IP Library Granted Patent US 11,784,983
Granted Patent B1
US 11,784,983 · App. 17/181,749 · Granted Oct 10, 2023

SSL encryption with reduced bandwidth

Inventors: Santosh Nichani (Secunderabad, IN); Ramanathan Ramanathan (Bellevue, WA); Srinivas Vengala (Secunderabad, IN); Sri Rajesh Rayudu (Hyderabad, IN); Rameshchandra Bhaskar Ketharaju (Hyderabad, IN); Shanmukeswara Rao Donkada (Hyderabad, IN)
Assignee: Wells Fargo Bank, N.A.
H04L63/0428H04L63/166H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,784,983
App. No.
17/181,749
Granted
Oct 10, 2023
Kind
B1
Abstract

Systems and methods provide for a solution for encryption by dynamically opening multiple channels between the client and the server, where the channels include both secured (e.g., SSL/TLS and etc.) channels and non-secured channels. Non-sensitive information can be over non-secured channels, and sensitive information can be sent via the secured channels. The system can recognize whether the information is sensitive or not via the use of tags on a page or frame that delineate which information is sensitive. For instance, on a form, tags can mark off the areas of the form that may contain sensitive information, such as social security numbers, names, addresses, financial information, and other private information. All the data within the tags can be considered sensitive and so be communicated to the server via a secure channel while other data can be transmitted through unsecured channels.

Claims (35)

1. A system, comprising:

a processor coupled to a memory that stores instructions that, when executed by the processor, cause the processor to:

identify static data and dynamic data of a set of data, wherein the dynamic data changes between frames or sessions;

classify the static data as non-sensitive data and the dynamic data as sensitive data based on one or more tags associated with the dynamic data;

determine a security policy based on the one or more tags; and

initiate transmission to a network entity of the non-sensitive data on an unsecure communication channel and the sensitive data on a secure communication channel in accordance with the security policy.

2. The system of claim 1 , wherein the instructions further cause the processor to initiate the transmission of the sensitive data based on a security policy that specifies one or more rules regarding the sensitive data.

3. The system of claim 2 , wherein at least one of the one or more rules specify encryption type for the sensitive data.

4. The system of claim 2 , wherein at least one of the one or more rules specify access rights to the sensitive data.

5. The system of claim 1 , wherein the instructions further cause the processor to identify a type of the sensitive data.

6. The system of claim 5 , wherein the instructions further cause the processor to identify the type of the sensitive data based on a tag associated with the sensitive data.

7. The system of claim 5 , wherein the instructions further cause the processor to identify the type of the sensitive data based on determining a form of the sensitive data.

8. The system of claim 5 , wherein the instructions further cause the processor to vary one of encryption or communication channel based on the type of the sensitive data.

9. The system of claim 1 , wherein the static data comprises page layout, style, or template information.

10. The system of claim 1 , wherein the dynamic data comprises name, address, or financial information.

11. A method, comprising:

identifying static data and dynamic data in a set of data, wherein the dynamic data changes between frames or sessions;

classifying the static data as non-sensitive data and the dynamic data as sensitive data based on one or more tags associated with the dynamic data;

opening at least one secure communication channel and at least one unsecure communication channel to a network entity;

determining a security policy based on the one or more tags; and

initiating transmission, to the network entity, of the non-sensitive data over the unsecure communication channel and the sensitive data over the secure communication channel in accordance with the security policy.

12. The method of claim 11 , further comprising initiating transmission of the sensitive data based on a security policy that specifies one or more rules associated with the sensitive data.

13. The method of claim 12 , further comprising initiating encryption of the sensitive data based on a rule of the one or more rules that specifies an encryption scheme for the sensitive data.

14. The method of claim 12 , further comprising setting access rights for the sensitive data based on a rule of the one or more rules.

15. The method of claim 12 , further comprising varying employment of at least one of encryption or communication channel based on a type of the sensitive data.

16. The method of claim 15 , further comprising identifying the type of the sensitive data based on a tag associated with the sensitive data.

17. The method of claim 15 , further comprising identifying the type of the sensitive data based on one or more features of the sensitive data.

18. A computer-readable storage medium that stores instruction that, when executed by a processor, cause the processor to perform operations, comprising:

identifying static data and dynamic data in a set of data, wherein the dynamic data changes between frames or sessions;

classifying the static data as non-sensitive data and the dynamic data as sensitive data based on one or more tags associated with the dynamic data;

determining a security policy based on the one or more tags;

establishing at least one secure communication channel and at least one unsecure communication channel to a network entity; and

initiating transmission to the network entity of the non-sensitive data on the unsecure communication channel and the sensitive data on the secure communication channel in accordance with the security policy.

19. The computer-readable storage medium of claim 18 , the operations further comprising initiating transmission of the sensitive data based on a security policy that specifies one or more rules associated with the sensitive data.

20. The computer-readable storage medium of claim 19 , the operations further comprising varying employment of at least one of encryption or communication channel based on a determined type of the sensitive data.

Assignments (2)
ADDRESS CHANGE Recorded Jun 2, 2025
From: WELLS FARGO BANK, N.A.
To: WELLS FARGO BANK, N.A.
Reel/Frame 071769/0143 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 1, 2021
From: NICHANI, SANTOSH; DONKADA, SHANMUKESWARA RAO; KETHARAJU, RAMESHCHANDRA BHASKAR; RAMANATHAN, RAMANATHAN; VENGALA, SRINIVAS
To: WELLS FARGO BANK, N.A.
Reel/Frame 055442/0459 →
Continuity (1)
Continuation 15385001 · Dec 20, 2016