IP Library Granted Patent US 7,093,121
Granted Patent B2
US 7,093,121 · App. 10/041,482 · Granted Aug 15, 2006

Transferring data via a secure network connection

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,093,121
App. No.
10/041,482
Granted
Aug 15, 2006
Kind
B2
Abstract

A request for secure data sent from a client computer 2 to a webtsite server computer 4 is redirected to a proxy computer 6 . A secure connection is established with the proxy computer 6 using a protocol such as HTTP and Certificate Exchange. The proxy computer 6 then establishes its own secure connection with the website server 4 . The data requested is passed in encrypted form from the website server computer 4 to the proxy computer 6 . The proxy computer 6 decrypts this data and then scans it for illegal content, such as computer viruses, worms, Trojans, banned computer files, banned words, banned combinations of words or banned images and the like. Providing no illegal content is found, the data is encrypted again for transfer over the secure link between the proxy computer 6 and the client computer 2 . The proxy computer 6 may conveniently be the firewall computer within a local area network.

Claims (66)

1. A computer program product for controlling a proxy computer to transfer data via a secure network connection, said computer program product comprising:

first link establishing code operable to establish a first secure link between a first computer and said proxy computer;

second link establishing code operable to establish a second secure link between said proxy computer and a second computer;

receiving code operable to receive at said proxy computer said data in an encrypted un-scannable form from said second computer;

decrypting code operable to decrypt said data at said proxy computer for scanning of said data;

scanning code operable to scan said data at said proxy computer for illegal content and triggering illegal content found action if illegal content is found within said data; and

sending code operable to send said data in encrypted form from said proxy computer to said first computer;

wherein further included is:

computer code for receiving a security Certificate from said proxy computer at a client computer;

computer code for prompting a user of said client comnuter to accent said security Certificate if said proxy computer is not configured as a Certification Authority within a browser of said client computer; computer code for receiving at said proxy computer from said client computer a symmetric key encrypted using a public key in said security Certificate if said user accepts said security Certificate, and

computer code for decrypting at said proxy computer said symmetric key using a private key;

wherein said first computer and said second computer are respective ones of said client computer accessing said data via said browser and a website server computer;

wherein said website server computer associates said security Certificate with said data sent from said website server computer to said proxy computer for use by said proxy computer to authenticate said data and said proxy computer associates said security Certificate issued by said proxy computer with said data sent from said proxy computer to said client computer for use by said client computer to authenticate said data;

wherein said proxy computer is a firewall computer;

wherein said proxy comnuter uses said s 'symmetric key for communication with said client computer;

wherein a webpage indicating that said data is not secure is returned to said client computer if said security Certificate from said website server computer is not produced by a recosnized Certification Authority;

wherein said illegal content found action includes at least one of sending a warning webpage to said client computer and terminating said first secure link between said proxy computer and said website server computer.

2. A computer program product as claimed in claim 1 , wherein said data is secure web content.

3. A computer program product as claimed in claim 1 , wherein said first secure link is made using a HTTPS secure protocol.

4. A computer program product as claimed in claim 1 , wherein said second secure link is made using a HITPS secure protocol.

5. A computer program product as claimed in claim 1 , wherein said illegal content includes one or more of: a computer virus, a worm, a Trojan, a banned computer file, a banned word, a banned combination of words and a banned image.

6. A method of transferring data via a secure network connection, said method comprising the steps of:

establishing a first secure link between a first computer and a proxy computer;

establishing a second secure link between said proxy computer and a second computer;

receiving at said proxy computer said data in an encrypted un-scannable form from said second computer;

decrypting said data at said proxy computer for scanning of said data;

scanning said data at said proxy computer for illegal content and triggering illegal content found action if illegal content is found within said data; and

sending said data in encrypted form from said proxy computer to said first computer;

wherein said method further comprises the steps of:

receiving a security Certificate from said proxy computer at a client computer,

prompting a user of said client computer to accept said security Certificate if said proxy comnuter is not configured as a Certification Authority within a browser of said client computer,

receiving at said proxy computer from said client computer a symmetric key encrvuted using a public key in said security Certificate if said user accepts said security Certificate, and

decrypting at said proxy computer said symmetric key using a private key;

wherein said first computer and said second computer are respective ones of said client computer accessing said data via said browser and a website server computer;

wherein said website server computer associates said security Certificate with said data sent from said website server computer to said proxy computer for use by said proxy computer to authenticate said data and said proxy computer associates said security Certificate issued by said proxy computer with said data sent from said proxy computer to said client computer for use by said client computer to authenticate said data;

wherein said proxy computer is a firewall computer;

wherein said proxy computer uses said symmetric key for communication with said client computer;

wherein a webpage indicating that said data is not secure is returned to said client computer if said security Certificate from said website server computer is not produced by a recognized Certification Authority;

wherein said illegal content found action includes at least one of sending a warning webpage to said client computer and terminating said first secure link between said proxy computer and said website server computer.

7. A method as claimed in claim 6 , wherein said data is secure web content.

8. A method as claimed in claim 6 , wherein said first secure link is made using a HTTPS secure protocol.

9. A method as claimed in claim 6 , wherein said second secure link is made using a HTTPS secure protocol.

10. A method as claimed in claim 6 , wherein said illegal content includes one or more of: a computer virus, a worm, a Trojan, a banned computer file, a banned word, a banned combination of words and a banned image.

11. A method as claimed in claim 6 , wherein the security Certificate is one of a default certificate and a certificate obtained from an organization.

12. Apparatus for transferring data via a secure network connection, said apparatus comprising:

first link establishing logic operable to establish a first secure link between a first computer and said proxy computer;

second link establishing logic operable to establish a second secure link between said proxy computer and a second computer;

receiving logic operable to receive at said proxy computer said data in an encrypted un-scannable form from said second computer;

decrypting logic operable to decrypt said data at said proxy computer for scanning of said data;

scanning logic operable to scan said data at said proxy computer for illegal content and triggering illegal content found action if illegal content is found within said data; and

sending logic operable to send said data in encrypted form from said proxy computer to said first computer;

wherein further included is;

logic for receiving a security Certificate from said proxy computer at a client computer,

logic for promoting a user of said client computer to accept said security Certificate if said proxy comnuter is not configured as a Certification Authority within a browser of said client computer,

logic for receiving at said proxy computer from said client computer a symmetric key encrypted using a public key in said security Certificate if said user accepts said security Certificate, and

logic for decrypting at said proxy computer said symmetric key using a private key;

wherein said first computer and said second computer are respective ones of said client computer accessing said data via said browser and a website server computer;

wherein said website server computer associates said security Certificate with said data sent from said website server computer to said proxy computer for use by said proxy computer to authenticate said data and said proxy computer associates said security Certificate issued by said proxy computer with said data sent from said proxy computer to said client computer for use by said client computer to authenticate said data;

wherein said proxy computer is a firewall computer;

wherein said proxy computer uses said symmetric, key for communication with said client comnuter;

wherein a webpage indicating that said data is not secure is returned to said client computer if said security Certificate from said website server computer is not produced by a recognized Certification Authority;

wherein said ideal content found action includes at least one of sending a warning webpage to said client computer and terminating said first secure link between said Proxy computer and said website server computer.

13. Apparatus as claimed in claim 12 , wherein said data is secure web content.

14. Apparatus as claimed in claim 12 , wherein said first secure link is made using a HTTPS secure protocol.

15. Apparatus as claimed in claim 12 , wherein said second secure link is made using a HTTPS secure protocol.

16. Apparatus as claimed in claim 12 , wherein said illegal content includes one or more of: a computer virus, a worm, a Trojan, a banned computer file, a banned word, a banned combination of words and a banned image.

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →