US2004006706A1PendingUtilityA1
Methods and systems for implementing a secure application execution environment using derived user accounts for internet content
Priority: Jun 6, 2002Filed: Jun 6, 2003Published: Jan 8, 2004
Est. expiryJun 6, 2022(expired)· nominal 20-yr term from priority
Inventors:Ulfar Erlingsson
H04L 63/1483G06F 21/53G06F 21/51
48
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Methods and systems are disclosed for implementing a secure application execution environment using Derived User Accounts (SAE DUA) for Internet content. Content is received and a determination is made if the received content is trusted or untrusted content. The content is accessed in a protected derived user account (DUA) such as a SAE DUA if the content is untrusted otherwise the content is accessed in a regular DUA if the content is trusted.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for providing secure content use comprising:
receiving content from a resource; determining if the received content is trusted or untrusted content; and taking a first action with respect to the received content, if the content is untrusted, or taking a second action with respect to the received content, if the content is trusted.
2 . The method of claim 1 , wherein the first action is accessing the received content in a derived user account (DUA) and the second action is accessing the received content in a regular DUA.
3 . The method of claim 1 , wherein determining further comprises:
determining if the received content is trusted or untrusted based on a partition of the resource.
4 . The method of claim 3 , wherein determining if the received content is trusted or untrusted further comprises:
identifying the resource based on a characteristic of the resource; and partitioning the resource as trusted or untrusted based on the identified characteristic.
5 . The method of claim 1 , wherein receiving content comprises:
intercepting one or more requests for the content; and wherein the first action is redirecting the one or more intercepted requests to a protected DUA, if the content is untrusted, or redirecting the one or more requests to a regular DUA, if the content is trusted.
6 . A computing system for providing secure content comprising:
at least one memory hosting a protected derived user account (DUA) and a regular DUA; and a processor configured to receive content from a resource, determine if the received content is trusted or untrusted content, and take a first action with respect to the received content, if the content is untrusted, or take a second action with respect to the received content, if the content is trusted.
7 . The computing system of claim 6 , wherein the first action is accessing the received content in a derived user account (DUA) and the second action is accessing the received content in a regular DUA.
8 . The computing system of claim 6 , wherein the processor is further configured to determine if the content is trusted or untrusted based on a partition of the resource.
9 . The computing system of claim 8 , wherein the processor is further configured to identify the resource based on a characteristic of the resource, and to partition the resource as trusted or untrusted based on the identified characteristic.
10 . The computing system of claim 6 , wherein the processor is further configured to intercept one or more requests for the content and redirect the one or more requests to the protected DUA, if the content is untrusted, or redirect the one or more requests to the regular DUA, if the content is trusted.
11 . A computer-readable medium containing instructions for controlling a computing system having a processor, to perform a method comprising:
receiving content from a resource; determining if the received content is trusted or untrusted content; and taking a first action with respect to the received content, if the content is untrusted, or taking a second action with respect to the received content, if the content is trusted.
12 . The computer-readable medium of claim 11 , wherein the first action is accessing the received content in a derived user account (DUA) and the second action is accessing the received content in a regular DUA.
13 . The computer-readable medium of claim 11 , wherein the instructions further control the computing system to perform a method comprising:
determining if the received content is trusted or untrusted based on a partition of the resource.
14 . The computer-readable medium of claim 13 , wherein the instructions further control the computing system to perform a method comprising:
identifying the resource based on a characteristic of the resource; and partitioning the resource as trusted or untrusted based on the identified characteristic.
15 . The computer-readable medium of claim 11 , wherein the instructions further control the computing system to perform a method comprising:
intercepting one or more requests for the content; and wherein the first action is redirecting the one or more intercepted requests to a protected DUA, if the content is untrusted, or redirecting the one or more requests to a regular DUA, if the content is trusted.Join the waitlist — get patent alerts
Track US2004006706A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.