IP Library Granted Patent US 7,979,909
Granted Patent B2
US 7,979,909 · App. 11/949,480 · Granted Jul 12, 2011

Application controlled encryption of web browser data

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,979,909
App. No.
11/949,480
Granted
Jul 12, 2011
Kind
B2
Abstract

A browser cache-securing component facilitates online communication of confidential data, such as for financial information, purchasing transactions, or user identification. Caching webpages for subsequent presentation enhances user productivity and efficiency while reducing burdens on network resources. Yet, the security risks of intrusions into cache memory are mitigated by retaining encrypted data in cache memory without prior decryption. A modest overhead in decrypting when and if the webpage is to be presented again gains a security and privacy advantage without taking away functionality. Decrypted versions of confidential data can thereby be relegated to volatile memory. Upon termination of a session, a session key shared by a network server is deleted, preventing subsequent decryption. Executing the browser cache-securing component in a virtual machine environment allows multiple browser types to benefit from the security feature.

Claims (33)

1. A method for improving security of confidential data cached by a web browser, comprising:

receiving a decryption component that facilitates secure communication of confidential data from a server;

receiving a webpage containing encrypted content;

caching the webpage and the encrypted content;

presenting confidential data by decrypting the encrypted content with the decryption component; and

deleting the decryption component from the web browser upon a session terminating event, wherein the session terminating event comprises receiving a reset session key from the server.

2. The method of claim 1 , wherein the presenting confidential data is in response to a user command to backup to a previously presented webpage.

3. The method of claim 1 , wherein the decryption component comprises a session key and decryption software.

4. The method of claim 3 , wherein deleting the decryption component comprises deleting the session key.

5. The method of claim 1 , wherein the session terminating event comprises closing a browser that presents the confidential data.

6. The method of claim 5 , wherein the decryption component comprises a session key and decryption software, deleting the decryption component comprises deleting the session key.

7. The method of claim 1 , wherein the session terminating event comprises a time expiration condition.

8. The method of claim 1 , further comprising sending authentication credentials with secure hypertext transport protocol utilizing secure socket layer (SSL) encryption and receiving a unique set cookie as the session key.

9. An apparatus that improves security of confidential data, comprising:

at least one processor coupled to a memory, the processor executing:

a first set of codes that cause a client computer to receive a decryption component for secure communication of confidential data from a server;

a second set of codes that cause the client computer to receive a webpage containing encrypted content;

a third set of codes that cause the client computer to cache the webpage and the encrypted content;

a fourth set of codes that cause the client computer to present confidential data by decrypting the encrypted content with the decryption component; and

a fifth set of codes that cause the client computer to delete the decryption component upon a session terminating event, wherein the session terminating event comprises receiving a reset session key.

10. The apparatus of claim 9 , wherein the presenting confidential data is in response to a user command to backup to a previously presented webpage.

11. The apparatus of claim 9 , wherein the decryption component comprises a session key and decryption software.

12. The apparatus of claim 11 , wherein deleting the decryption component comprises deleting the session key.

13. The apparatus of claim 9 , wherein the session terminating event comprises closing a browser that presents the confidential data.

14. The apparatus of claim 13 , wherein the decryption component comprises a session key and decryption software, deleting the decryption component comprises deleting the session key.

15. The apparatus of claim 9 , wherein the session terminating event comprises a time expiration condition.

16. The apparatus of claim 9 , further comprising sending authentication credentials with secure hypertext transport protocol utilizing secure socket layer (SSL) encryption and receiving a unique set cookie as the session key.

17. An apparatus that improves security of confidential data, comprising:

a networked computing platform;

a browser component executed by the networked computing platform for rendering a webpage;

a cache memory that caches a decryption component, a session key, a webpage containing encrypted content, and a decryption algorithm,

wherein the browser utilizes the cache memory to present confidential data by decrypting the encrypted content with the decryption component in response to a user command to return to a previously rendered webpage, and to delete the session key to prevent subsequent decryption of the encrypted content in cache memory, and wherein the browser deletes the session key based at least in part upon a reset session key received by the browser.

18. The apparatus of claim 17 , wherein the browser deletes the session key based at least in part upon a detected interruption in a connection to a server hosting the webpage.

Assignments (4)
ADDRESS CHANGE Recorded Jun 2, 2025
From: WELLS FARGO BANK, N.A.
To: WELLS FARGO BANK, N.A.
Reel/Frame 071769/0158 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 4, 2009
From: WELLS FARGO & COMPANY
To: WELLS FARGO BANK, N.A.
Reel/Frame 022207/0325 →
MERGER Recorded Jan 23, 2009
From: WACHOVIA CORPORATION
To: WELLS FARGO & COMPANY
Reel/Frame 022144/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 3, 2007
From: JANCULA, JEFFREY JOHN; SURI, NATHAN THANGAVADIVEL; NA, QIYUAN
To: WACHOVIA CORPORATION
Reel/Frame 020188/0901 →