IP Library Granted Patent US 11,929,992
Granted Patent B2
US 11,929,992 · App. 17/467,733 · Granted Mar 12, 2024

Encrypted cache protection

Inventors: Mark Willem Loman (Delden, NL); Lute Edwin Engels (Zuidwolde, NL); Ronny Henk Gert Tijink (Hengelo, NL); Victor Marinus Johann Simon van Hillo (Delden, NL); Alexander Vermaning (Enschede, NL); Jeroen Harmsen (Hengelo, NL)
Assignee: Sophos Limited
H04L63/0414H04L63/0435H04L63/102H04L63/105H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,929,992
App. No.
17/467,733
Granted
Mar 12, 2024
Kind
B2
Abstract

Secrets such as secure session cookies for a web browser can be protected on a compute instance with multiple layers of encryption, such as by encrypting key material that in turn controls cryptographic access to the secret. A compute instance can be instrumented to detect when a process attempts to decrypt this key material so that the process requesting decryption can be compared to authorized or legitimate users of the secret.

Claims (32)

1. A computer program product comprising computer executable code embodied in a non-transitory computer readable medium that, when executing on one or more computing devices, performs the steps of:

instrumenting a data protection application programming interface for an operating system on an endpoint to detect access to a decryption service used by the operating system to encrypt and decrypt data blobs using a master key derived from user credentials for the endpoint;

detecting a call from a process executing on the endpoint to the data protection application programming interface to unprotect a symmetric key used to cryptographically secure a web browser session cookie stored by a web browser application on the endpoint;

comparing first process information for the process to second process information for the web browser application that stored the web browser session cookie; and

in response to determining that the process is not associated with the web browser application, preventing the process from accessing the web browser session cookie with the symmetric key and initiating a remediation of the endpoint.

2. A method comprising:

instrumenting an application programming interface on a compute instance to detect access to a decryption service used by an operating system of the compute instance;

detecting a call from a first process executing on the compute instance to the application programming interface to unprotect a key used to cryptographically secure a secret on the compute instance;

comparing first process information for the first process to second process information for one or more other processes associated with the secret;

in response to determining that the first process is an authorized user of the secret, permitting the first process to decrypt the key for use in accessing the secret; and

in response to determining that the first process is not an authorized user of the secret, preventing the first process from decrypting the key for use in accessing the secret.

3. The method of claim 2 further comprising, when the first process is not an authorized user, initiating a remediation.

4. The method of claim 3 wherein the remediation includes terminating the first process.

5. The method of claim 3 wherein the remediation includes quarantining the compute instance.

6. The method of claim 3 wherein the remediation includes performing a malware scan.

7. The method of claim 3 wherein the remediation includes generating a beacon identifying the first process.

8. The method of claim 3 wherein the remediation includes performing a root cause analysis.

9. The method of claim 2 wherein the first process information includes one or more of a process name, a process identifier, an application name, and a path.

10. The method of claim 2 wherein the one or more other processes include at least one process associated with a web browser application.

11. The method of claim 2 wherein the one or more other processes include a process for an authorized application that stored the secret.

12. The method of claim 2 wherein the one or more other processes include a process for an application including one or more of a privacy cleaner and a backup utility.

13. The method of claim 2 wherein the secret includes a web browser session cookie.

14. The method of claim 2 wherein the secret includes logon credentials stored in an application cache and encrypted with the key.

15. The method of claim 2 wherein the secret includes one or more of a token, a cookie, a credential, and a cryptographic key.

16. The method of claim 2 wherein the decryption service encrypts and decrypts using a master key derived from user credentials for the compute instance.

17. The method of claim 2 wherein the application programming interface is a data protection application programming interface for the operating system.

18. The method of claim 2 wherein the application programming interface accesses decryption resources in a kernel of the operating system.

19. A compute instance comprising:

a memory in a user space of an operating system, the memory storing a first key encrypted with a master key derived from user credentials for the compute instance and a secret encrypted with the first key;

an application programming interface configured to provide programmatic access to cryptographic tools of the operating system based on the master key; and

a security function hooked to the application programming interface, the security function configured to detect a request to decrypt the first key with the application programming interface, and to determine whether a process requesting decryption of the first key is an authorized user of the secret.

20. The compute instance of claim 19 wherein the secret is a web browser session cookie and wherein the security function is configured to detect whether the process is associated with a web browser that stored the web browser session cookie.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 9, 2021
From: LOMAN, MARK WILLEM; ENGELS, LUTE EDWIN; TIJINK, RONNY HENK GERT; VAN HILLO, VICTOR MARINUS JOHANN SIMON; VERMANING, ALEXANDER; HARMSEN, JEROEN
To: SOPHOS LIMITED
Reel/Frame 057558/0907 →
Continuity (2)
Provisional Application 63168654 · Mar 31, 2021
Related Publication 20220321540A1 · Oct 6, 2022