IP Library Granted Patent US 12,242,595
Granted Patent B2
US 12,242,595 · App. 17/979,648 · Granted Mar 4, 2025

Data management using secure browsers

Inventor: Akshay Joshi (Ottawa, CA)
Assignee: Stripe, Inc.
G06F21/53G06F21/577G06F16/958G06F16/972G06F21/62G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,242,595
App. No.
17/979,648
Granted
Mar 4, 2025
Kind
B2
Abstract

Various embodiments described herein support or provide for data management operations, such as receiving a request to access a webpage; determining that accessing the webpage requires secure access via a secure browser; identifying a virtual machine that is configured to allow access to the webpage; and causing display of the webpage in the secure browser embedded in a local browser of the sender device.

Claims (46)

1. A method comprising:

receiving, from a sender device, a request to access a webpage;

determining that accessing the webpage requires secure access via a secure browser, the secure access being associated with a security policy;

identifying a virtual machine that is configured to allow access to the webpage, the virtual machine directly managing a preconfigured directory that is provided by the security policy;

causing display of the webpage in the secure browser embedded in a local browser of the sender device, the secure browser being provided by the virtual machine;

detecting that data associated with the webpage is returned from the webpage displayed in the secure browser embedded in the local browser; and

causing the data to be saved in a virtual memory associated with the virtual machine instead of a local memory of the sender device.

2. The method of claim 1 , wherein the security policy disables one or more commands to prevent data exchanged via the secure browser from being accessed by the sender device.

3. The method of claim 2 , wherein the one or more commands include one or more of: copy command, paste command, cut command, and save command.

4. The method of claim 1 , wherein the security policy provides the preconfigured directory to store a first file to be uploaded to the webpage and to receive a second file returned from the webpage, the preconfigured directory being configured to prevent access by the sender device.

5. The method of claim 4 , wherein uploading of the first file to the webpage and downloading of the second file may be performed automatically or manually by a user of the sender device.

6. The method of claim 1 , further comprising:

providing the sender device with a Uniform Resource Locator (URL) based on the request to access the webpage;

detecting an activation of the URL by the sender device; and

in response to detecting the activation of the URL, causing display of the webpage in the secure browser embedded in the local browser of the sender device based on the security policy.

7. The method of claim 1 , wherein the preconfigured directory comprises a virtual data storage associated with the virtual machine in a cloud computing platform, and wherein the sender device cannot access files stored in the preconfigured directory.

8. A system comprising:

at least one memory storing instructions; and

one or more hardware processors communicatively coupled to the at least one memory and configured by the instructions to perform operations comprising:

receiving, from a sender device, a request to access a webpage;

determining that accessing the webpage requires secure access via a secure browser, the secure access being associated with a security policy;

identifying a virtual machine that is configured to allow access to the webpage, the virtual machine directly managing a preconfigured directory that is provided by the security policy;

causing display of the webpage in the secure browser embedded in a local browser of the sender device, the secure browser being provided by the virtual machine;

detecting that data associated with the webpage is returned from the webpage displayed in the secure browser embedded in the local browser; and

causing the data to be saved in a virtual memory associated with the virtual machine instead of a local memory of the sender device.

9. The system of claim 8 , wherein the security policy disables one or more commands to prevent data exchanged via the secure browser from being accessed by the sender device.

10. The system of claim 9 , wherein the one or more commands include one or more of: copy command, paste command, cut command, and save command.

11. The system of claim 8 , wherein the security policy provides the preconfigured directory to store a first file to be uploaded to the webpage and to receive a second file returned from the webpage, the preconfigured directory being configured to prevent access by the sender device.

12. The system of claim 11 , wherein uploading of the first file to the webpage and downloading of the second file may be performed automatically or manually by a user of the sender device.

13. The system of claim 8 , wherein the preconfigured directory comprises a virtual data storage associated with the virtual machine in a cloud computing platform, and wherein the sender device cannot access files stored in the preconfigured directory.

14. The system of claim 8 , wherein the operations further comprise:

providing the sender device with a Uniform Resource Locator (URL) based on the request to access the webpage;

detecting an activation of the URL by the sender device; and

in response to detecting the activation of the URL, causing display of the webpage in the secure browser embedded in the local browser of the sender device based on the security policy.

15. A non-transitory computer-readable medium comprising instructions that, when executed by a hardware processor of a device, cause the device to perform operations comprising:

receiving, from a sender device, a request to access a webpage;

determining that accessing the webpage requires secure access via a secure browser, the secure access being associated with a security policy;

identifying a virtual machine that is configured to allow access to the webpage, the virtual machine directly managing a preconfigured directory that is provided by the security policy;

causing display of the webpage in the secure browser embedded in a local browser of the sender device, the secure browser being provided by the virtual machine;

detecting that data associated with the webpage is returned from the webpage displayed in the secure browser embedded in the local browser; and

causing the data to be saved in a virtual memory associated with the virtual machine instead of a local memory of the sender device.

16. The non-transitory computer-readable medium of claim 15 , wherein the security policy disables one or more commands to prevent data exchanged via the secure browser from being accessed by the sender device.

17. The non-transitory computer-readable medium of claim 16 , wherein the one or more commands include one or more of: copy command, paste command, cut command, and save command.

18. The non-transitory computer-readable medium of claim 15 , wherein the security policy provides the preconfigured directory to store a first file to be uploaded to the webpage and to receive a second file returned from the webpage, the preconfigured directory being configured to prevent access by the sender device.

19. The non-transitory computer-readable medium of claim 18 , wherein uploading of the first file to the webpage and downloading of the second file may be performed automatically or manually by a user of the sender device.

20. The non-transitory computer-readable medium of claim 15 , wherein the preconfigured directory comprises a virtual data storage associated with the virtual machine in a cloud computing platform, and wherein the sender device cannot access files stored in the preconfigured directory.

Assignments (2)
CHANGE OF NAME Recorded Jan 30, 2026
From: STRIPE, INC.
To: STRIPE, LLC
Reel/Frame 074572/0345 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 2, 2022
From: JOSHI, AKSHAY
To: STRIPE, INC.
Reel/Frame 061637/0298 →
Continuity (1)
Related Publication 20240143735A1 · May 2, 2024
References Cited (6)
US 11803635B2 · Wing · 2023 [cited by examiner]
US 20200089898A1 · Borkar · 2020 [cited by examiner]
US 20220342981A1 · Wing · 2022 [cited by examiner]
US 20220360607A1 · Amiga · 2022 [cited by examiner]
“Browser Security Explained: Threats and Defensive Measures”—Perception Point, Industry Insights, Aug. 11, 2022 https://perception-point.io/blog/browser-security-threats-solutions-user-education/ (Year: 2022). [cited by examiner]
“Secure Browser to Stay Private and Safe in 2022”—Theme Circle, Mar. 2022 https://www.themecircle.net/secure-browser-stay-private-safe-2022/ (Year: 2022). [cited by examiner]