IP Library › Granted Patent US 8,542,825
Granted Patent B2
US 8,542,825 · App. 13/158,221 · Granted Sep 24, 2013

Imparting cryptographic information in network communications

Inventors: Asa Whillock (San Francisco, CA); Edward Chan (Fremont, CA); Srinivas Manapragada (Fremont, CA); Matthew Kaufman (Bonny Doon, CA); Pritham Shetty (Los Altos, CA); Michael Thornburgh (San Jose, CA)
Assignee: Adobe Systems Incorporated
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,542,825
App. No.
13/158,221
Granted
Sep 24, 2013
Kind
B2
Abstract

This specification describes technologies relating to imparting cryptographic information in network communications. In general, aspects of the subject matter described in this specification can be embodied in methods that include identifying a location in a pre-defined portion of a network communication to be sent in a client-server environment, wherein the pre-defined portion is reserved for random data, inserting cryptographic information into the pre-defined portion of the network communication at the location, and sending the network communication in the client-server environment to facilitate modifying interactions in the client-server environment based at least in part on a result of processing of the cryptographic information; and on a receiving side, receiving cryptographic information inserted into the pre-defined portion of the network communication in the client-server environment, identifying the location, processing the cryptographic information, and modifying interactions in the client-server environment based at least in part on a result of the processing.

Claims (67)

1. A method comprising:

receiving cryptographic information inserted into a pre-defined portion of a network communication in a client-server environment, wherein the pre-defined portion of the network communication is reserved for random data to support bandwidth detection;

identifying a location of the cryptographic information in the pre-defined portion of the network communication;

processing the cryptographic information; and

modifying interactions in the client-server environment based at least in part on a result of the processing of the cryptographic information;

wherein the random data is different from the cryptographic information.

2. The method of claim 1 , wherein identifying the location comprises using at least part of the network communication to determine the location.

3. The method of claim 2 , wherein the pre-defined portion includes the random data, and using at least part of the network communication to determine the location comprises:

retrieving a portion of the random data; and

determining an index into the pre-defined portion of the network communication based on the retrieved portion of the random data.

4. The method of claim 3 , wherein using at least part of the network communication to determine the location comprises:

retrieving multiple different portions of the random data; and

determining multiple different indices into the pre-defined portion of the network communication based on the different portions of the random data.

5. The method of claim 1 , wherein processing the cryptographic information comprises establishing a cryptographic key, and wherein modifying interactions in the client-server environment comprises initiating an encrypted session using the cryptographic key.

6. The method of claim 1 , wherein processing the cryptographic information comprises authenticating the network communication, and wherein modifying interactions in the client-server environment comprises turning on or off a feature of a program operating in the client-server environment.

7. A non-transitory computer-readable medium having a computer program product encoded therein, the computer program product operable to cause data processing apparatus to perform operations comprising:

receiving cryptographic information inserted into a pre-defined portion of a network communication in a client-server environment, wherein the pre-defined portion of the network communication is reserved for random data to support bandwidth detection;

identifying a location of the cryptographic information in the pre-defined portion of the network communication;

processing the cryptographic information; and

modifying interactions in the client-server environment based at least in part on a result of the processing of the cryptographic information;

wherein the random data is different from the cryptographic information.

8. The non-transitory computer-readable medium of claim 7 , wherein identifying the location comprises using at least part of the network communication to determine the location.

9. The non-transitory computer-readable medium of claim 8 , wherein the pre-defined portion includes the random data, and using at least part of the network communication to determine the location comprises:

retrieving a portion of the random data; and

determining an index into the pre-defined portion of the network communication based on the retrieved portion of the random data.

10. The non-transitory computer-readable medium of claim 9 , wherein using at least part of the network communication to determine the location comprises:

retrieving multiple different portions of the random data; and

determining multiple different indices into the pre-defined portion of the network communication based on the different portions of the random data.

11. The non-transitory computer-readable medium of claim 7 , wherein processing the cryptographic information comprises establishing a cryptographic key, and wherein modifying interactions in the client-server environment comprises initiating an encrypted session using the cryptographic key.

12. The non-transitory computer-readable medium of claim 7 , wherein processing the cryptographic information comprises authenticating the network communication, and wherein modifying interactions in the client-server environment comprises turning on or off a feature of a program operating in the client-server environment.

13. A system comprising:

a server computer programmed to establish both non-encrypted sessions and encrypted sessions over a network, with client computers, using a session startup handshake including a network communication including a pre-defined portion reserved for random data to support bandwidth detection;

a first of the client computers programmed to establish non-encrypted sessions with the server computer using the session startup handshake; and

a second of the client computers programmed to establish encrypted sessions with the server computer using the session startup handshake including cryptographic information inserted into the pre-defined portion of the network communication;

wherein the server computer and the second client computer are programmed to perform operations comprising: identifying a location of the cryptographic information in the pre-defined portion of the network communication, processing the cryptographic information, and modifying interactions between the server computer and the second client computer based at least in part on a result of the processing of the cryptographic information;

wherein the random data is different from the cryptographic information.

14. The system of claim 13 , wherein the client computers comprise mobile devices.

15. The system of claim 13 , wherein identifying the location comprises using at least part of the network communication to determine the location.

16. The system of claim 15 , wherein the pre-defined portion includes the random data, and using at least part of the network communication to determine the location comprises:

retrieving a portion of the random data; and

determining an index into the pre-defined portion of the network communication based on the retrieved portion of the random data.

17. The system of claim 16 , wherein using at least part of the network communication to determine the location comprises:

retrieving multiple different portions of the random data; and

determining multiple different indices into the pre-defined portion of the network communication based on the different portions of the random data.

18. The system of claim 13 , wherein processing the cryptographic information comprises:

authenticating the network communication, and

establishing a cryptographic key; and

wherein modifying interactions between the server computer and the second client computer comprises:

turning on or off a feature of a program operating in the server computer or the second client computer, and

initiating an encrypted session between the server computer and the second client computer using the cryptographic key.

19. The system of claim 13 , wherein the server computer and the second client computer are programmed to perform the operations comprising: inserting a message authentication code and encryption key establishment information into the network communication.

20. A method comprising:

identifying a location in a pre-defined portion of a network communication to be sent in a client-server environment, wherein the pre-defined portion of the network communication is reserved for random data to support bandwidth detection;

inserting cryptographic information into the pre-defined portion of the network communication at the location; and

sending the network communication in the client-server environment to facilitate modifying interactions in the client-server environment based at least in part on a result of processing of the cryptographic information;

wherein the random data is different from the cryptographic information.

21. The method of claim 20 , wherein the pre-defined portion includes the random data, and identifying the location comprises:

retrieving a portion of the random data; and

determining an index into the pre-defined portion of the network communication based on the retrieved portion of the random data.

22. A non-transitory computer-readable medium having a computer program product encoded therein, the computer program product operable to cause data processing apparatus to perform operations comprising:

identifying a location in a pre-defined portion of a network communication to be sent in a client-server environment, wherein the pre-defined portion of the network communication is reserved for random data to support bandwidth detection;

inserting cryptographic information into the pre-defined portion of the network communication at the location; and

sending the network communication in the client-server environment to facilitate modifying interactions in the client-server environment based at least in part on a result of processing of the cryptographic information;

wherein the random data is different from the cryptographic information.

23. The non-transitory computer-readable medium of claim 22 , wherein the pre-defined portion includes the random data, and identifying the location comprises:

retrieving a portion of the random data; and

determining an index into the pre-defined portion of the network communication based on the retrieved portion of the random data.

Assignments (2)
CHANGE OF NAME Recorded Apr 8, 2019
From: ADOBE SYSTEMS INCORPORATED
To: ADOBE INC.
Reel/Frame 048867/0882 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 15, 2011
From: WHILLOCK, ASA; CHAN, EDWARD; MANAPRAGADA, SRINIVAS; KAUFMAN, MATTHEW; SHETTY, PRITHAM; THORNBURGH, MICHAEL
To: ADOBE SYSTEMS INCORPORATED
Reel/Frame 026458/0660 →
Continuity (2)
Continuation 11872661 · Oct 15, 2007
Related Publication 20110302417A1 · Dec 8, 2011