US2019354709A1PendingUtilityA1

Enforcement of same origin policy for sensitive data

Individually held — no corporate assignee on recordPriority: Jun 22, 2009Filed: May 13, 2019Published: Nov 21, 2019
Est. expiryJun 22, 2029(~2.9 yrs left)· nominal 20-yr term from priority
H04L 67/02H04L 63/166G06F 21/31H04L 63/0823H04L 63/08G06F 21/6218
57
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Methods, systems, and apparatus relating to enforcement of same origin policy of sensitive data are described. In an embodiment, a security agent may help ensure release of sensitive data is only triggered by authorized sources. The security agent may help ensure sensitive data is only released to authorized destinations. A security agent may translate or obfuscate sensitive data. Sensitive data may include HTTP cookies, session data, authentication information, authorization information, personal information, user credentials, and/or other data sensitive in nature. Sensitive data destinations and/or sensitive data origins may be identified. Identification may be performed using secure means (such as for example a SSL/TLS handshake). Other embodiments are also disclosed and claimed.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method to protect sensitive data comprising:
 examining a Hypertext Transfer Protocol (HTTP) message received over a communication channel secured using a digital certificate;   determining a sensitive data;   determining an origin identifier identifying the digital certificate used to secure the communication channel; and   adding the determined origin identifier to a list of authorized origin identifiers for the sensitive data.   
     
     
         2 . The method of  claim 1 , wherein the sensitive data comprises one or more of: Hypertext Transfer Protocol (HTTP) Cookie, session cookie, session data, authentication information, authorization information, user credentials, personal data, and data sensitive in nature. 
     
     
         3 . The method of  claim 1 , wherein Transport Layer Security (TLS) is used to secure the communications channel, and wherein determining the sensitive data comprises extracting a value from the Hypertext Transfer Protocol (HTTP) message. 
     
     
         4 . The method of  claim 2 , wherein the authorized origin identifiers for the sensitive data comprises authorized destinations for the sensitive data. 
     
     
         5 . The method of  claim 1 , wherein the authorized origin identifiers for the sensitive data comprises authorized triggers for the sensitive data. 
     
     
         6 . The method of  claim 4 , further comprising: ensuring release of the sensitive data is only transmitted to an authorized destination. 
     
     
         7 . The method of  claim 5 , further comprising: ensuring release of the sensitive data is only triggered by an authorized trigger. 
     
     
         8 . A system, comprising:
 a computing device coupled to a network, including:   a processor; and   a non-transitory computer readable medium comprising instructions executable for:
 examining a Hypertext Transfer Protocol (HTTP) message received over a communication channel, wherein the communication channel is secured with a digital certificate; 
 determining a sensitive data; 
 determining an origin identifier identifying the digital certificate used to secure the communication channel; and 
 adding the determined origin identifier to a list comprising authorized origin identifiers for the sensitive data. 
   
     
     
         9 . The system of  claim 8 , wherein the sensitive data comprises one or more of: Hypertext Transfer Protocol (HTTP) Cookie, session cookie, session data, authentication information, authorization information, user credentials, personal data, and data sensitive in nature. 
     
     
         10 . The system of  claim 9 , wherein the communications channel secured by a digital certificate comprises Transport Layer Security (TLS), and wherein determining the sensitive data comprises extracting an HTTP header value from the Hypertext Transfer Protocol (HTTP) message. 
     
     
         11 . The system of  claim 8 , wherein the authorized origin identifiers for the sensitive data comprises authorized destinations for the sensitive data. 
     
     
         12 . The system of  claim 9 , wherein the authorized origin identifiers for the sensitive data comprises authorized triggers for the sensitive data. 
     
     
         13 . The system of  claim 11 , further comprising: ensuring release of the sensitive data is transmitted only to an authorized origin identifier. 
     
     
         14 . The system of  claim 12 , further comprising: ensuring release of the sensitive data is triggered only by an authorized origin identifier. 
     
     
         15 . An apparatus to protect sensitive data, the apparatus comprising:
 a computing device coupled to a network, including:   a processor; and   a security agent for:
 examining a Hypertext Transfer Protocol (HTTP) message received over a communication channel secured with a digital certificate; 
 determining a sensitive data; 
 determining an origin identifier identifying the digital certificate used to secure the communication channel; and 
 adding the determined origin identifier to a list of authorized origin identifiers for the sensitive data. 
   
     
     
         16 . The apparatus of  claim 15 , wherein the sensitive data comprises one or more of: Hypertext Transfer Protocol (HTTP) Cookie, session cookie, session data, authentication information, authorization information, user credentials, personal data, and data sensitive in nature. 
     
     
         17 . The apparatus of  claim 15 , wherein the Transport Layer Security (TLS) protocol is used to secure the communications channel, and wherein determining the sensitive data comprises extracting a value from the Hypertext Transfer Protocol (HTTP) message. 
     
     
         18 . The apparatus of  claim 16 , wherein the authorized origin identifiers for the sensitive data comprises authorized destinations for the sensitive data. 
     
     
         19 . The apparatus of  claim 15 , wherein the authorized origin identifiers comprises authorized triggers for the sensitive data. 
     
     
         20 . The apparatus of  claim 18 , the security agent further comprises: ensuring release of the sensitive data is only transmitted to an authorized destination. 
     
     
         21 . The apparatus of  claim 19 , the security agent further comprises: ensuring release of the sensitive data is only triggered by an authorized trigger.

Join the waitlist — get patent alerts

Track US2019354709A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.