May 19, 2021Publication date: November 24, 2022Inventors: Yotam LIVNY, Orr SROUR, Amir ZYSKIND
-
Publication number: 20220166762Abstract: Embodiments described herein are directed to an integrated circuit (IC) for obtaining elevated credentials and performing actions with respect to a network-based resource in accordance with the elevated credentials. For instance, a user may request his privileges with respect to the resource to be elevated. Responsive to submitting the request, the client device's main CPU may send a request to a specialized IC included in the client device. The specialized IC performs various forms of validation responsive to the request. If validation is successful, the specialized IC sends a request for elevated privileges to a network-based service, which determines whether the user is authorized to do so. Upon a successful determination, the service provides a response granting the elevated credentials. The specialized integrated circuit is then given access to a private key that the IC utilizes to digitally sign an action request to perform the desired action.Type: ApplicationFiled: November 25, 2020Publication date: May 26, 2022Inventors: Orr SROUR, Yotam LIVNY
-
Patent number: 10542103Abstract: The disclosure is related to context driven interactions between a host computing device having a digitized surface and a client device. During a touch interaction, the host computing device detects a touch on the digitized surface and receives a client identifier from the client device. In an implementation, the host computing device may respond to a touch interaction in a context driven manner. The host computing device may determine an event based on a context of the touch interaction. The context may include, for example, the location (e.g., coordinates) of the touch, the client identifier received during the touch interaction, and an active application on the host computing device during the touch interaction. Based on the determined event, the host computing device may request specific information regarding the client device. The specific information may be selected by the host computing device based on the determined event.Type: GrantFiled: September 12, 2016Date of Patent: January 21, 2020Assignee: MICROSOFT TECHNOLOGY LICENSING, LLCInventors: Orr Srour, Amir Zyskind, Uri Ron
-
Publication number: 20190302903Abstract: Examples are disclosed herein that relate to a six degree-of-freedom (DOF) input device. An example provides an input device comprising a body, a sensor system configured to sense motion of the input device with six DOF, a communication interface and a controller. The controller is configured to transmit output based on sensor data from the sensor system for use in controlling an application in a first mode in which each of the six degrees-of-freedom is used as input, the application being controlled in the first mode in response to detecting a first condition, and transmit output based on sensor data from the sensor system for use in controlling the application in a second mode in which one or more of the six degrees-of-freedom is not used as input, the application being controlled in the second mode in response to detecting a second condition.Type: ApplicationFiled: March 30, 2018Publication date: October 3, 2019Applicant: Microsoft Technology Licensing, LLCInventors: Charlene Mary ATLAS, Ishac BERTRAN, Benjamin Hunter BOESEL, Lorenz Henric JENTZ, Nikolai Michael FAALAND, Christian KLEIN, Xin Xian LIANG, Orr SROUR
-
Publication number: 20180077248Abstract: The disclosure is related to context driven interactions between a host computing device having a digitized surface and a client device. During a touch interaction, the host computing device detects a touch on the digitized surface and receives a client identifier from the client device. In an implementation, the host computing device may respond to a touch interaction in a context driven manner. The host computing device may determine an event based on a context of the touch interaction. The context may include, for example, the location (e.g., coordinates) of the touch, the client identifier received during the touch interaction, and an active application on the host computing device during the touch interaction. Based on the determined event, the host computing device may request specific information regarding the client device. The specific information may be selected by the host computing device based on the determined event.Type: ApplicationFiled: September 12, 2016Publication date: March 15, 2018Inventors: Orr SROUR, Amir Zyskind, Uri Ron