Enforcement of same origin policy for sensitive data
Abstract
Methods, systems, and apparatus relating to enforcement of same origin policy of sensitive data are described. In an embodiment, a security agent may help ensure release of sensitive data is only triggered by authorized sources. The security agent may help ensure sensitive data is only released to authorized destinations. A security agent may translate or obfuscate sensitive data. Sensitive data may include HTTP cookies, session data, authentication information, authorization information, personal information, user credentials, and/or other data sensitive in nature. Sensitive data destinations and/or sensitive data origins may be identified. Identification may be performed using secure means (such as for example a SSL/TLS handshake). Other embodiments are also disclosed and claimed.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method to protect sensitive data comprising:
examining a Hypertext Transfer Protocol (HTTP) message received over a communication channel secured using a digital certificate; determining a sensitive data; determining an origin identifier identifying the digital certificate used to secure the communication channel; and adding the determined origin identifier to a list of authorized origin identifiers for the sensitive data.
2 . The method of claim 1 , wherein the sensitive data comprises one or more of: Hypertext Transfer Protocol (HTTP) Cookie, session cookie, session data, authentication information, authorization information, user credentials, personal data, and data sensitive in nature.
3 . The method of claim 1 , wherein Transport Layer Security (TLS) is used to secure the communications channel, and wherein determining the sensitive data comprises extracting a value from the Hypertext Transfer Protocol (HTTP) message.
4 . The method of claim 2 , wherein the authorized origin identifiers for the sensitive data comprises authorized destinations for the sensitive data.
5 . The method of claim 1 , wherein the authorized origin identifiers for the sensitive data comprises authorized triggers for the sensitive data.
6 . The method of claim 4 , further comprising: ensuring release of the sensitive data is only transmitted to an authorized destination.
7 . The method of claim 5 , further comprising: ensuring release of the sensitive data is only triggered by an authorized trigger.
8 . A system, comprising:
a computing device coupled to a network, including: a processor; and a non-transitory computer readable medium comprising instructions executable for:
examining a Hypertext Transfer Protocol (HTTP) message received over a communication channel, wherein the communication channel is secured with a digital certificate;
determining a sensitive data;
determining an origin identifier identifying the digital certificate used to secure the communication channel; and
adding the determined origin identifier to a list comprising authorized origin identifiers for the sensitive data.
9 . The system of claim 8 , wherein the sensitive data comprises one or more of: Hypertext Transfer Protocol (HTTP) Cookie, session cookie, session data, authentication information, authorization information, user credentials, personal data, and data sensitive in nature.
10 . The system of claim 9 , wherein the communications channel secured by a digital certificate comprises Transport Layer Security (TLS), and wherein determining the sensitive data comprises extracting an HTTP header value from the Hypertext Transfer Protocol (HTTP) message.
11 . The system of claim 8 , wherein the authorized origin identifiers for the sensitive data comprises authorized destinations for the sensitive data.
12 . The system of claim 9 , wherein the authorized origin identifiers for the sensitive data comprises authorized triggers for the sensitive data.
13 . The system of claim 11 , further comprising: ensuring release of the sensitive data is transmitted only to an authorized origin identifier.
14 . The system of claim 12 , further comprising: ensuring release of the sensitive data is triggered only by an authorized origin identifier.
15 . An apparatus to protect sensitive data, the apparatus comprising:
a computing device coupled to a network, including: a processor; and a security agent for:
examining a Hypertext Transfer Protocol (HTTP) message received over a communication channel secured with a digital certificate;
determining a sensitive data;
determining an origin identifier identifying the digital certificate used to secure the communication channel; and
adding the determined origin identifier to a list of authorized origin identifiers for the sensitive data.
16 . The apparatus of claim 15 , wherein the sensitive data comprises one or more of: Hypertext Transfer Protocol (HTTP) Cookie, session cookie, session data, authentication information, authorization information, user credentials, personal data, and data sensitive in nature.
17 . The apparatus of claim 15 , wherein the Transport Layer Security (TLS) protocol is used to secure the communications channel, and wherein determining the sensitive data comprises extracting a value from the Hypertext Transfer Protocol (HTTP) message.
18 . The apparatus of claim 16 , wherein the authorized origin identifiers for the sensitive data comprises authorized destinations for the sensitive data.
19 . The apparatus of claim 15 , wherein the authorized origin identifiers comprises authorized triggers for the sensitive data.
20 . The apparatus of claim 18 , the security agent further comprises: ensuring release of the sensitive data is only transmitted to an authorized destination.
21 . The apparatus of claim 19 , the security agent further comprises: ensuring release of the sensitive data is only triggered by an authorized trigger.Join the waitlist — get patent alerts
Track US2019354709A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.