US2023315889A1PendingUtilityA1

Systems and Methods for Controlling Data Access in Client-Side Encryption

Assignee: GOOGLE LLCPriority: Apr 26, 2021Filed: Jun 6, 2023Published: Oct 5, 2023
Est. expiryApr 26, 2041(~14.7 yrs left)· nominal 20-yr term from priority
Inventors:Wei Peng
G06F 21/6218G06F 21/602G06F 21/606H04L 63/0428H04L 67/02H04L 9/0894H04L 67/564
69
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and methods for controlling access to data in applications using client-side encryption. In that regard, in some examples, a first application (e.g., an email application, calendar application, messaging application, word processing application, file storage application, etc.) hosted from a particular web domain may be configured to invoke a second application hosted from a different origin (e.g., a different web domain or subdomain) to handle receiving and encrypting any sensitive information from a client entered through a client application (e.g., a web browser), and to handle decrypting information to be provided to the client through the client application. This second application may be loaded in an inline frame or similar subwindow or subroutine configured to prevent or limit the first application from having access to sensitive information in the second application.

Claims

exact text as granted — not AI-modified
1 . A computer-implemented method comprising:
 receiving, by one or more processors of a processing system, first configuration data from a first application identifying how to encrypt content of a message being composed;   sending, by the one or more processors, a request to a second application to create an encryptor based on the first configuration data:   receiving, by the one or more processors, the encryptor from the second application;   sending, by the one or more processors, second configuration data to the first application indicating a readiness to accept the content of the message to be encrypted;   receiving, by the one or more processors, the content of the message from the first application for display to a user by a client application; and   encrypting, by the one or more processors using the encryptor, the content of the message.   
     
     
         2 . The method of  claim 1 , wherein the content comprises text, one or more files, or both the text and the one or more files. 
     
     
         3 . The method of  claim 1 , wherein the first application is an email application, calendar application, messaging application, or file storage application. 
     
     
         4 . The method of  claim 1 , wherein the first application comprises a webpage. 
     
     
         5 . The method of  claim 4 , wherein the second application comprises an inline frame within the webpage. 
     
     
         6 . The method of  claim 5 , wherein the webpage is from a first origin and the inline frame is from a second origin. 
     
     
         7 . The method of  claim 6 , wherein the first origin and the second origin represent different web domains. 
     
     
         8 . The method of  claim 7 , wherein the first origin and the second origin represent different web subdomains of a common web domain. 
     
     
         9 . The method of  claim 1 , wherein the second configuration data identifies how to decrypt the encrypted content. 
     
     
         10 . The method of  claim 1 , wherein the client application comprises a web browser. 
     
     
         11 . The method of  claim 1 , further comprising:
 sending, by the one or more processors, the encrypted content of the message to the first application.   
     
     
         12 . A computer-implemented method comprising:
 receiving, by one or more processors of a processing system, configuration data from a first application identifying how to decrypt content of an encrypted message;   sending, by the one or more processors, a request to a second application to create a decryptor based on the configuration data:   receiving, by the one or more processors, the decryptor from the second application;   sending, by the one or more processors, an indication of readiness to accept the content of the of the encrypted message to the first application;   receiving, by the one or more processors, the content of the message from the first application; and   decrypting, by the one or more processors using the decrypter, the content of the message for display to a user by a client application.   
     
     
         13 . The method of  claim 12 , wherein the encrypted content comprises text, one or more files, or both the text and the one or more files. 
     
     
         14 . The method of  claim 13 , wherein the first application is an email application, calendar application, messaging application, or file storage application. 
     
     
         15 . The method of  claim 12 , wherein the first application comprises a webpage. 
     
     
         16 . The method of  claim 15 , wherein the second application comprises an inline frame within the webpage. 
     
     
         17 . The method of  claim 16 , wherein the webpage is from a first origin and the inline frame is from a second origin. 
     
     
         18 . The method of  claim 17 , wherein the first origin and the second origin represent different web domains. 
     
     
         19 . The method of  claim 17 , wherein the first origin and the second origin represent different web subdomains of a common web domain. 
     
     
         20 . The method of  claim 12 , wherein the client application comprises a web browser.

Join the waitlist — get patent alerts

Track US2023315889A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.