IP Library Granted Patent US 7,444,678
Granted Patent B2
US 7,444,678 · App. 10/868,414 · Granted Oct 28, 2008

Securing resources from untrusted scripts behind firewalls

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,444,678
App. No.
10/868,414
Granted
Oct 28, 2008
Kind
B2
Abstract

The invention provides a new mechanism which is used to protect all internal resources against requests from sandboxed scripts. In the preferred embodiment, the mechanism is implemented for SOAP calls by untrusted scripts. When an attempt is made to access a resource at a previously-unknown URI, the sandbox reads a file at that domain with declarations to determine whether access is permitted to the script. If the file is not found, the access is denied.

Claims (34)

1. A method for protecting internal resources against an untrusted script originated from an external server, said script being executed in a security sandbox behind a network firewall, said method comprising the steps of:

responsive to said untrusted script requesting access to an internal resource at a request URI, said security sandbox loading a script control definition from a declaration file at the root directory of said request URI, said script control definition comprising allowable request types and script originations;

said security sand box validating said script control definition at said root directory;

if said request URI is not a subdirectory, allowing said untrusted script to access said internal resource only in response to operations comprising:

said security sandbox verifying that the type of request is allowed in said script control definition at said root directory;

said security sandbox verifying that the origination of said untrusted script is allowed in said script control definition at said root directory;

if said request URI is a subdirectory, allowing said untrusted script to access said internal resource only in response to operations comprising:

said security sandbox verifying that delegation is allowed in said script control definition at root directory;

only if delegation is allowed, said security sandbox loading a script control definition from a declaration file at said subdirectory of said request URI, said script control definition at said subdirectory comprising allowable request types and script originations;

said security sand box validating said script control definition at said subdirectory;

said security sandbox verifying that the type of request is allowed in said script control definition at said subdirectory:

said security sandbox verifying that the origination of said untrusted script is allowed in said script control definition at said subdirectory.

2. The method of claim 1 , further comprising the step of:

said security sandbox denying said untrusted script to accept said internal resource when said declaration file is not found at said root directory.

3. The method of claim 1 , further comprising the step of:

said security sandbox denying said untrusted script to accept said internal resource when said security box cannot validate said script control definition at said root directory.

4. The method of claim 1 , further comprising the step of:

said security sandbox denying said untrusted script to accept said internal resource when said type of request is not allowed in said script control definition at said root directory.

5. The method of claim 1 , further comprising the step of:

said security sandbox denying said untrusted script to accept said internal resource when said origination of request is not allowed in said script control definition at said root directory.

6. The method of claim 1 , further comprising the step of:

said security sandbox denying said untrusted script to accept said internal resource when said declaration file is not found at said subdirectory.

7. The method of claim 1 , further comprising the step of:

said security sandbox denying said untrusted script to accept said internal resource when said security box cannot validate said script control definition at said subdirectory.

8. The method of claim 1 , further comprising the step of:

said security sandbox denying said untrusted script to accept said internal resource when said type of request is not allowed in said script control definition at said subdirectory.

9. The method of claim 1 , further comprising the step of:

said security sandbox denying said untrusted script to accept said internal resource when said origination of request is not allowed in said script control definition at said subdirectory.

10. The method of claim 1 , wherein any type of request is allowed when “any” is specified as the type to be allowed in a declaration file.

11. The method of claim 1 , wherein scripts from all origination are allowed when allowed originations are not specified in a declaration file.

12. The method of claim 1 , wherein wildcard characters are used to specify originations from which scripts are allowed.

13. The method of claim 1 , wherein said script control definitions are cached by said sandbox so that said script control definitions are only loaded once.

14. The method of claim 1 , wherein said request URI specifies a SOAP request.

15. The method of claim 1 , wherein said declaration files are of XML.

Assignments (8)
CHANGE OF NAME Recorded Dec 20, 2021
From: FACEBOOK, INC.
To: META PLATFORMS, INC.
Reel/Frame 058961/0436 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 3, 2012
From: AOL INC.
To: FACEBOOK, INC.
Reel/Frame 028487/0304 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Nov 16, 2010
From: BANK OF AMERICA, N A
To: AOL INC; AOL ADVERTISING INC; GOING INC; LIGHTNINGCAST LLC; MAPQUEST, INC; NETSCAPE COMMUNICATIONS CORPORATION; QUIGO TECHNOLOGIES LLC; SPHERE SOURCE, INC; TACODA LLC; TRUVEO, INC; YEDDA, INC
Reel/Frame 025323/0416 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 30, 2009
From: AOL LLC
To: AOL INC.
Reel/Frame 023750/0210 →
SECURITY AGREEMENT Recorded Dec 14, 2009
From: AOL INC.; AOL ADVERTISING INC.; BEBO, INC.; ICQ LLC; GOING, INC.; LIGHTNINGCAST LLC; MAPQUEST, INC.; NETSCAPE COMMUNICATIONS CORPORATION; QUIGO TECHNOLOGIES LLC; SPHERE SOURCE, INC.; TACODA LLC; TRUVEO, INC.; YEDDA, INC.
To: BANK OF AMERICAN, N.A. AS COLLATERAL AGENT
Reel/Frame 023649/0061 →
CORRECTIVE ASSIGNMENT TO CORRECT THE NATURE OF CONVEYANCE PREVIOUSLY RECORDED ON REEL 019711 FRAME 0316. ASSIGNOR(S) HEREBY CONFIRMS THE NATURE OF CONVEYANCE IS CHANGE OF NAME. Recorded Mar 25, 2009
From: AMERICA ONLINE, INC.
To: AOL LLC, A DELAWARE LIMITED LIABILITY COMPANY
Reel/Frame 022451/0186 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 17, 2007
From: AMERICA ONLINE, INC.
To: AOL LLC, A DELAWARE LIMITED LIABILITY COMPANY
Reel/Frame 019711/0316 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 14, 2004
From: WHITMER, RAY; DHURVASULA, HARISH
To: AMERICAN ONLINE, INCORPORATED
Reel/Frame 015480/0982 →