IP Library Granted Patent US 10,447,672
Granted Patent B2
US 10,447,672 · App. 15/482,638 · Granted Oct 15, 2019

Facilitating encrypted persistent storage in browsers

Inventors: Kevin Venkiteswaran (Alameda, CA); Sergey Gorbaty (Emeryville, CA); Bob Yao (Daly City, CA); Trevor James Bliss (Oakland, CA)
Assignee: salesforce.com, inc.
H04L63/061G06F16/957G06F21/60G06F21/6209G06F21/6263H04L63/0428H04L67/1027H04L67/142H04L67/146
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,447,672
App. No.
15/482,638
Granted
Oct 15, 2019
Kind
B2
Abstract

Disclosed are some implementations of systems, apparatus, methods and computer program products for encrypting and securely storing session data during a browser session using a session-based cryptographic key. The session data may be decrypted during the browser session or other browser sessions using the session-based cryptographic key or other backwards compatible session-based cryptographic keys. In addition, session-based cryptographic keys may be shared among browser sessions to enable encrypted session data to be decrypted across page refreshes and browser tabs.

Claims (58)

1. A computing device comprising:

a memory; and

a processor configured to:

during a first browser session of a web browser situated at the computing device, obtain a first cryptographic key, the first browser session being associated with a session identifier (ID);

during the first browser session of the web browser, obtain session data;

apply the first cryptographic key to the session data to generate encrypted session data;

store the encrypted session data in the memory;

during a second browser session of the web browser, transmit a cryptographic key request to a server, the second browser session being associated with the session ID;

responsive to the cryptographic key request, receive a second cryptographic key from the server;

retrieve the encrypted session data from the memory; and

decrypt the encrypted session data using the second cryptographic key.

2. The computing device as recited in claim 1 , the processor being further configured to:

determine whether the second cryptographic key is configured to decrypt the encrypted session data;

wherein decrypting the encrypted session data using the second cryptographic key is performed in response to determining that the second cryptographic key is configured to decrypt the encrypted session data.

3. The computing device as recited in claim 2 , the processor being further configured to determine whether the second cryptographic key is configured to decrypt the encrypted session data by

decrypting an encrypted sentinel value with the second cryptographic key.

4. The computing device as recited in claim 1 , wherein the first cryptographic key and the second cryptographic key are stored in ephemeral memory.

5. The computing device as recited in claim 1 , wherein the memory comprises an indexed database, and wherein the encrypted session data is stored in the indexed database.

6. The computing device as recited in claim 1 , wherein the memory comprises a browser cache, and wherein the encrypted session data is stored in the browser cache.

7. The computing device as recited in claim 1 , the processor being further configured to:

transmit, by a second browser instance associated with the second browser session, the second cryptographic key to a first browser instance associated with the first browser session.

8. A computer program product comprising one or more non-transitory computer-readable media having computer program instructions stored therein, the computer program instructions capable of being executed by one or more processors, computer program instructions configurable to cause:

during a first browser session of a web browser situated at a computing device, obtaining a first cryptographic key, the first browser session being associated with a session identifier (ID);

during the first browser session of the web browser, obtaining session data;

applying the first cryptographic key to the session data to generate encrypted session data;

storing the encrypted session data in a memory of the computing device;

during a second browser session of the web browser, transmitting a cryptographic key request to a server, the second browser session being associated with the session ID;

responsive to the cryptographic key request, receiving a second cryptographic key from the server;

retrieving the encrypted session data from the memory; and

decrypting the encrypted session data using the second cryptographic key.

9. The computer program product as recited in claim 8 , the computer program instructions further configurable to cause:

determining whether the second cryptographic key is configured to decrypt the encrypted session data;

wherein decrypting the encrypted session data using the second cryptographic key is performed in response to determining that the second cryptographic key is configured to decrypt the encrypted session data.

10. The computer program product as recited in claim 9 , wherein determining whether the second cryptographic key is configured to decrypt the encrypted session data comprises:

decrypting an encrypted sentinel value with the second cryptographic key.

11. The computer program product as recited in claim 8 , wherein the first cryptographic key and the second cryptographic key are stored in ephemeral memory.

12. The computer program product as recited in claim 8 , wherein the memory comprises an indexed database, and wherein the encrypted session data is stored in the indexed database.

13. The computer program product as recited in claim 8 , wherein the memory comprises a browser cache, and wherein the encrypted session data is stored in the browser cache.

14. The computer program product as recited in claim 8 , the computer program instructions further configurable to cause:

transmitting, by a second browser instance associated with the second browser session, the second cryptographic key to a first browser instance associated with the first browser session.

15. A method, comprising:

during a first browser session of a web browser situated at a computing device, obtaining a first cryptographic key, the first browser session being associated with a session identifier (ID);

during the first browser session of the web browser, obtaining session data;

applying the first cryptographic key to the session data to generate encrypted session data;

storing the encrypted session data in a memory of the computing device;

during a second browser session of the web browser, transmitting a cryptographic key request to a server, the second browser session being associated with the session ID;

responsive to the cryptographic key request, receiving a second cryptographic key from the server;

retrieving the encrypted session data from the memory; and

decrypting the encrypted session data using the second cryptographic key.

16. The method as recited in claim 15 , further comprising:

determining whether the second cryptographic key is configured to decrypt the encrypted session data;

wherein decrypting the encrypted session data using the second cryptographic key is performed in response to determining that the second cryptographic key is configured to decrypt the encrypted session data.

17. The method as recited in claim 16 , wherein determining whether the second cryptographic key is configured to decrypt the encrypted session data comprises:

decrypting an encrypted sentinel value with the second cryptographic key.

18. The method as recited in claim 15 , wherein the memory comprises an indexed database, and wherein the encrypted session data is stored in the indexed database.

19. The method as recited in claim 15 , wherein the memory comprises a browser cache, and wherein the encrypted session data is stored in the browser cache.

20. The method as recited in claim 15 , the method further comprising:

transmitting, by a second browser instance associated with the second browser session, the second cryptographic key to a first browser instance associated with the first browser session.

Assignments (2)
CHANGE OF NAME Recorded Nov 21, 2024
From: SALESFORCE.COM, INC.
To: SALESFORCE, INC.
Reel/Frame 069431/0179 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 30, 2019
From: VENKITESWARAN, KEVIN; GROBATY, SERGEY; YAO, BOB; BLISS, TREVOR JAMES
To: SALESFORCE.COM, INC.
Reel/Frame 049325/0308 →
Continuity (2)
Provisional Application 62415632 · Nov 1, 2016
Related Publication 20180124027A1 · May 3, 2018