IP Library Granted Patent US 8,789,199
Granted Patent B2
US 8,789,199 · App. 13/465,401 · Granted Jul 22, 2014

Authenticating a web page with embedded javascript

Inventor: Martin Boesgaard (Solrød Strand, DK)
Assignee: Codesealer APS
H04L63/14G06F21/51G06F21/52G06F21/14G06F21/125G06F21/128
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,789,199
App. No.
13/465,401
Granted
Jul 22, 2014
Kind
B2
Abstract

A method for detecting if a digital document (e.g. an HTML document) is changed by others than authenticated script code (e.g. JavaScript code) is presented. The method includes loading the authenticated script code into a trusted computer application and storing a snapshot of the digital document in the trusted computer application. Before the authenticated script code is executed, the snapshot of the digital document is compared with the document to verify if the digital document is still authentic. After executing the authenticated script code, the snapshot of the digital document is replaced with an up-to-date copy reflecting eventual changes made to the digital document by the executed script code. The digital document can then at any time be compared with the most recent snapshot to verify if it is authentic.

Claims (19)

1. A method of preventing modification of embedded script code in a digital document being viewed by a party or entity at a client computer communicating with a web server through the Internet, the web server hosting the digital document, the digital document comprising embedded script code methods, the method comprising:

providing, via the Internet, the digital document comprising the embedded script code methods to said party or entity from the web server;

creating, under the control of a trusted computer application running at said client computer, a first script code data object in the trusted computer application;

storing in the first script code data object of the trusted computer application said embedded script code methods of the digital document;

wherein said step of storing is carried out under the control of software provided by a security component;

overwriting, in the digital document, calls to at least one of the embedded script code methods with calls to the trusted computer application in order to invoke, at said computer, script code of the first script code data object in the trusted computer application in place of invoking the calls to the at least one embedded script code method, whereby the embedded script code methods are executable without being modifiable by the party or entity viewing the digital document; and

invoking the calls to the script code of the first script data object in the trusted computer application in response to an occurrence of one or more predetermined events in the digital document at said computer to invoke the calls to the at least one embedded script code methods comprised in the digital document,

wherein the digital document containing embedded script code has at least one section without embedded script code, and wherein said at least one section without embedded script code is omitted from the step of loading at least a part of the embedded script code in the digital document into the trusted computer application.

2. A method of detecting when a digital document with embedded script code has been modified and of preventing access to the embedded script code in the digital document, comprising the embedded script code modification prevention method of claim 1 to prevent access to the embedded script code.

3. A method according to claim 1 where the digital document is fetched by the trusted computer application and then forwarded to a viewer computer program to be viewed by a user.

4. A method according to claim 1 , further comprising:

storing the digital document being viewed in a viewer computer program in a shadow copy;

applying modifications caused by embedded script code to the shadow copy; and

subsequently copying the shadow copy to the viewed copy of the digital document to make the changes caused by the embedded script code appear in the viewer computer program.

5. A method according to claim 3 where the fetched digital document is fetched from a server over a network.

6. A method according to claim 3 where the viewer computer program is a web browser.

7. A method according to claim 3 where the digital document after being fetched but before being forwarded to the viewer computer program is at least one of a) authenticated and b) decrypted.

8. A method according to claim 3 wherein the digital document is fetched as several subcomponents, and at least one part of said digital document is fetched by the trusted computer program.

9. A method according to claim 1 , comprising the further step of removing possible embedded script code in the at least one marked section from the digital document.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 14, 2018
From: CODESEALER A/S
To: CODESEALER 2018 APS
Reel/Frame 047779/0140 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 15, 2017
From: CODESEALER APS
To: CODESEALER A/S
Reel/Frame 043603/0036 →
Priority Claims (2)
DK 2008-00220 · Feb 18, 2008 · national
DK 2008-00842 · Jun 17, 2008 · national
Continuity (2)
Continuation 12735774
Related Publication 20120222127A1 · Aug 30, 2012