Secure local web application data manager
Abstract
Apparatus, systems and methods may provide a browser interface to detect an attempt by web content to manipulate data in a local data store. In addition, the data may be classified into a category if the data is remotely accessible. Additionally, a security policy may be applied to the data based on the category. In one example, a separator may separate the data from other data based on the category, the data may be encrypted/decrypted based on the category, and/or context information and user input may be determined to apply the security policy further based on the context information and the user input.
Claims
exact text as granted — not AI-modifiedWe claim:
1 . An apparatus comprising:
a browser interface to detect an attempt to access stored data in a local data store by web content received at a browser of the apparatus; and a separator to:
separate remotely accessible web data from other web data stored in the local data store; and
separate the remotely accessible web data into a plurality of storage regions each associated with a respective category that labels the remotely accessible web data as being a particular type of remotely accessible data.
2 . The apparatus of claim 1 , wherein the remotely accessible web data is to be stored in a storage region associated with a privacy category when the remotely accessible web data is to be labeled as being privacy data, wherein the remotely accessible web data is to be stored in a storage region associated with a cryptographic category when the remotely accessible web data is to be labeled as being cryptographic data, and wherein the remotely accessible web data is to be stored in a storage region associated with an application specific category when the remotely accessible web data is to be labeled as being application specific data.
3 . The apparatus of claim 1 , wherein the remotely accessible web data is to be labeled as being privacy data when the remotely accessible web data is to include remotely accessible browsing history data or personal data, cryptographic data when the remotely accessible web data is to include username information, password information, or challenge information, and application specific data when the remotely accessible web data is to include webmail data, retail data, or auction data.
4 . The apparatus of claim 1 , further including policy logic to apply a security policy to permit access or to deny access to the remotely accessible web data based on the category.
5 . The apparatus of claim 1 , further including a context sensor interface to determine context information for the apparatus, wherein the context information is to include a geolocation of the apparatus when the attempt is made and a use of the apparatus when the attempt is made, and wherein a security policy is to be applied to permit access or to deny access to the remotely accessible web data based on the context information.
6 . The apparatus of claim 1 , wherein the browser interface is to receive user input including a user profile, and wherein a security policy is to be applied to permit access or to deny access to the remotely accessible web data based on the user input.
7 . The apparatus of claim 1 , further including a hardware security element to perform a hardware-assisted encryption process on the remotely accessible web data.
8 . The apparatus of claim 1 , wherein the browser interface is to monitor a Hypertext Markup Language 5 (HTML5) web application to detect the attempt in one or more of an HTML5 Web Storage of the apparatus or an HTML5 Application Cache of the apparatus.
9 . A method comprising:
detecting an attempt to access stored data in a local data store by web content received at a browser of an apparatus; separating remotely accessible web data from other web data stored in the local data store; and separating the remotely accessible web data into a plurality of storage regions each associated with a respective category that labels the remotely accessible web data as being a particular type of remotely accessible data.
10 . The method of claim 9 , wherein the remotely accessible web data is stored in a storage region associated with a privacy category when the remotely accessible web data is labeled as being privacy data, wherein the remotely accessible web data is stored in a storage region associated with a cryptographic category when the remotely accessible web data is labeled as being cryptographic data, and wherein the remotely accessible web data is stored in a storage region associated with an application specific category when the remotely accessible web data is labeled as being application specific data.
11 . The method of claim 9 , wherein the remotely accessible web data is labeled as being privacy data when the remotely accessible web data includes remotely accessible browsing history data or personal data, cryptographic data when the remotely accessible web data includes username information, password information, or challenge information, and application specific data when the remotely accessible web data includes webmail data, retail data, or auction data.
12 . The method of claim 9 , further including applying a security policy to permit access or to deny access to the remotely accessible web data based on the category.
13 . The method of claim 9 , further including:
determining context information for the apparatus, wherein the context information includes a geolocation of the apparatus when the attempt is made and a use of the apparatus when the attempt is made, and wherein a security policy is applied to permit access or to deny access to the remotely accessible web data based on the context information; receiving user input including a user profile, wherein the security policy is applied to permit access or to deny access to the remotely accessible web data based on the user input; and generating a report that identifies the attempt, the remotely accessible web data, the category, and the security policy.
14 . The method of claim 9 , further including performing a hardware-assisted encryption process on the remotely accessible web data.
15 . At least one non-transitory computer readable storage medium comprising a set of instructions which, when executed by a processor, cause a device to:
detect an attempt to access stored data in a local data store by web content received at a browser of an apparatus; separate remotely accessible web data from other web data stored in the local data store; and separate the remotely accessible web data into a plurality of storage regions each associated with a respective category that labels the remotely accessible web data as being a particular type of remotely accessible data.
16 . The at least one computer readable storage medium of claim 15 , wherein the remotely accessible web data is to be stored in a storage region associated with a privacy category when the remotely accessible web data is to be labeled as being privacy data, wherein the remotely accessible web data is to be stored in a storage region associated with a cryptographic category when the remotely accessible web data is to be labeled as being cryptographic data, and wherein the remotely accessible web data is to be stored in a storage region associated with an application specific category when the remotely accessible web data is to be labeled as being application specific data.
17 . The at least one computer readable storage medium of claim 15 , wherein the remotely accessible web data is to be labeled as being privacy data when the remotely accessible web data is to include remotely accessible browsing history data or personal data, cryptographic data when the remotely accessible web data is to include username information, password information, or challenge information, and application specific data when the remotely accessible web data is to include webmail data, retail data, or auction data.
18 . The at least one computer readable storage medium of claim 15 , wherein the instructions, when executed, cause the device to apply a security policy to permit access or to deny access to the remotely accessible web data based on the category.
19 . The at least one computer readable storage medium of claim 15 , wherein the instructions, when executed, cause the device to:
determine context information for the apparatus, wherein the context information is to include a geolocation of the apparatus when the attempt is made and a use of the apparatus when the attempt is made, and wherein a security policy is to be applied to permit access or to deny access to the remotely accessible web data based on the context information; receive user input including a user profile, wherein the security policy is to be applied to permit access or to deny access to the remotely accessible web data based on the user input; and generate a report that is to identify the attempt, the remotely accessible web data, the category, and the security policy.
20 . The at least one computer readable storage medium of claim 15 , wherein the instructions, when executed, cause the device to perform a hardware-assisted encryption process on the remotely accessible web data.Join the waitlist — get patent alerts
Track US2016359921A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.