IP Library Granted Patent US 11,038,863
Granted Patent B2
US 11,038,863 · App. 16/557,547 · Granted Jun 15, 2021

Facilitating encrypted persistent storage in browsers

Inventors: Kevin Venkiteswaran (Alameda, CA); Sergey Gorbaty (Emeryville, CA); Bob Yao (Daly City, CA); Trevor James Bliss (Oakland, CA)
Assignee: salesforce.com, inc.
H04L63/061G06F16/957G06F21/60G06F21/6209G06F21/6263H04L63/0428H04L67/1027H04L67/142H04L67/146
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,038,863
App. No.
16/557,547
Granted
Jun 15, 2021
Kind
B2
Abstract

Disclosed are some implementations of systems, apparatus, methods and computer program products for encrypting and securely storing session data during a browser session using a session-based cryptographic key. The session data may be decrypted during the browser session or other browser sessions using the session-based cryptographic key or other backwards compatible session-based cryptographic keys. In addition, session-based cryptographic keys may be shared among browser sessions to enable encrypted session data to be decrypted across page refreshes and browser tabs.

Claims (80)

1. A computer program product comprising one or more non-transitory computer-readable media having computer program instructions stored therein, the computer program instructions capable of being executed by one or more processors, the computer program instructions configurable to cause:

during a first browser session of a web browser situated at a computing device:

obtaining a first cryptographic key;

obtaining session data;

applying, at the computing device, the first cryptographic key to the session data to generate encrypted session data; and

storing the encrypted session data in a memory of the computing device, the first browser session being associated with a session identifier (ID); and

during a second browser session of the web browser:

obtaining a second cryptographic key;

retrieving the encrypted session data from the memory; and

decrypting, at the computing device, the encrypted session data using the second cryptographic key, the second browser session being associated with the session ID.

2. The computer program product as recited in claim 1 , the computer program instructions further configurable to cause:

determining whether the second cryptographic key is configured to decrypt the encrypted session data;

wherein decrypting the encrypted session data using the second cryptographic key is performed in response to determining that the second cryptographic key is configured to decrypt the encrypted session data.

3. The computer program product as recited in claim 2 , wherein determining whether the second cryptographic key is configured to decrypt the encrypted session data comprises:

decrypting an encrypted sentinel value with the second cryptographic key.

4. The computer program product as recited in claim 1 , the computer program instructions configurable to cause:

transmitting, by a second browser instance associated with the second browser session, the second cryptographic key to a first browser instance associated with the first browser session.

5. The computer program product as recited in claim 1 , the computer program instructions further configurable to cause:

obtaining the second cryptographic key from a first browser instance associated with the first browser session.

6. The computer program product as recited in claim 1 , the computer program instructions further configurable to cause:

during the second browser session,

obtaining second session data;

applying the second cryptographic key to the second session data to generate encrypted second session data; and

storing the encrypted second session data in the memory;

wherein the first cryptographic key cannot be used to decrypt the encrypted second session data.

7. The computer program product as recited in claim 1 , the session ID being associated with a main authentication session related to the first and second browser sessions.

8. The computer program product as recited in claim 1 , the first cryptographic key being different from the second cryptographic key.

9. A computing device comprising:

a memory; and

a processor configurable to cause:

during a first browser session of a web browser situated at the computing device:

obtaining a first cryptographic key;

obtaining session data;

applying, at the computing device, the first cryptographic key to the session data to generate encrypted session data; and

storing the encrypted session data in the memory, the first browser session being associated with a session identifier (ID); and

during a second browser session of the web browser:

obtaining a second cryptographic key;

retrieving the encrypted session data from the memory; and

decrypting, at the computing device, the encrypted session data using the second cryptographic key, the second browser session being associated with the session ID.

10. The computing device as recited in claim 9 , the processor further configurable to cause:

determining whether the second cryptographic key is configured to decrypt the encrypted session data;

wherein decrypting the encrypted session data using the second cryptographic key is performed in response to determining that the second cryptographic key is configured to decrypt the encrypted session data.

11. The computing device as recited in claim 10 , wherein determining whether the second cryptographic key is configured to decrypt the encrypted session data comprises:

decrypting an encrypted sentinel value with the second cryptographic key.

12. The computing device as recited in claim 9 , the processor configurable to cause:

transmitting, by a second browser instance associated with the second browser session, the second cryptographic key to a first browser instance associated with the first browser session.

13. The computing device as recited in claim 9 , the processor further configurable to cause:

obtaining the second cryptographic key from a first browser instance associated with the first browser session.

14. The computing device as recited in claim 9 , the processor further configurable to cause:

during the second browser session,

obtaining second session data;

applying the second cryptographic key to the second session data to generate encrypted second session data; and

storing the encrypted second session data in the memory;

wherein the first cryptographic key cannot be used to decrypt the encrypted second session data.

15. The computing device as recited in claim 9 , the session ID being associated with a main authentication session related to the first and second browser sessions.

16. A method, comprising:

during a first browser session of a web browser situated at a computing device:

obtaining a first cryptographic key;

obtaining session data;

applying, at the computing device, the first cryptographic key to the session data to generate encrypted session data; and

storing the encrypted session data in a memory of the computing device, the first browser session being associated with a session identifier (ID); and

during a second browser session of the web browser:

obtaining a second cryptographic key;

retrieving the encrypted session data from the memory; and

decrypting, at the computing device, the encrypted session data using the second cryptographic key, the second browser session being associated with the session ID.

17. The method as recited in claim 16 , further comprising:

determining whether the second cryptographic key is configured to decrypt the encrypted session data;

wherein decrypting the encrypted session data using the second cryptographic key is performed in response to determining that the second cryptographic key is configured to decrypt the encrypted session data.

18. The method as recited in claim 17 , wherein determining whether the second cryptographic key is configured to decrypt the encrypted session data comprises:

decrypting an encrypted sentinel value with the second cryptographic key.

19. The method as recited in claim 16 , further comprising:

transmitting, by a second browser instance associated with the second browser session, the second cryptographic key to a first browser instance associated with the first browser session.

20. The method as recited in claim 16 , further comprising:

obtaining the second cryptographic key from a first browser instance associated with the first browser session.

21. The method as recited in claim 16 , further comprising:

during the second browser session,

obtaining second session data;

applying the second cryptographic key to the second session data to generate encrypted second session data; and

storing the encrypted second session data in the memory;

wherein the first cryptographic key cannot be used to decrypt the encrypted second session data.

Assignments (1)
CHANGE OF NAME Recorded Jan 27, 2025
From: SALESFORCE.COM, INC.
To: SALESFORCE, INC.
Reel/Frame 070014/0841 →
Continuity (3)
Continuation 15482638 · Apr 7, 2017
Provisional Application 62415632 · Nov 1, 2016
Related Publication 20190386971A1 · Dec 19, 2019