IP Library Granted Patent US 12,261,885
Granted Patent B2
US 12,261,885 · App. 18/477,745 · Granted Mar 25, 2025

System and method for maintaining internet anonymity via client fingerprint

Inventor: Shawn Bracken (San Francisco, CA)
Assignee: Plaid Inc.
H04L63/166H04L41/0813H04L63/0428H04L63/10H04L67/01
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,261,885
App. No.
18/477,745
Granted
Mar 25, 2025
Kind
B2
Abstract

A system and method for altering client fingerprint that includes editing data components of network communication from a client device to a server, which comprises editing network protocol data from the client during negotiation of a cryptographic protocol; selectively enabling access to library components specified in the edited client network protocol data; and sending a client communication to the server using the edited client network protocol data.

Claims (62)

1. A method, comprising:

modifying a set of data components of a message received from a first device,

wherein the set of data components is modified from a first format associated with the first device to a second format associated with a second device,

wherein the message is a hello message,

wherein the modified set of data components establishes a fingerprint for the second device, and

wherein the fingerprint is associated with information that indicates a type of the second device;

selectively enabling access to library components specified in the modified set of data components of the message;

performing, based on the modified set of data components, negotiation of a cryptographic protocol; and

modifying, based on performing negotiation of the cryptographic protocol and based on the library components, ongoing communication from the first device.

2. The method of claim 1 , wherein modifying the ongoing communication comprises encrypting the ongoing communication based on the library components.

3. The method of claim 1 , wherein selectively enabling access to library components comprises enabling access to at least one of:

a first library associated with a compression method,

a second library associated with client point formats,

a third library associated with an application protocol related to the first device, or

a fourth library associated with an extension related to the first device.

4. The method of claim 1 , wherein the modification of the set of data components occurs during performing the negotiation of the cryptographic protocol.

5. The method of claim 1 , wherein modifying the set of data components comprises replacing a first cipher suite specified in the message with a second cipher suite associated with the second device.

6. A device, comprising:

one or more memories; and

one or more processors, coupled to the one or more memories, configured to:

modify a set of data components of a message received from a first device,

wherein the set of data components is modified from a first format associated with the first device to a second format associated with a second device,

wherein the message is a hello message,

wherein the modified set of data components establishes a fingerprint for the second device, and

wherein the fingerprint is associated with information that indicates a type of the second device;

selectively enable access to library components specified in the modified set of data components of the message;

perform, based on the modified set of data components, negotiation of a cryptographic protocol; and

modify, based on performing negotiation of the cryptographic protocol and based on the library components, ongoing communication from the first device.

7. The device of claim 6 , wherein the one or more processors, to modify the ongoing communication, are configured to encrypt the ongoing communication based on the library components.

8. The device of claim 6 , wherein the one or more processors, to selectively enable access to library components, are configured to enable access to at least one of:

a first library associated with a compression method,

a second library associated with client point formats,

a third library associated with an application protocol related to the first device, or

a fourth library associated with an extension related to the first device.

9. The device of claim 6 , wherein the modification of the set of data components occurs during performing the negotiation of the cryptographic protocol.

10. The device of claim 6 , wherein the one or more processors, to modify the set of data components, are configured to replace a first cipher suite specified in the message with a second cipher suite associated with the second device.

11. A non-transitory computer-readable medium storing a set of instructions, the set of instructions comprising:

one or more instructions that, when executed by one or more processors of a device, cause the device to:

modify a set of data components of a message received from a first device,

wherein the set of data components is modified from a first format associated with the first device to a second format associated with a second device,

wherein the message is a hello message,

wherein the modified set of data components establishes a fingerprint for the second device, and

wherein the fingerprint is associated with information that indicates a type of the second device;

selectively enable access to library components specified in the modified set of data components of the message;

perform, based on the modified set of data components, negotiation of a cryptographic protocol; and

modify, based on performing negotiation of the cryptographic protocol and based on the library components, ongoing communication from the first device.

12. The non-transitory computer-readable medium of claim 11 , wherein the one or more instructions, that cause the device to modify the ongoing communication, cause the device to encrypt the ongoing communication based on the library components.

13. The non-transitory computer-readable medium of claim 11 , wherein the one or more instructions, that cause the device to selectively enable access to library components, cause the device to enable access to at least one of:

a first library associated with a compression method,

a second library associated with client point formats,

a third library associated with an application protocol related to the first device, or

a fourth library associated with an extension related to the first device.

14. The non-transitory computer-readable medium of claim 11 , wherein the modification of the set of data components occurs during performing the negotiation of the cryptographic protocol.

15. The method of claim 1 , wherein the first device is a client device, and

wherein the second device is a targeted device.

16. The method of claim 1 , wherein the ongoing communication conforms to the negotiated cryptographic protocol using the library components to facilitate translation of data of the ongoing communications to a particular format.

17. The device of claim 6 , wherein the first device is a client device, and

wherein the second device is a targeted device.

18. The device of claim 6 , wherein the ongoing communication conforms to the negotiated cryptographic protocol using the library components to facilitate translation of data of the ongoing communications to a particular format.

19. The non-transitory computer-readable medium of claim 11 , wherein the first device is a client device, and

wherein the second device is a targeted device.

20. The non-transitory computer-readable medium of claim 11 , wherein ongoing communications conform to the negotiated cryptographic protocol using the library components to facilitate translation of data of the ongoing communications to a particular format.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2023
From: BRACKEN, SHAWN
To: PLAID INC.
Reel/Frame 065071/0842 →
Continuity (3)
Continuation 16880114 · May 21, 2020
Provisional Application 62850890 · May 21, 2019
Related Publication 20240031408A1 · Jan 25, 2024
References Cited (22)
US 7430755B1 · Hughes · 2008 [cited by examiner]
US 10298404B1 · Behm et al. · 2019 [cited by applicant]
US 10462116B1 · Sharifi Mehr · 2019 [cited by examiner]
US 11082403B2 · McGinnity et al. · 2021 [cited by applicant]
US 20080022374A1 · Brown et al. · 2008 [cited by applicant]
US 20140337614A1 · Kelson · 2014 [cited by examiner]
US 20150113264A1 · Wang · 2015 [cited by examiner]
US 20150350209A1 · Tamura · 2015 [cited by applicant]
US 20160119287A1 · Khazan et al. · 2016 [cited by applicant]
US 20170068954A1 · Hockey et al. · 2017 [cited by applicant]
US 20170223049A1 · Kuperman et al. · 2017 [cited by applicant]
US 20180026797A1 · Behm et al. · 2018 [cited by applicant]
US 20180039988A1 · Gupta · 2018 [cited by applicant]
US 20180234341A1 · Ignatchenko · 2018 [cited by applicant]
US 20180324153A1 · Althouse · 2018 [cited by examiner]
US 20190182235A1 · Raman · 2019 [cited by examiner]
US 20190318122A1 · Hockey et al. · 2019 [cited by applicant]
US 20200213206A1 · Bracken · 2020 [cited by examiner]
WO 2019200402A1 · 2019 [cited by applicant]
Co-pending U.S. Appl. No. 16/880,114, inventor Bracken; Shawn, filed May 21, 2020. [cited by applicant]
Husak M., et al., “Network-based HTTPS Client Identification Using SSL/TLS Fingerprinting,” 2015 10th International Conference on Availability, Reliability and Security, IEEE, Aug. 24, 2015, pp. 389-396. [cited by applicant]
Ulrich J., “Browser Fingerprinting via SSL Client Hello Messages,” InfoSec Handlers Diary Blog, Dec. 11, 2013, pp. 1-5. [cited by applicant]