IP Library Granted Patent US 9,935,995
Granted Patent B2
US 9,935,995 · App. 14/581,469 · Granted Apr 3, 2018

Embedded script security using script signature validation

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,935,995
App. No.
14/581,469
Granted
Apr 3, 2018
Kind
B2
Abstract

A technique allows a client computer with a web browser to receive a web page having active content in response to transmitting a request for content. The active content includes a signature and a set of attributes associated with a web domain. The web browser can interpret the signature and the set of attributes as formatted in the active content. Validation of the signature and the set of attributes can be in a secure mode through a secure enclave module.

Claims (34)

1. One or more non-transitory machine readable media, on which are stored instructions, comprising instructions that when executed by a processor cause a machine to:

receive, by a browser on a computing system, a web page with active content; and

in response to the browser detecting the active content, determine that the computing system comprises a secure memory location;

in response to determining that the computing system comprises a secure memory location, validate, utilizing the secure memory location of the computing system, the active content for a presence of unauthorized content by validating a signature of at least a portion of the active content while leaving the active content in cleartext, wherein the signature is formatted for execution of the active content regardless of the determination that the computing system comprises the secure memory location; and

execute the active content in response to determining that the validation of the active content indicates that the active content originated from an authorized origin.

2. The one or more non-transitory machine readable media of claim 1 , wherein the active content further includes a set of attributes.

3. The one or more non-transitory machine readable media of claim 2 , wherein the signature and the set of attributes are formatted to be ignored by a browser incapable of interpreting the signature and the set of attributes.

4. The one or more non-transitory machine readable media of claim 2 , wherein the instructions to validate the active content comprise instructions that when executed cause the browser to check the set of attributes following a positive determination that the signature is valid; and

wherein the set of attributes includes information for one or more of an origin of the active content, an author of the active content, and a permitted use of the active content.

5. The one or more non-transitory machine readable media of claim 4 , wherein the instructions to validate the active content comprise instructions that when executed cause the browser to refuse to execute the active content if the check of the set of attributes indicates that the active content originated at a location other than an authorized origin.

6. The one or more non-transitory machine readable media of claim 1 , wherein the instructions to receive the active content comprise instructions that when executed cause the browser to receive authentication information related to authenticating a web server.

7. The one or more non-transitory machine readable media of claim 1 , wherein the instructions to validate the active content comprise instructions that when executed cause the browser to receive instructions related to obtaining a validation certificate from a certificate server.

8. A computer system for script security, comprising:

one or more processors; and

a memory coupled to the one or more processors, on which are stored instructions, comprising instructions that when executed cause at least some of the one or more processors to:

receive a web page with active content at a browser;

locate the active content with a parser;

in response to the browser locating the active content, determine that the computing system comprises a secure memory location;

in response to determining that the computing system comprises a secure memory location, validate, utilizing the secure memory location of the computing system, the active content for a presence of unauthorized content by validating a signature of at least a portion of the active content while leaving the active content in cleartext, wherein the signature is formatted for execution of the active content regardless of the determination that the computing system comprises the secure memory location; and

execute the active content in response to determining that the validation of the active content indicates that the active content originated from an authorized origin.

9. The computer system of claim 8 , wherein the active content further includes a set of attributes and wherein signature and the set of attributes are formatted to be ignored by a browser incapable of interpreting the signature and the set of attributes.

10. The computer system of claim 8 , wherein the active content further includes a set of attributes and wherein instructions further comprise instructions that when executed cause at least some of the one or more processors to:

check via the browser the set of attributes following a positive determination that the signature is valid;

wherein the set of attributes includes information for one or more of an origin of the active content, an author of the active content, and a permitted use of the active content.

11. The computer system of claim 8 , wherein the instructions further comprise instructions that when executed cause at least some of the one or more processors to receive, via the browser, authentication information related to authenticating a web server.

12. The computer system of claim 8 , wherein the instructions further comprise instructions that when executed cause at least some of the one or more processors to receive via the browser instructions related to obtaining a validation certificate from a certificate server.

13. A method for script security, comprising:

receiving at a browser on a computer system, a web page with active content;

locating by the browser the active content;

in response to the browser locating the active content, determining that the computing system comprises a secure memory location;

in response to determining that the computing system comprises a secure memory location, validate, utilizing the secure memory location of the computing system, the active content for a presence of unauthorized content by validating a signature of at least a portion of the active content while leaving the active content in cleartext, wherein the signature is formatted for execution of the active content regardless of the determination that the computing system comprises the secure memory location; and

executing the active content in response to determining that the validation of the active content indicates that the active content originated from an authorized origin.

14. The method of claim 13 , wherein the active content includes a set of attributes, and wherein the method further comprising checking the set of attributes following a positive determination that the signature is valid;

wherein checking the set of attributes comprises checking information related to at least one of origin of the active content, author of the active content, and a permitted use of the active content.

Assignments (11)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TITLE INSIDE THE ASSIGNMENT DOCUMENT PREVIOUSLY RECORDED AT REEL: 037276 FRAME: 0096. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Feb 24, 2016
From: SAMBANDAM, VENKATA RAMANAN; HUNT, SIMON
To: MCAFEE, INC.
Reel/Frame 037901/0075 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 11, 2015
From: SAMBANDAM, VENKATA RAMANAN; HUNT, SIMON
To: MCAFEE, INC.
Reel/Frame 037276/0096 →