IP Library Granted Patent US 10,841,276
Granted Patent B2
US 10,841,276 · App. 16/465,781 · Granted Nov 17, 2020

Method and system for carrying out a sensitive operation in the course of a communication session

Inventor: Didier Hugot (Gemenos, FR)
Assignee: THALES DIS FRANCE SA
H04L61/3025H04L61/1511H04L61/1552H04L63/1466H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,841,276
App. No.
16/465,781
Granted
Nov 17, 2020
Kind
B2
Abstract

The invention relates to a method for carrying out a sensitive operation in the course of a communication between a processing unit and a first service server, said first server being accessible via a first domain name and/or first electronic address. The method comprises the step of using at least one second domain name different from the first and/or a second electronic address different from the first to carry out all or part of the sensitive operation. The invention also relates to a system corresponding to the method and comprising the server and/or the processing unit.

Claims (26)

1. A method for carrying out a sensitive operation in the course of a communication between a processing unit and a first service server, said first server being accessible via a first domain name and/or a first electronic address,

the method comprises the step of using at least one second domain name different from the first domain name, and/or a second electronic address different from the first electronic address, in the course of all or part of said sensitive operation,

wherein the method implements a cross-domain sharing mechanism or steps to enable the server and/or service application to share the same user session on at least two domain names and/or at least two electronic addresses,

wherein the server and/or the processing unit implement instructions from a program or steps configured to trigger at an appropriate time a cross-domain and/or cross-address browsing and carry out all or part of said sensitive operation outside the first domain name and/or outside the first address, and

wherein the trigger is based on a level of risk threshold.

2. A method according to claim 1 , wherein the method implements cross-domain session cookies.

3. A method according to claim 1 , wherein the second domain name is an anonymous type.

4. A method according to claim 1 , wherein the first and second electronic addresses are different or identical, the domain names being different from each other.

5. A method according to claim 1 , wherein the domain names and/or the electronic addresses are part of a set of domain names and/or electronic addresses pointing to the same site or web page of the server and the number of which is greater than two, the domain names and/or the electronic addresses being renewed regularly.

6. A method according to claim 5 , wherein the set of domain names includes a number of domain names greater than 10.

7. A system for carrying out a sensitive operation in the course of a communication between a processing unit and a first service server, said first server being accessible via a first domain name and/or a first electronic address,

comprising a non-transitory computer-readable medium encoded with a micro-code or program, comprising instructions configured to use at least a second domain name different from the first domain name and/or a second electronic address different from the first address, in the course of all or part of said sensitive operation,

the system further comprising a software mechanism for sharing cross-domain sessions to enable the server and/or service application to share the same user session on at least two domain names and/or at least two electronic addresses,

wherein the first service server and/or the processing unit implements instructions from said micro-code or program configured to trigger at an appropriate time a cross-domain and/or cross-address browsing and carry out all or part of said sensitive operation outside the first domain name and/or outside the first address, and

wherein the trigger is based on a level of risk threshold.

8. A system according to claim 7 , wherein the domain names and/or the electronic addresses are part of a set of domain names and/or electronic addresses pointing to the same site or web page of the server, the set comprising a number of domain names and/or electronic addresses greater than ten.

9. A processing unit for carrying out a sensitive operation with a first service server having a first domain name and/or a first electronic address,

comprising a program, or micro-code with instructions configured to use at least a second domain name different from the first domain name and/or a second electronic address different from the first address, in the course of all or part of said sensitive operation,

the processing unit further comprising a program, or micro-code with instructions for sharing cross-domain sessions to enable the server and/or service application to share the same user session on at least two domain names and/or at least two electronic addresses,

wherein the processing unit implements instructions from a program or steps configured to trigger at an appropriate time a cross-domain and/or cross-address browsing and carry out all or part of said sensitive operation outside the first domain name and/or outside the first address, and

wherein the trigger is based on a level of risk threshold.

10. A service server having a first domain name and/or a first electronic address and having a hardware and/or software configuration to carry out a sensitive operation in the course of a communication with a processing unit,

comprising a non-transitory computer-readable medium encoded with a program comprising or generating micro-code instructions configured to use at least a second domain name different from the first domain name and/or a second electronic address different from the first address, in the course of all or part of said sensitive operation,

the service server further comprising a program, or micro-code with instructions for sharing cross-domain sessions to enable the server and/or service application to share the same user session on at least two domain names and/or at least two electronic addresses,

wherein the service server implements instructions from a program or steps configured to trigger at an appropriate time a cross-domain and/or cross-address browsing and carry out all or part of said sensitive operation outside the first domain name and/or outside the first address, and

wherein the trigger is based on a level of risk threshold.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 28, 2023
From: THALES DIS FRANCE SA
To: THALES DIS FRANCE SAS
Reel/Frame 064730/0766 →
CHANGE OF NAME Recorded Sep 15, 2020
From: GEMALTO SA
To: THALES DIS FRANCE SA
Reel/Frame 053773/0332 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 18, 2019
From: HUGOT, DIDIER
To: GEMALTO SA
Reel/Frame 050757/0079 →