IP Library › Granted Patent US 11,457,036
Granted Patent B2
US 11,457,036 · App. 16/817,237 · Granted Sep 27, 2022

Proxy computer system to provide selective decryption

Inventor: Anthony Scotney (Hobart, AU)
H04L63/1433H04L63/0281H04L63/0428H04L67/53H04L67/56H04L67/60H04L67/01
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,457,036
App. No.
16/817,237
Granted
Sep 27, 2022
Kind
B2
Abstract

A proxy computer system receives content intended for a client computer from a third-party network service, where the content includes an encrypted portion. The proxy computer system makes a determination as to whether the encrypted portion is to be decrypted for the client computer, where the determination is made based at least in part on a historical analysis of the client computer. The proxy computer system sends the content to the client computer in a form that is based on the determination.

Claims (40)

1. A proxy server system comprising:

a memory resource to store a set of instructions; and

one or more processors to access the set of instructions from the memory resource to perform operations including:

aggregating proxy-based data comprising usage parameters of a plurality of client devices or associated users when accessing content hosted by a third-party network service through the proxy server system;

receiving, from a client device, a request including a proxy link that corresponds to a link to content hosted by a third-party network service;

retrieving the content from the third-party network service on behalf of the client device using the link, the content including one or more sensitive portions of data in an encrypted format and a remainder portion that is not encrypted;

determining a risk metric for the client device or an associated user based on analyzing the proxy-based data corresponding to the client device or the associated user;

determining that the client device is approved to view the one or more sensitive portions of data based on the risk metric; and

in response to determining that the client device is approved to view the one or more sensitive portions of data based on the risk metric, providing modified content to the client device, the modified content including the remainder portion that is not encrypted and decrypted versions of the one or more sensitive portions of data.

2. The proxy server system of claim 1 , wherein determining that the client device is approved includes determining that the risk metric is below a first threshold value.

3. The proxy server system of claim 1 , wherein determining the risk metric is based on proxy-based data comprising information that is indicative of a device, network address, or physical location when the client device or associated user previously accessed the third-party network service or the server system.

4. The proxy server system of claim 1 , wherein determining the risk metric is based on proxy-based data comprising access times of content hosted by the third-party network service through the proxy server system by the client device or an associated user.

5. The proxy server system of claim 1 , wherein determining the risk metric is based on proxy-based data comprising data usage via the proxy server system of the client device or an associated user.

6. The proxy server system of claim 1 , wherein the risk metric is based on one or more metrics indicating a risk that the client device or an associated user is an imposter.

7. The proxy server system of claim 1 , wherein determining the risk metric is based on one or more metrics indicating a risk that the client device is inadequately protected due to poor security integrity.

8. The proxy server system of claim 7 , wherein the one or more metrics indicating a risk that the client device is inadequately protected due to poor security integrity is based at least on one or more current activities of a user of the client device, as detected on the client device.

9. The proxy server system of claim 1 , wherein analyzing the proxy-based data corresponding to the client device or the associated user includes building a usage profile of a user of the client device based on the proxy-based data corresponding at least one of the client device and the associated user.

10. The proxy server system of claim 9 , wherein the one or more processors determine the risk metric by comparing one or more usage parameters of a current user session with the usage profile of the client device or associated users.

11. The proxy server system of claim 1 , wherein the one or more processors receive and scan a content submission of a user of the client device for content corresponding to one or more sensitive fields of a form to identify the one or more sensitive portions of data.

12. The proxy server system of claim 11 , wherein the one or more processors encrypt the content submission corresponding to the one or more sensitive fields before submitting the content to the third-party network service.

13. A method for providing a proxy service between a client device and a third-party network service, the method being implemented by one or more processors of a network computer system and comprising:

aggregating proxy-based data comprising usage parameters of a plurality of client devices or associated users when accessing content hosted by the third-party network service through the proxy service;

receiving, from a client device, a request including a proxy link that corresponds to a link to content hosted by the third-party network service;

retrieving the content from the third-party network service on behalf of the client device using the link, the content including one or more sensitive portions of data in an encrypted format and a remainder portion that is not encrypted;

determining a risk metric for the client device or an associated user based on analyzing the proxy-based data corresponding to the client device or the associated user;

determining that the client device is approved to view the one or more sensitive portions of data based on the risk metric; and

in response to determining that the client device is approved to view the one or more sensitive portions of data based on the risk metric, providing modified content to the client device, the modified content including the remainder portion that is not encrypted and decrypted versions of the one or more sensitive portions of data.

14. The method of claim 13 , wherein determining that the client device is approved includes determining that the risk metric is below a first threshold value.

15. The method of claim 13 , wherein determining the risk metric is based on proxy-based data comprising information that is indicative of a device, network address, or physical location when the client device or associated user previously accessed the third-party network service or the proxy service.

16. The method of claim 13 , wherein determining the risk metric is based on proxy-based data comprising access times of content hosted by the third-party network service through the proxy server system by the client device or an associated user.

17. The method of claim 13 , wherein the risk metric is based on one or more metrics indicating a risk that the client device or an associated user is an imposter.

18. The method of claim 13 , wherein determining the risk metric is based on one or more metrics indicating a risk that the client device is inadequately protected due to poor security integrity.

19. The method of claim 13 , wherein analyzing the proxy-based data corresponding to the client device or the associated user includes building a usage profile of a user of the client device based on the proxy-based data corresponding at least one of the client device and the associated user.

20. A non-transitory computer-readable medium that stores instructions, which when executed by one or more processors of a proxy computer system, cause the proxy computer system to perform operations that include:

aggregating proxy-based data comprising usage parameters of a plurality of client devices or associated users when accessing content hosted by a third-party network service through a proxy server system;

receiving, from a client device, a request including a proxy link that corresponds to a link to content hosted by a third-party network service;

retrieving the content from the third-party network service on behalf the client device using the link, the content including one or more sensitive portions of data in an encrypted format and a remainder portion that is not encrypted;

determining a risk metric for the client device or an associated user based on analyzing the proxy-based data corresponding to the client device or the associated user;

determining that the client device is approved to view the one or more sensitive portions of data based on the risk metric; and

in response to determining that the client device is approved to view the sensitive portions of data based on the risk metric, providing modified content to the client device, the modified content including the remainder portion that is not encrypted and decrypted versions of the one or more sensitive portions of data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 18, 2020
From: SCOTNEY, ANTHONY
To: STRATOKEY PTY LTD.
Reel/Frame 052188/0575 →
Continuity (3)
Continuation 15808690 · Nov 9, 2017
Provisional Application 62419960 · Nov 9, 2016
Related Publication 20200213345A1 · Jul 2, 2020