IP Library Granted Patent US 8,065,720
Granted Patent B1
US 8,065,720 · App. 10/752,385 · Granted Nov 22, 2011

Techniques for managing secure communications

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,065,720
App. No.
10/752,385
Granted
Nov 22, 2011
Kind
B1
Abstract

Methods and systems for managing secure communications are provided. An external client establishes secure communications with a secure site. During the secure session, the external client attempts to access potentially insecure references. These potentially insecure references are inspected before being made available to the external client. In some instances, the potentially insecure references are translated into secure references, which suppress normally occurring security warning messages that are issued to the external client. In other instances, the potentially insecure references are processed by a proxy on behalf of the external client and appear to the external client to occur within the secure session.

Claims (20)

1. A method to manage secure communications executes in a proxy server, the method, comprising:

establishing, by the proxy server, a secure session on a secure site with an external client that communicates from an insecure site;

detecting, by the proxy server, access attempts during the secure session directed to insecure transactions, the insecure transactions identified as links to a site that is external (external site) to, not controlled by, and not recognized by the secure site, and the access attempts are directed to the insecure transactions having references to resources of the external site; and

transparently managing, by the proxy server, the access attempts by pre-acquiring content from the external site by accessing the links on behalf of the external client to pre-acquire the content and by scanning and inspecting the content within the secure site before determining whether the content should be made available to the external client during the secure session, and at least one access attempt associated with at least one piece of the content that is scanned identifies a true insecure reference by determining that the true insecure reference is a particular reference that has been determined by the method to have had the piece of the content or metadata of the true insecure reference tampered with, and the true insecure reference is entirely removed from the content before the content is supplied to the external client and an event is reported as a custom warning inserted into the content supplied to the external client, the event identifies for the external client within the content that the true insecure reference was removed before being provided to the external client, and a number of other access attempts are associated with different content for other references that are secure but appear insecure, these other references are provided as secure references to the external client to suppress warning messages from being generated within the external client with these other access attempts made during the secure session.

2. The method of claim 1 wherein the detecting further includes translating any non-secure links into secure links for some of the insecure transactions before presenting results of the access attempts to the external client.

3. The method of claim 1 wherein managing includes at least one or more of:

permitting normally occurring security warnings to present messages to the external client by taking no action;

generating for and displaying to a custom warning message that is presented to the external client;

issuing alerts, notifications, or advisories to a monitoring entity or log; and

determining a number of the links are low-risk to or trusted by the secure site and thereby suppressing normally occurring security warnings from being presented to the external client.

4. A method to manage secure communications executes in a proxy server, the method, comprising:

detecting, by the proxy server, insecure transactions occurring during a secure session, the insecure transactions result from actions requested by an external client participating in the secure session;

inspecting, by the proxy server, the insecure transactions in advance of satisfying the actions requested by pre-acquiring content associated with the insecure transactions before making available to the external client, and the insecure transactions are associated with links to an external site located outside a secure site associated with the secure session, and content are pre-acquired from the external site via the links and inspected and scanned on behalf of the external client within the proxy server, and a number of references associated with some of the insecure references are determined to be secure, these references are translated to appear secure to the external client and when accessed by the external client suppress warning messages from occurring within the external client; and

making, by the proxy server, a determination based on the inspection for taking processing actions including one or more of the following: permitting some of the insecure transactions to proceed unmodified by performing the actions requested for the external client;

permitting, by the proxy server, some of the insecure transactions to proceed in a modified fashion; and denying some of the insecure transactions by denying the actions requested, and some of the insecure transactions that are denied are identified as references that have a World-Wide Web (WWW) cookie associated with their headers, and these references are entirely removed from the content before the content is supplied to the external client and the references entirely removed are reported as custom warning messages to the external client as an event within the content, the event identifies for the external client within the content that the true insecure reference was removed before being provided to the external client.

5. The method of claim 4 , wherein the making a determination further includes, permitting some of the insecure transactions to proceed in the modified fashion by changing the reference links from Hypertext Transfer Protocol (HTTP) insecure links to HTTP over Secure Sockets Layer (HTTPS) in order to suppress security warning messages.

6. The method of claim 4 wherein the making a determination further includes permitting some of the insecure transactions to proceed unmodified by permitting normally occurring security warnings to be presented to the external client before satisfying the external client access attempt to reference the external site.

7. The method of claim 4 wherein the making a determination further includes permitting some of the insecure transactions to proceed in a modified fashion by transparently processing the external client access attempt within the proxy server making the external client access attempt appear to be part of the secure session.

8. The method of claim 4 wherein the making a determination further includes denying the some of the insecure transactions after determining that the external client access attempt is corrupted and notifying the external client of a denial.

9. The method of claim 4 wherein the making a determination further includes denying the some of the insecure transactions after determining that the external client access attempt is corrupted and logging information about the external client access attempt.

Assignments (13)
RELEASE OF SECURITY INTEREST REEL/FRAME 035656/0251 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.)
Reel/Frame 062623/0009 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TO CORRECT TYPO IN APPLICATION NUMBER 10708121 WHICH SHOULD BE 10708021 PREVIOUSLY RECORDED ON REEL 042388 FRAME 0386. ASSIGNOR(S) HEREBY CONFIRMS THE NOTICE OF SUCCESSION OF AGENCY. Recorded Jul 26, 2018
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 048793/0832 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
NOTICE OF SUCCESSION OF AGENCY Recorded May 2, 2017
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 042388/0386 →
CHANGE OF NAME Recorded Sep 13, 2016
From: NOVELL, INC.
To: MICRO FOCUS SOFTWARE INC.
Reel/Frame 040020/0703 →
SECURITY INTEREST Recorded May 13, 2015
From: MICRO FOCUS (US), INC.; BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; NOVELL, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 035656/0251 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028252/0216 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034470/0680 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028252/0316 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034469/0057 →
GRANT OF PATENT SECURITY INTEREST FIRST LIEN Recorded May 23, 2012
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028252/0216 →
GRANT OF PATENT SECURITY INTEREST SECOND LIEN Recorded May 23, 2012
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028252/0316 →
RELEASE OF SECURITY INTEREST IN PATENTS FIRST LIEN (RELEASES RF 026270/0001 AND 027289/0727) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0077 →
RELEASE OF SECURITY IN PATENTS SECOND LIEN (RELEASES RF 026275/0018 AND 027290/0983) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0154 →