IP Library Granted Patent US 9,906,369
Granted Patent B2
US 9,906,369 · App. 15/001,015 · Granted Feb 27, 2018

System and method of cryptographically signing web applications

Inventors: Ryan Lester (Dover, DE); Jann Horn (Oldenburg, DE); Bryant Zadegan (Dover, DE)
Assignee: CYPH, INC.
H04L9/3247G06F8/60G06F21/45G06F21/606H04L5/0037H04L9/08H04L9/0861H04L9/321H04L9/3215H04L9/3228H04L51/16H04L63/0281H04L63/0435H04L63/0442H04L63/061H04L63/065H04L63/08H04L63/0838H04L63/123H04L63/18H04L67/02H04L67/10H04L67/141H04L67/146H04W12/10H04L67/42
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,906,369
App. No.
15/001,015
Granted
Feb 27, 2018
Kind
B2
Abstract

Embodiments disclosed herein provide a method that includes receiving, at a client-side web browser, a minimal bootstrap payload from an application server; storing, by a client-side processor, the minimal bootstrap payload in a client-side local cache, where the locally cached minimal bootstrap payload is executed by the client-side processor before executing an application from the application server; the minimal bootstrap payload includes at least one public key and at least one Uniform Resource Location (URL) address of an application code payload.

Claims (40)

1. A method, comprising:

receiving, at a client-side web browser, a minimal bootstrap payload from an application server;

storing, by the client-side processor, the minimal bootstrap payload in the client-side local cache, wherein

the locally cached minimal bootstrap payload is executed by the client-side processor before executing an application from the application server;

the minimal bootstrap payload includes at least one public key, at least one Uniform Resource Location (URL) address of an application code payload, a second URL and a backup URL;

the client-side processor executes the minimal bootstrap payload, which comprises:

receiving, at the client-side web browser, the application code payload from the URL specified by the minimal bootstrap payload, wherein the received application code payload includes a cryptographic signature that was generated using a private key associated with a public key specified by the minimal bootstrap payload;

verifying, by the client-side processor, the received application code payload cryptographic signature using a locally stored public key;

executing, by the client-side processor, the received application code payload after the received application payload has been successfully verified;

receiving a cryptographically signed pre-computed hash from the second URL,

verifying, by the client-side processor, the received pre-computed hash using a locally stored public key;

storing, by the client-side processor, in the client-side local cache a copy of the verified pre-computed hash with or without its associated signature; and

receiving a backup application code payload from a backup URL when the minimal bootstrap payload fails to verify the received application code payload cryptographic signature using a locally stored public key.

2. The method of claim 1 , wherein the minimal bootstrap payload further comprises:

storing, by the client-side processor, in the client-side local cache a copy of the verified application code payload; and

executing the client-side local cache copy of the verified application code payload when the minimal bootstrap payload fails to verify the received application code payload cryptographic signature using the locally stored public key.

3. The method of claim 1 , wherein the minimal bootstrap payload and the application code payload are written using a combination of HyperText Markup Language (HTML), Cascading Style Sheets (CSS) and JavaScript (JS).

4. The method of claim 1 , wherein the minimal bootstrap payload includes at least two public keys and further comprises verifying, by the client-side processor, the received application code payload cryptographic signature using multiple locally stored public keys.

5. The method of claim 1 , wherein the minimal bootstrap payload further comprises computing, by the client-side processor, a hash of the received application code payload.

6. The method of claim 5 , wherein the client-side processor executes the minimal bootstrap payload, which further comprises comparing the computed hash of the received application code payload with the client-side local cache's copy of the verified pre-computed hash when the received application code payload does not include a cryptographic signature.

7. A non-transitory computer readable medium comprising instructions which, when executed by a computing device, executes a method comprising:

receiving, at a client-side web browser, a minimal bootstrap payload from an application server;

storing, by the client-side processor, the minimal bootstrap payload in the client-side local cache, wherein

the locally cached minimal bootstrap payload is executed by the client-side processor before executing an application from the application server;

the minimal bootstrap payload includes at least one public key, at least one Uniform Resource Location (URL) address of an application code payload, a second URL and a backup URL;

the client-side processor executes the minimal bootstrap payload, which comprises:

receiving, at the client-side web browser, the application code payload from the URL specified by the minimal bootstrap payload, wherein the received application code payload includes a cryptographic signature using a private key associated with a public key specified by the minimal bootstrap payload;

verifying, by the client-side processor, the received application code payload cryptographic signature using a locally stored public key;

executing, by the client-side processor, the received application code payload after the received application payload has been successfully verified;

receiving a cryptographically signed pre-computed hash from the second URL,

verifying, by the client-side processor, the received pre-computed hash using a locally stored public key;

storing, by the client-side processor, in the client-side local cache a copy of the verified pre-computed hash with or without its associated signature; and

receiving a backup application code payload from a backup URL when the minimal bootstrap payload fails to verify the received application code payload cryptographic signature using a locally stored public key.

8. The non-transitory computer readable medium of claim 7 , wherein the minimal bootstrap payload further comprises:

storing, by the client-side processor, in the client-side local cache a copy of the verified application code payload; and

executing the client-side local cache copy of the verified application code payload when the minimal bootstrap payload fails to verify the received application code payload cryptographic signature using the locally stored public key.

9. The non-transitory computer readable medium of claim 7 , wherein the minimal bootstrap payload and the application code payload are written using a combination of HyperText Markup Language (HTML), Cascading Style Sheets (CSS) and JavaScript (JS).

10. The non-transitory computer readable medium of claim 7 , wherein the minimal bootstrap payload includes at least two public keys and further comprises verifying, by the client-side processor, the received application code payload cryptographic signature using multiple locally stored public keys.

11. The non-transitory computer readable medium of claim 7 , wherein the minimal bootstrap payload further comprises computing, by the client-side processor, a hash of the received application code payload.

12. The non-transitory computer readable medium of claim 11 , wherein the client-side processor executes the minimal bootstrap payload, which further comprises further comprises comparing the computed hash of the received application code payload with the client-side local cache's copy of the verified pre-computed hash when the received application code payload does not include a cryptographic signature.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 17, 2026
From: CYPH INC.
To: GADMI SECURITY LLC
Reel/Frame 074987/0964 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 22, 2018
From: LESTER, RYAN; ZADEGAN, BRYANT; HORN, JANN
To: CYPH INC.
Reel/Frame 046205/0630 →
Continuity (3)
Continuation PCTUS2015047788 · Aug 31, 2015
Provisional Application 62104307 · Jan 16, 2015
Related Publication 20170078099A1 · Mar 16, 2017