IP Library Granted Patent US 8,843,516
Granted Patent B2
US 8,843,516 · App. 11/417,090 · Granted Sep 23, 2014

Internet security

Inventors: Chik Weng Leong (Kuala Lumpur, MY); Ying Chyn Ng (Kuala Lumpur, MY); Chee Hoo Lau (Kuala Lumpur, MY)
Assignee: E-Lock Corporation SDN. BHD.
G06F17/30867H04L63/1441G06F2221/2119H04L63/1483
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,843,516
App. No.
11/417,090
Granted
Sep 23, 2014
Kind
B2
Abstract

Redirection of user entered data to an unauthenticated website (“phishing”) is checked by, at redirection, detecting the presence of data entry fields in a user web page and, if any are present, authenticating the redirection address against lists of approved websites or the redirection web site certificate. If the new address is not authenticated, the user may still opt to be redirected.

Claims (39)

1. A method of controlling a submission of user-entered information in a web browser, comprising:

(a) detecting when the user attempts to send a page request to navigate from a current web page to a different web address;

(b) detecting data entry fields in the currently displayed page; and

(c) if no data entry fields are detected, allowing a submission of the page request to the different web address, or

(d) if data entry fields are detected; verifying that the different web address is either in an approved list of web addresses, or corresponds to a site certificate of a secure site before allowing a submission of the page request to the different web address; and allowing the submission of the page request to the different web address if it is verified or denying the submission of the page request to the different web address if it is not verified.

2. The method as claimed in claim 1 , wherein if the different web address is not verified, the user is queried for verification.

3. The method as claimed in claim 2 , wherein the user may add the different web address to the approved list of web addresses.

4. The method as claimed in claim 2 , wherein the data entry fields are detected in the current web page by detecting web form fields of the text type.

5. The method as claimed in claim 1 , wherein the approved, list of web addresses includes one or more of a user-approved list, an embedded approved list, or a web-based approved list.

6. The method as claimed in claim 5 , wherein the web-based approved list is a list available from a secure server.

7. The method as claimed in claim 1 , wherein the different web address is compared with a rejection black list.

8. The method as claimed in claim 1 , wherein the secure site is a site using the Secure Sockets Layer protocol.

9. The method as claimed in claim 1 , wherein the verifying results in degrees of verification and each degree is indicated to the user by a color indication.

10. A system for authenticating a web browser address comprising one or more computer-readable media having stored thereon a computer program comprising:

(a) a web browser; and

(b) a web browser plug-in,

(c) wherein the plug-in intercepts any request to view a web page differing from a displayed web page, analyzing the displayed web page for data entry fields and,

(1) if no data entry fields are detected, allowing a transmission of the request to view, or

(2) if data entry fields are detected, comparing the requested web page address with previously authenticated addresses before allowing the transmission of the request to view, and allowing transmission of the request to view if the differing web page address is one of the previously authenticated addresses, or denying transmission of the request to view if the differing web page address is not one of the previously authenticated addresses.

11. The system as claimed in claim 10 , wherein the authenticated addresses are held in lists and at least one list is embedded in the plug-in.

12. The system as claimed in claim 10 , wherein the plug-in also provides rejection if a request matches a list of sites to be rejected.

13. The system as claimed in claim 10 , wherein the authenticator indicates its active presence in the browser by displaying a toolbar.

14. The system as claimed in claim 13 , wherein the toolbar indicates the status of current requests of web page addresses.

15. A system for authenticating a web browser address comprising a web browser plug-in comprising:

(a) an interceptor which intercepts any request to view a web page differing from the current web page; and

(b) an analyzer which analyses the current web page for data entry fields and,

(1) if no data entry fields are detected, allows the request or

(2) if data entry fields are detected, compares an address of the request with previously authenticated addresses before allowing the request,

wherein if data entry fields are present, and the requested web page address matches one of the previously authenticated addresses, the plug-in allows the request or if data entry fields are present and the requested web page address does not match one previously authenticated addresses, the plug-in denies the request.

16. The system as claimed in claim 15 , wherein if the requested web page address is not authenticated, the plug-in queries the user for authentication.

17. The system as claimed in claim 16 , wherein the address analyser uses at least one of an address list internal to the plug-in, an address list associated with the browser, or an address list available from a web server.

18. The system as claimed in claim 15 , wherein the plug-in interacts with the user via a browser toolbar.

19. A computer program product comprising

a non-transitory computer readable medium including instructions which are operable to control an internet browser to:

(a) detect when the user attempts to send a page request to navigate from a current web page to a different web address;

(b) detect data entry fields in the current web page; and

(1) if data entry fields are not detected, allowing a submission of the page request to the different web address, or

(2) if data entry fields are detected, verifying-that the different web address is either in an approved list of web addresses, or corresponds to a site certificate of a secure site before allowing the submission of the page request to the different web address; and allowing the submission of the page request to the different web address if it is verified or denying the submission of the page request to the different web address if it is not verified.

20. The computer program product as claimed in claim 19 , wherein the instructions are present in the form of a browser plug-in.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 27, 2006
From: LEONG, CHIK WENG; NG, YING CHYN; LAU, CHEE HOO
To: E-LOCK CORPORATION SDN.BHD.
Reel/Frame 018133/0924 →
Priority Claims (1)
MY PI 20051966 · May 3, 2005 · national
Continuity (1)
Related Publication 20060253446A1 · Nov 9, 2006