IP Library Granted Patent US 12,651,094
Granted Patent B2
US 12,651,094 · App. 18/438,109 · Granted Jun 9, 2026

Seamless and secure cloud to computer pointer relay

Inventors: Assaf Bar-Ness (Rehovot, IL); Netanel Hadad (Lod, IL); Shoham Dekel (Tel Aviv, IL)
Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
G06F21/83G06F21/602
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,651,094
App. No.
18/438,109
Granted
Jun 9, 2026
Kind
B2
Abstract

A seamless and secure cloud to PC pointer relay allows a pointer/cursor to be moved between secure and unsecure windows while being displayed with smooth transitions and while transitioning between secure and unsecure data handling for pointer information. A secure input unit encrypts pointing device operations in the secure window. A user (host) computing device performs location calculations on encrypted data, which conceals pointing device operations in the secure window from the host operating system. The secure unit decrypts the encrypted data returned by the host operating system to determine the calculated pointer location information. The secure unit relays the calculated pointer operation information to the source of the secure window (e.g., remote cloud server) to process user interaction with the secure window while keeping the host operating system unaware of user activity in the secure window (e.g., other than position, if the host renders the pointer).

Claims (50)

1 . A computing device comprising:

a central processing unit (CPU) configured to execute an operating system (OS);

a graphics unit configured to generate a combined image comprising a secure window generated by a secure processor and an unsecure window generated by the CPU;

a display unit configured to display the combined image;

an input unit configured to:

receive pointing device information generated by pointing device operation in the secure window and the unsecure window displayed by the display unit;

send pointing device reports to the OS for pointing device operation in the unsecure window to render the pointer in the unsecure window;

send encrypted pointing device reports to the OS for the pointing device operation in the secure window to conceal the pointing device operation in the secure window from the OS, the OS configured to perform calculations on the encrypted pointing device reports to generate encrypted calculated pointing device information in a manner such that the OS is unaware of user activity in the secure window;

receive the encrypted calculated pointing device information from the OS responsive to the encrypted pointing device reports;

decrypt the encrypted calculated pointing device information to determine calculated pointing device information for pointing device operations in the secure window; and

send the calculated pointing device information to at least one of the OS or to the secure processor to render the pointer in the secure window.

2 . The computing device of claim 1 , wherein the input unit is configured to send the calculated pointing device operation information to the secure processor to perform the rendering of the pointer in the secure window.

3 . The computing device of claim 1 , wherein the input unit is configured to send the calculated pointing device operation information to the OS to perform the rendering of the pointer in the secure window.

4 . The computing device of claim 1 , wherein the pointing device operation information in the secure window comprises pointer location coordinates, selection events, and scroll events.

5 . The computing device of claim 1 , wherein the input unit is further configured to:

encrypt information in the encrypted pointing device reports using homomorphic encryption; and

decrypt the encrypted calculated pointing device operation information using homomorphic decryption.

6 . The computing device of claim 1 , wherein the input unit is further configured to:

receive indications from the OS responsive to the pointing device entering and exiting the secure window.

7 . The computing device of claim 1 , wherein the secure processor is in a remote computing device.

8 . The computing device of claim 7 , wherein the remote computing device comprises a virtual machine.

9 . A method, comprising:

receiving pointing device information generated by pointing device operation in a secure window and an unsecure window displayed by a display unit;

sending pointing device reports to an operating system (OS) for the pointing device operation in the unsecure window to render the pointer in the unsecure window;

sending encrypted pointing device reports to the OS for the pointing device operation in the secure window to conceal the pointing device operation in the secure window from the OS, the OS configured to perform calculations on the encrypted pointing device reports to generate encrypted calculated pointing device information in a manner such that the OS is unaware of user activity in the secure window;

receiving the encrypted calculated pointing device information from the OS responsive to the encrypted pointing device reports;

decrypting the encrypted calculated pointing device information to determine calculated pointing device information for pointing device operations in the secure window; and

sending the calculated pointing device information to at least one of the OS or to a computing source of the secure window to render the pointer in the secure window.

10 . The method of claim 9 , wherein the sending of the calculated pointing device operation information comprises sending the calculated pointing device operation information in the secure window to the computing source of the secure window to perform the rendering of the pointer in the secure window.

11 . The method of claim 9 , wherein the sending of the calculated pointing device operation information comprises sending the calculated pointing device operation information in the secure window to the OS to perform the rendering of the pointer in the secure window.

12 . The method of claim 9 , wherein the pointing device operation information in the secure window comprises pointer location coordinates, selection events, and scroll events.

13 . The method of claim 9 , further comprising:

encrypting information in the encrypted pointing device reports using homomorphic encryption; and

decrypting the encrypted calculated pointing device operation information using homomorphic decryption.

14 . The method of claim 9 , further comprising:

receiving indications from the OS responsive to the pointing device entering and exiting the secure window.

15 . A computer-readable storage device having instructions recorded thereon that, when executed by a processor, implements a method comprising:

receiving pointing device information generated by pointing device operation in a secure window and an unsecure window displayed by a display unit;

sending pointing device reports to an operating system (OS) for the pointing device operation in the unsecure window to render the pointer in the unsecure window;

sending encrypted pointing device reports to the OS for the pointing device operation in the secure window to conceal the pointing device operation in the secure window from the OS, the OS configured to perform calculations on the encrypted pointing device reports to generate encrypted calculated pointing device information in a manner such that the OS is unaware of user activity in the secure window;

receiving the encrypted calculated pointing device information from the OS responsive to the encrypted pointing device reports;

decrypting the encrypted calculated pointing device information to determine calculated pointing device information for pointing device operations in the secure window; and

sending the calculated pointing device information to at least one of the OS or to a computing source of the secure window to render the pointer in the secure window.

16 . The computer-readable storage device of claim 15 , wherein the sending of the calculated pointing device operation information comprises sending the calculated pointing device operation information in the secure window to the computing source of the secure window to perform the rendering of the pointer in the secure window.

17 . The computer-readable storage device of claim 15 , wherein the sending of the calculated pointing device operation information comprises sending the calculated pointing device operation information in the secure window to the computing source of the secure window to perform the rendering of the pointer in the secure window.

18 . The computer-readable storage device of claim 15 , wherein the sending of the calculated pointing device operation information comprises sending the calculated pointing device operation information in the secure window to the OS to perform the rendering of the pointer in the secure window.

19 . The computer-readable storage device of claim 15 , wherein the pointing device operation information in the secure window comprises pointer location coordinates, selection events, and scroll events.

20 . The computer-readable storage device of claim 15 , the method further comprising:

encrypting information in the encrypted pointing device reports using homomorphic encryption; and

decrypting the encrypted calculated pointing device operation information using homomorphic decryption.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 21, 2024
From: BAR-NESS, ASSAF; HADAD, NETANEL; DEKEL, SHOHAM
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 066858/0237 →
Continuity (2)
Provisional Application 63612448 · Dec 20, 2023
Related Publication 20250209216A1 · Jun 26, 2025
References Cited (19)
US 11182073B2 · Ragan, Jr. · 2021 [cited by examiner]
US 11405367B1 · Kuo · 2022 [cited by examiner]
US 20050193143A1 · Meyers · 2005 [cited by applicant]
US 20090282359A1 · Saul · 2009 [cited by applicant]
US 20100269039A1 · Pahlavan et al. · 2010 [cited by applicant]
US 20110078532A1 · Vonog et al. · 2011 [cited by applicant]
US 20120011280A1 · Gilboa · 2012 [cited by applicant]
US 20120011445A1 · Gilboa · 2012 [cited by applicant]
US 20120265981A1 · Moon et al. · 2012 [cited by applicant]
US 20130106698A1 · Zhang · 2013 [cited by applicant]
US 20140071833A1 · Agrawal · 2014 [cited by applicant]
US 20150220242A1 · Guest · 2015 [cited by applicant]
US 20180159896A1 · Soman · 2018 [cited by examiner]
US 20220229908A1 · Peisert · 2022 [cited by examiner]
US 20220414272A1 · Karri · 2022 [cited by examiner]
EP 3010199A1 · 2016 [cited by examiner]
WO WO2020243362A1 · 2020 [cited by examiner]
WO 2022166927A1 · 2022 [cited by applicant]
Navarrete, Jean, “DRM for WebRTC: End-to-end security for video streaming”, Retrieved From: https://castlabs.com/news/webrtc-drm-end-to-end-security/, Mar. 14, 2023, 13 Pages. [cited by applicant]