IP Library › Granted Patent US 12,549,525
Granted Patent B2
US 12,549,525 · App. 17/963,379 · Granted Feb 10, 2026

Enhancing security of sensitive data in HTTP/2 and HTTP/3 connections

Inventors: Leonid Rodniansky (Allston, MA); Tania Butovsky (Needham, MA); Mikhail Shpak (New York, NY)
Assignee: International Business Machines Corporation
H04L63/0428H04L63/168H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,549,525
App. No.
17/963,379
Granted
Feb 10, 2026
Kind
B2
Abstract

An approach is disclosed for processing one or more HTTP requests and responses, by a protection solution, where a version of the plurality of HTTP requests and responses is at least version 2. When an HTTP settings request is detected in the one or more HTTP requests, by the protection solution, a protected dynamic dictionary is allocated in a protected memory area and an allocation of an application dynamic dictionary in application space in an HTTP server is prevented. When an HTTP header request is detected in the one or more HTTP requests, fields of the HTTP header are decompressed into the protected dynamic dictionary, the HTTP header request is updated to form an updated header request based on content in the protected dynamic dictionary, and the updated header request is sent to the HTTP server.

Claims (53)

1 . A method for enhancing security of sensitive data in Hypertext Transfer Protocol (HTTP) connections comprising:

processing a plurality of HTTP requests and responses, by a protection solution,

wherein a version of the plurality of HTTP requests and responses is at least version 2;

responsive to detecting an HTTP settings request in the plurality of HTTP requests, by the protection solution,

allocating a protected dynamic dictionary in a protected memory area and preventing allocation of an application dynamic dictionary in application space in an HTTP server; and

responsive to detecting an HTTP header request in the plurality of HTTP requests,

decompressing fields of the HTTP header into the protected dynamic dictionary, updating the HTTP header request to form an updated header request based on content in the protected dynamic dictionary, and sending the updated header request to the HTTP server.

2 . The method of claim 1 , wherein the version of the plurality of HTTP requests and responses is selected from a group consisting of HTTP/2, HTTP/3, and a higher version utilizing header compression.

3 . The method of claim 2 , wherein the higher version utilizes QPACK.

4 . The method of claim 2 , wherein the higher version utilizes HPACK.

5 . The method of claim 1 , wherein the protected dynamic dictionary is allocated from an encrypted area of memory.

6 . The method of claim 1 , wherein the protection solution further comprises:

receiving the plurality of HTTP requests from a Transport Layer Security (TLS) terminator.

7 . The method of claim 6 , wherein the TLS terminator runs as in application in the HTTP server and sends the plurality of decrypted HTTP requests to the protection solution.

8 . The method of claim 1 , wherein the preventing allocation of the application dynamic dictionary in application space in the HTTP server is performed by setting a SETTINGS_MAX_HEADER_LIST_SIZE variable to zero in the HTTP header request.

9 . The method of claim 1 , wherein the processing of the plurality of HTTP requests further comprises:

receiving a plurality of HTTPS requests; and

decrypting the plurality of HTTPS requests to form the plurality of HTTP requests.

10 . The method of claim 1 , further comprising:

analyzing the plurality of HTTP requests and responses to associate a current HTTP request with a current destination for the current HTTP request;

comparing the current destination to a supported set of destinations; and

responsive to determining the current destination is not in the supported set of destinations,

forwarding the current HTTP request to the destination without modifying the current HTTP request;

responsive to determining the current destination is in the supported set of destinations,

checking for an allocation of the protected dynamic dictionary associated with the current destination;

responsive to determining an absence of the allocation of the protected dynamic dictionary associated with the current destination,

allocating the protected dynamic dictionary associated with the current destination and ensuring the current destination does not directly utilize a dynamic dictionary; and

processing the current HTTP request utilizing the protected dynamic dictionary associated with the current destination when the current destination is in the supported set of destinations.

11 . The method of claim 10 , wherein the utilizing of the protected dynamic dictionary associated with the current destination further comprises:

adding selected entries from a current header of the current HTTP request to the dynamic dictionary if needed;

updating the current header of the current HTTP request from the dynamic dictionary to form an updated current HTTP request; and

forwarding the updated current HTTP request to the current destination.

12 . An information handling system for enhancing security of sensitive data in Hypertext Transfer Protocol (HTTP) connections comprising:

one or more processors;

a memory coupled to at least one of the processors;

a network interface that connects the local device to one or more remote web sites; and

a set of computer program instructions stored in the memory and executed by at least one of the processors in order to perform actions comprising:

processing a plurality of HTTP requests and responses, by a protection solution, wherein a version of the plurality of HTTP requests and responses is at least version 2;

responsive to detecting an HTTP settings request in the plurality of HTTP requests, by the protection solution,

allocating a protected dynamic dictionary in a protected memory area and preventing allocation of an application dynamic dictionary in application space in an HTTP server; and

responsive to detecting an HTTP header request in the plurality of HTTP requests, decompressing fields of the HTTP header into the protected dynamic dictionary, updating the HTTP header request to form an updated header request based on content in the protected dynamic dictionary, and sending the updated header request to the HTTP server.

13 . The information handling system of claim 12 , wherein the version of the plurality of HTTP requests and responses is selected from a group consisting of HTTP/2, HTTP/3, and a higher version utilizing header compression.

14 . The information handling system of claim 13 , wherein the higher version utilizes QPACK.

15 . The information handling system of claim 13 , wherein the higher version utilizes H PACK.

16 . A computer program product for enhancing security of sensitive data in Hypertext Transfer Protocol (HTTP) connections stored in a computer readable storage medium, comprising computer program code that, when executed by the computer program product, performs actions comprising:

processing a plurality of HTTP requests and responses, by a protection solution, wherein a version of the plurality of HTTP requests and responses is at least version 2;

responsive to detecting an HTTP settings request in the plurality of HTTP requests, by the protection solution,

allocating a protected dynamic dictionary in a protected memory area and preventing allocation of an application dynamic dictionary in application space in an HTTP server; and

responsive to detecting an HTTP header request in the plurality of HTTP requests, decompressing fields of the HTTP header into the protected dynamic dictionary, updating the HTTP header request to form an updated header request based on content in the protected dynamic dictionary, and sending the updated header request to the HTTP server.

17 . The computer program product of claim 16 , wherein the version of the plurality of HTTP requests and responses is selected from a group consisting of HTTP/2, HTTP/3, and a higher version utilizing header compression.

18 . The computer program product of claim 17 , wherein the higher version utilizes QPACK.

19 . The computer program product of claim 17 , wherein the higher version utilizes HPACK.

20 . The computer program product of claim 16 , wherein the protected dynamic dictionary is allocated from an encrypted area of memory.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 11, 2022
From: RODNIANSKY, LEONID; BUTOVSKY, TANIA; SHPAK, MIKHAIL
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 061384/0371 →
Continuity (1)
Related Publication 20240121223A1 · Apr 11, 2024
References Cited (31)
US 6519647B1 · Howard et al. · 2003 [cited by applicant]
US 9021605B2 · Blue et al. · 2015 [cited by applicant]
US 9177174B1 · Shoemaker et al. · 2015 [cited by applicant]
US 9317851B2 · Little, Jr. et al. · 2016 [cited by applicant]
US 10846689B2 · Matthews et al. · 2020 [cited by applicant]
US 10904218B2 · Muttik · 2021 [cited by applicant]
US 11799750B1 · Prasad · 2023 [cited by examiner]
US 20050114672A1 · Duncan et al. · 2005 [cited by applicant]
US 20060048224A1 · Duncan et al. · 2006 [cited by applicant]
US 20090055889A1 · Carlson et al. · 2009 [cited by applicant]
US 20180288017A1 · Stephan · 2018 [cited by examiner]
US 20200007501A1 · Jain · 2020 [cited by examiner]
US 20200128032A1 · Halme · 2020 [cited by examiner]
US 20220188437A1 · Butovsky et al. · 2022 [cited by applicant]
US 20230198964A1 · Viswambharan · 2023 [cited by examiner]
US 20250175194A1 · Narendra · 2025 [cited by examiner]
CN 114726564A · 2022 [cited by examiner]
miter.org, CVE—CVE-2012-4929, https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2012-4929 (Downloaded Jul. 26, 2022. [cited by applicant]
W3techs, Usage statistics of HTTP/2 for websites, https://w3techs.com/technologies/details/ce-http2 (Downloaded Jul. 26, 2022). [cited by applicant]
IBM, IBM Security Guardium solutions, https://www.ibm.com/guardium (Downloaded Jul. 26, 2022). [cited by applicant]
Sansec, NginRAT parasite targets Nginx, https://sansec.io/research/nginrat, Dec, 1, 2021. [cited by applicant]
miter.org, CWE—CWE-922: Insecure Storage of Sensitive Information, https://cwe.mitre.org/data/definitions/922.html (Downloaded Jul. 26, 2022). [cited by applicant]
miter.org, Cleartext Storage of Sensitive Information in Memory (4.8), https://cwe.mitre.org/data/definitions/316.html (Downloaded Jul. 26, 2022). [cited by applicant]
haprox.org, HAProxy—The Reliable, High Performance TCP/HTTP Load Balancer, HAProxy—The Reliable, High Performance TCP/HTTP Load Balancer, http://www.haproxy.org/ (Downloaded Jul. 26, 2022). [cited by applicant]
Contributers to Wikimedia Projects, HTTP/3, https://en.wikipedia.org/wiki/HTTP/3 (Downloaded Jul. 26, 2022). [cited by applicant]
Contributers to Wikimedia Projects, HTTP/2, https://en.wikipedia.org/wiki/HTTP/2 (Downloaded Jul. 26, 2022). [cited by applicant]
Contributers to Wikimedia Projects, Nginx, https://en.wikipedia.org/wiki/Nginx (Downloaded Jul. 26, 2022). [cited by applicant]
Contributers to Wikimedia Projects, CRIME, https://en.wikipedia.org/wiki/CRIME(Downloaded Jul. 26, 2022). [cited by applicant]
Vlad Krasnov, HPACK: the silent killer (feature) of HTTP/2, https://blog.cloudflare.com/hpack-the-silent-killer-feature-of-http-2/ , Nov. 28, 2016. [cited by applicant]
Miter Corporation, CWE-316: Cleartext Storage of Sensitive Information in Memory, https://cwe.mitre.org/data/definitions/316.html (Downloaded Oct. 7, 2022). [cited by applicant]
Imperva, HTTP/2: In-depth analysis of the top four flaws of the next generation web protocol, https//imperva.com/docs/Imperva_HII_HTTP2.pdf (downloaded Oct. 7, 2022). [cited by applicant]