IP Library Granted Patent US 11,562,092
Granted Patent B1
US 11,562,092 · App. 17/706,361 · Granted Jan 24, 2023

Loading and managing third-party tools on a website

Inventors: Yair Dovrat (Brussels, BE); Yoav Moshe (Amsterdam, NL)
Assignee: CLOUDFLARE, INC.
G06F21/6218H04L63/0428
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,562,092
App. No.
17/706,361
Granted
Jan 24, 2023
Kind
B1
Abstract

Managing the loading of third-party tools on a website is described. Configuration is received for loading the third-party tools. An intermediary server receives a request for a page that is hosted at an origin server. The intermediary server retrieves the page and modifies the page including automatically including a third-party tool manager to the retrieved page. The third-party tool manager includes a set of one or more client-side scripts that, when executed by the client network application, collects and transmits information to the intermediary server for loading the third-party tools. The intermediary server loads the third-party tools based on the received information and the configuration. The intermediary server causes event data to be transmitted to third-party tool servers that correspond with the third-party tools.

Claims (32)

1. A method, comprising:

receiving configuration for loading a plurality of third-party tools of a plurality of third-party tool providers for a website, wherein the received configuration includes a data loss prevention rule;

receiving, at an intermediary server from a client network application of a client device, a request for a page of the website, wherein the web site is hosted at an origin server;

retrieving, by the intermediary server, the page;

modifying, by the intermediary server, the retrieved page by automatically including a third-party tool manager to the retrieved page, wherein the third-party tool manager includes a set of one or more client-side scripts that, when executed by the client network application of the client device, transmits information to the intermediary server for loading the plurality of third-party tools;

receiving, from the client network application via the third-party tool manager, information for loading the plurality of third-party tools;

scanning the received information and determining that there is a violation of the data loss prevention rule, and responsive to this determination, obfuscating data of the received information that is in violation of the data loss;

loading the plurality of third-party tools based on the received information including the obfuscated data and the configuration; and

causing event data to be transmitted to a plurality of third-party tool servers that correspond with the plurality of third-party tools.

2. The method of claim 1 , wherein causing event data to be transmitted to at least one of the plurality of third-party tool servers includes the intermediary server transmitting the event data to that third-party tool server using an application programming interface (API) provided by the third-party tool server provider of that third-party tool.

3. The method of claim 1 , wherein causing event data to be transmitted to at least one of the plurality of third-party tool servers includes constructing a URL with the event data to be transmitted to that third-party tool server and transmitting an optimized client-side script to the client network application that, when executed by the client network application, transmits the event data to that third-party tool server.

4. The method of claim 1 , wherein the page does not include the plurality of third-party tools.

5. The method of claim 1 , wherein the received configuration includes a setting that defines a specific geolocation or region in which decryption of traffic is permitted to occur.

6. The method of claim 1 , wherein the intermediary server is in a first data center, and wherein the first data center is one of a plurality of data centers that each include a set of one or more intermediary servers, and wherein the received configuration includes a setting that defines that only an intermediary server that is located in a same data center to which the client network application connects is permitted to load the plurality of third-party tools based on the received information and the configuration.

7. The method of claim 1 , wherein the received information includes a screen resolution of the client network application.

8. The method of claim 1 , wherein the received information is received as a result of a configured interaction occurring with the page.

9. A non-transitory machine-readable storage medium that provides instructions that, if executed by a processor, will cause said processor to carry out operations comprising:

receiving configuration for loading a plurality of third-party tools of a plurality of third-party tool providers for a website, wherein the received configuration includes a data loss prevention rule;

receiving, at an intermediary server from a client network application of a client device, a request for a page of the website, wherein the web site is hosted at an origin server;

retrieving, by the intermediary server, the page;

modifying, by the intermediary server, the retrieved page by automatically including a third-party tool manager to the retrieved page, wherein the third-party tool manager includes a set of one or more client-side scripts that, when executed by the client network application of the client device, transmits information to the intermediary server for loading the plurality of third-party tools;

receiving, from the client network application via the third-party tool manager, information for loading the plurality of third-party tools;

scanning the received information and determining that there is a violation of the data loss prevention rule, and responsive to this determination, obfuscating data of the received information that is in violation of the data loss;

loading the plurality of third-party tools based on the received information including the obfuscated data and the configuration; and

causing event data to be transmitted to a plurality of third-party tool servers that correspond with the plurality of third-party tools.

10. The non-transitory machine-readable storage medium of claim 9 , wherein causing event data to be transmitted to at least one of the plurality of third-party tool servers includes the intermediary server transmitting the event data to that third-party tool server using an application programming interface (API) provided by the third-party tool server provider of that third-party tool.

11. The non-transitory machine-readable storage medium of claim 9 , wherein causing event data to be transmitted to at least one of the plurality of third-party tool servers includes constructing a URL with the event data to be transmitted to that third-party tool server and transmitting an optimized client-side script to the client network application that, when executed by the client network application, transmits the event data to that third-party tool server.

12. The non-transitory machine-readable storage medium of claim 9 , wherein the page does not include the plurality of third-party tools.

13. The non-transitory machine-readable storage medium of claim 9 , wherein the received configuration includes a setting that defines a specific geolocation or region in which decryption of traffic is permitted to occur.

14. The non-transitory machine-readable storage medium of claim 9 , wherein the intermediary server is in a first data center, and wherein the first data center is one of a plurality of data centers that each include a set of one or more intermediary servers, and wherein the received configuration includes a setting that defines that only an intermediary server that is located in a same data center to which the client network application connects is permitted to load the plurality of third-party tools based on the received information and the configuration.

15. The non-transitory machine-readable storage medium of claim 9 , wherein the received information includes a screen resolution of the client network application.

16. The non-transitory machine-readable storage medium of claim 9 , wherein the received information is received as a result of a configured interaction occurring with the page.

Assignments (1)
SECURITY INTEREST Recorded May 20, 2024
From: CLOUDFLARE, INC.
To: CITIBANK, N.A.
Reel/Frame 067472/0246 →
Continuity (1)
Provisional Application 63265089 · Dec 7, 2021