Systems and Methods for Controlling Data Access in Client-Side Encryption
Abstract
Systems and methods for controlling access to data in applications using client-side encryption. In that regard, in some examples, a first application (e.g., an email application, calendar application, messaging application, word processing application, file storage application, etc.) hosted from a particular web domain may be configured to invoke a second application hosted from a different origin (e.g., a different web domain or subdomain) to handle receiving and encrypting any sensitive information from a client entered through a client application (e.g., a web browser), and to handle decrypting information to be provided to the client through the client application. This second application may be loaded in an inline frame or similar subwindow or subroutine configured to prevent or limit the first application from having access to sensitive information in the second application.
Claims
exact text as granted — not AI-modified1 . A computer-implemented method comprising:
receiving, by one or more processors of a processing system, first configuration data from a first application identifying how to encrypt content of a message being composed; sending, by the one or more processors, a request to a second application to create an encryptor based on the first configuration data: receiving, by the one or more processors, the encryptor from the second application; sending, by the one or more processors, second configuration data to the first application indicating a readiness to accept the content of the message to be encrypted; receiving, by the one or more processors, the content of the message from the first application for display to a user by a client application; and encrypting, by the one or more processors using the encryptor, the content of the message.
2 . The method of claim 1 , wherein the content comprises text, one or more files, or both the text and the one or more files.
3 . The method of claim 1 , wherein the first application is an email application, calendar application, messaging application, or file storage application.
4 . The method of claim 1 , wherein the first application comprises a webpage.
5 . The method of claim 4 , wherein the second application comprises an inline frame within the webpage.
6 . The method of claim 5 , wherein the webpage is from a first origin and the inline frame is from a second origin.
7 . The method of claim 6 , wherein the first origin and the second origin represent different web domains.
8 . The method of claim 7 , wherein the first origin and the second origin represent different web subdomains of a common web domain.
9 . The method of claim 1 , wherein the second configuration data identifies how to decrypt the encrypted content.
10 . The method of claim 1 , wherein the client application comprises a web browser.
11 . The method of claim 1 , further comprising:
sending, by the one or more processors, the encrypted content of the message to the first application.
12 . A computer-implemented method comprising:
receiving, by one or more processors of a processing system, configuration data from a first application identifying how to decrypt content of an encrypted message; sending, by the one or more processors, a request to a second application to create a decryptor based on the configuration data: receiving, by the one or more processors, the decryptor from the second application; sending, by the one or more processors, an indication of readiness to accept the content of the of the encrypted message to the first application; receiving, by the one or more processors, the content of the message from the first application; and decrypting, by the one or more processors using the decrypter, the content of the message for display to a user by a client application.
13 . The method of claim 12 , wherein the encrypted content comprises text, one or more files, or both the text and the one or more files.
14 . The method of claim 13 , wherein the first application is an email application, calendar application, messaging application, or file storage application.
15 . The method of claim 12 , wherein the first application comprises a webpage.
16 . The method of claim 15 , wherein the second application comprises an inline frame within the webpage.
17 . The method of claim 16 , wherein the webpage is from a first origin and the inline frame is from a second origin.
18 . The method of claim 17 , wherein the first origin and the second origin represent different web domains.
19 . The method of claim 17 , wherein the first origin and the second origin represent different web subdomains of a common web domain.
20 . The method of claim 12 , wherein the client application comprises a web browser.Join the waitlist — get patent alerts
Track US2023315889A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.