IP Library › Granted Patent US 10,819,693
Granted Patent B2
US 10,819,693 · App. 16/450,866 · Granted Oct 27, 2020

Disposable browsers and authentication techniques for a secure online user environment

Inventors: Ramesh Rajagopal (Los Altos, CA); James K. Tosh (Fremont, CA); Fredric L. Cox (San Jose, CA); Perry F. Nguyen (Santa Clara, CA); Jason T. Champion (Mountain View, CA)
Assignee: Authentic8, Inc.
H04L63/08G06F21/31G06F21/313G06F21/35G06F21/36G06F21/43G06F21/53H04L63/102H04L63/1441H04L63/20H04L67/42G06F2221/2111H04L63/168
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,819,693
App. No.
16/450,866
Granted
Oct 27, 2020
Kind
B2
Abstract

Disclosed herein are systems and methods that allow for secure access to websites and web-based applications and other resources available through the browser. Also described are systems and methods for secure use and retention of user credentials, as well as methods for dynamic authentication of users and integrity checking of service providers in online environments. Thus, described in the present specification are systems and methods for constructing and destroying private, secure, browsing environments (a secure disposable browser), insulating the user from the threats associated with being online for the purposes of providing secure, policy-based interaction with online services.

Claims (55)

1. A secure system for enabling access to web content using disposable browsers, the secure system comprising:

a memory comprising computer instructions; and

an application server comprising a hardware processor associated with a computing device, wherein the hardware processor is operable to:

establish a secure environment for operating a disposable browser session;

initiate the disposable browser session within the secure environment, wherein a disposable browser associated with the disposable browser session is displayable on a client device executing a thin client process and located externally to the secure system;

configure the disposable browser session with session-specific data associated with the disposable browser session;

receive first data from the client device, the first data being associated with a web content request initiated on the disposable browser displayed on the client device;

communicate with a remote server associated with the web content request;

execute a web command associated with the web content request;

transmit, to the client device, second data associated with the web command or the web content request, wherein the second data comprises image data;

receive, from the client device, a user interaction with the image data displayed on the client device;

transmit, to the remote server, third data associated with the user interaction with the image data displayed on the client device; and

dispose, at an end of the disposable browser session, the session-specific data associated with the disposable browser session,

wherein identification information associated with the client device is not transmitted directly from the client device to the remote server.

2. The secure system of claim 1 , wherein the disposable browser session is initiated by the client device or by the secure system.

3. The secure system of claim 1 , wherein the disposable browser session is ended by the client device or by the secure system.

4. The secure system of claim 1 , wherein the session-specific data is associated with the disposable browser.

5. The secure system of claim 1 , wherein the session-specific data is associated with a user preference.

6. The secure system of claim 1 , wherein the receiving the first data from the client device occurs before the establishing the secure environment.

7. The secure system of claim 1 , wherein the receiving the first data from the client device occurs after the establishing the secure environment.

8. The secure system of claim 1 , wherein the receiving the first data from the client device occurs before the initiating the disposable browser session.

9. The secure system of claim 1 , wherein the receiving the first data from the client device occurs after the initiating the disposable browser session.

10. The secure system of claim 1 , wherein the web command is received from the remote server.

11. The secure system of claim 1 , wherein the secure environment is disposed of at the end of the disposable browser session.

12. The secure system of claim 1 , wherein the computer instructions are associated with performing a user authentication operation for a user of the client device, wherein the user authentication operation is associated with enabling the user of the client device to access an application or a page associated with the web content request.

13. The secure system of claim 1 , wherein the secure system is operable to remotely control the disposable browser.

14. The secure system of claim 1 , wherein the disposable browser session is insulated from other disposable browser sessions.

15. The secure system of claim 1 , wherein the computer instructions are associated with performing a user authentication operation for the client device or for a user of the client device.

16. A method for enabling access to web content using disposable browsers, the method comprising:

establishing, using one or more computing device processors, a secure environment for operating a disposable browser session;

initiating, using the one or more computing device processors, the disposable browser session within the secure environment, wherein a disposable browser associated with the disposable browser session is displayable on a client device executing a thin client process and located externally to the secure system;

configuring, using the one or more computing device processors, the disposable browser session with session-specific data associated with the disposable browser session;

receiving, using the one or more computing device processors, first data from the client device, the first data being associated with a web content request initiated on the disposable browser;

communicating, using the one or more computing device processors, with a remote server associated with the web content request;

executing, using the one or more computing device processors, a web command associated with the web content request;

transmitting, to the client device, second data associated with the web command or the web content request, wherein the second data comprises image data;

receiving, from the client device, a user interaction with the image data displayed on the client device;

transmitting, to the remote server, third data associated with the user interaction with the image data displayed on the client device; and

disposing, using the one or more computing device processors, at an end of the disposable browser session, the session-specific data associated with the disposable browser session,

wherein identification information associated with the client device or a user of the client device is not transmitted directly from the client device to the remote server.

17. The method of claim 16 , wherein the disposable browser session is initiated or ended by the client device or by the secure system.

18. The method of claim 16 , further comprising authenticating the client device or the user of the client device to an application or a page associated with the web content request.

19. A secure system for enabling access to web content using disposable browsers, the secure system comprising one or more hardware processors configured to:

establish a secure environment for operating a disposable browser session;

initiate the disposable browser session within the secure environment, wherein a disposable browser associated with the disposable browser session is displayable on a client device located externally to the secure system;

configure the disposable browser session with session-specific data associated with the disposable browser session;

receive first data from the client device, the first data being associated with a web content request initiated on the disposable browser displayed on the client device;

communicate with a remote server associated with the web content request;

execute a web command associated with the web content request;

transmit, to the client device, second data associated with the web command or the web content request, wherein the second data comprises image data;

receive, from the client device, a user interaction with the image data displayed on the client device;

transmit, to the remote server, third data associated with the user interaction with the image data displayed on the client device; and

dispose, at an end of the disposable browser session, the session-specific data associated with the disposable browser session,

wherein identification information associated with the client device is not transmitted directly from the client device to the remote server.

20. The secure system of claim 19 , wherein authentication information associated with the client device or a user of the client device is not transmitted directly from the client device to the remote server.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 9, 2020
From: RAJAGOPAL, RAMESH; TOSH, JAMES K.; COX, FREDRIC L.; NGUYEN, PERRY F.; CHAMPION, JASON T.
To: AUTHENTIC8, INC.
Reel/Frame 052057/0669 →
Continuity (5)
Continuation 15281440 · Sep 30, 2016
Continuation 14325128 · Jul 7, 2014
Continuation 13076421 · Mar 30, 2011
Provisional Application 61319250 · Mar 30, 2010
Related Publication 20190319936A1 · Oct 17, 2019
Cited By (2)
US 12,212,552 US 12,750,353