IP Library Granted Patent US 12,373,559
Granted Patent B1
US 12,373,559 · App. 18/479,666 · Granted Jul 29, 2025

Secure archive explorer

Inventors: Stephen John Stanley Thornhill (Chalfont St. Giles, GB); Michael Leslie Gardner (Bristol, GB); Todd Ignasiak (Mountain View, CA); David Jonathan Lee (Reading, GB)
Assignee: Menlo Security, Inc.
G06F21/565G06F16/113G06F21/602G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,373,559
App. No.
18/479,666
Granted
Jul 29, 2025
Kind
B1
Abstract

A secure archive explorer is disclosed. A determination is made that a user has selected, from an interface, an archive comprising at least one file. A determination is made that at least one of the selected archive or a subcomponent of the archive is encrypted. In response to determining that the at least one of the selected archive or subcomponent of the selected archive is encrypted, the user is prompted for a credential. Based at least in part on the user's response to the prompt, an action is taken.

Claims (25)

1. A system, comprising:

a processor configured to:

determine, at a browser isolation system, that a user has selected, from an interface rendered in a browser executing on a client device, an archive comprising at least one file, wherein the browser isolation system is configured to provide a surrogate browser to facilitate communications between the client browser and the archive, and wherein the archive is hosted by a remote site;

determine, by the browser isolation system, that at least one of the selected archive or a subcomponent of the selected archive is encrypted and in response to determining that the at least one of the selected archive or the subcomponent of the selected archive is encrypted, prompt the user for a credential in the browser; and

selectively providing access to the archive, or providing access to a modified version of the archive based at least in part on a security policy applicable to the user and based on the user's response to the prompt; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system of claim 1 , wherein the subcomponent is a file.

3. The system of claim 1 , wherein the subcomponent is an additional archive.

4. The system of claim 1 , wherein the user is prompted to select a sub-portion of content to download.

5. The system of claim 1 , wherein providing access to the modified version of the archive includes determining, for at least some files, which files do not pose a security threat, and offering those files which do not pose a security threat for download to the user.

6. The system of claim 1 , wherein, in the event the user's response does not include decryption information, the user is offered the ability to download unencrypted files.

7. The system of claim 1 , wherein the processor is further configured to provide a document viewer usable to view the at least one file.

8. The system of claim 1 , wherein in the event the system determines that the full contents of the archive do not pose a security threat, the user is provided an ability to download the archive.

9. The system of claim 1 , wherein in the event the system determines that the archive includes a file of a prohibited file type, the user is provided an ability to download a portion of the archive that excludes the file of the prohibited file type.

10. The system of claim 1 , wherein the processor is further configured to associate the archive with a unique identifier.

11. The system of claim 10 , wherein the unique identifier is associated with the user.

12. The system of claim 11 , wherein in the event a second user requests the same archive, the same archive will be assigned a second unique identifier, wherein the second unique identifier is associated with the second user.

13. A method, comprising:

determining, at a browser isolation system, that a user has selected, from an interface rendered in a browser executing on a client device, an archive comprising at least one file, wherein the browser isolation system is configured to provide a surrogate browser to facilitate communications between the client browser and the archive, and wherein the archive is hosted by a remote site;

determining, by the browser isolation system, that at least one of the selected archive or a subcomponent of the selected archive is encrypted and in response to determining that the at least one of the selected archive or the subcomponent of the selected archive is encrypted, and based at least in part on a security policy applicable to the user, prompting the user for a credential in the browser; and

selectively providing access to the archive, or providing access to a modified version of the archive based at least in part on a security policy applicable to the user and based on the user's response to the prompt.

14. A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for:

determining, at a browser isolation system, that a user has selected, from an interface rendered in a browser executing on a client device, an archive comprising at least one file, wherein the browser isolation system is configured to provide a surrogate browser to facilitate communications between the client browser and the archive, and wherein the archive is hosted by a remote site;

determining, by the browser isolation system, that at least one of the selected archive or a subcomponent of the selected archive is encrypted and in response to determining that the at least one of the selected archive or the subcomponent of the selected archive is encrypted, and based at least in part on a security policy applicable to the user, prompting the user for a credential in the browser; and

selectively providing access to the archive, or providing access to a modified version of the archive based at least in part on a security policy applicable to the user and based on the user's response to the prompt.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 21, 2024
From: THORNHILL, STEPHEN JOHN STANLEY; GARDNER, MICHAEL LESLIE; IGNASIAK, TODD; LEE, DAVID JONATHAN
To: MENLO SECURITY, INC.
Reel/Frame 066513/0370 →
Continuity (1)
Provisional Application 63412712 · Oct 3, 2022
References Cited (39)
US 8356357B1 · Barile · 2013 [cited by applicant]
US 8429429B1 · Kargman · 2013 [cited by applicant]
US 8726396B1 · Dodke · 2014 [cited by applicant]
US 8825748B2 · Sng · 2014 [cited by applicant]
US 8918867B1 · Salour · 2014 [cited by applicant]
US 9374374B2 · Steinberg · 2016 [cited by applicant]
US 9391832B1 · Song · 2016 [cited by applicant]
US 9887970B2 · Luff · 2018 [cited by applicant]
US 10958732B1 · Procopio · 2021 [cited by examiner]
US 11005819B1 · Song · 2021 [cited by applicant]
US 20100146600A1 · Eldar · 2010 [cited by applicant]
US 20120051657A1 · Lamanna · 2012 [cited by applicant]
US 20120096122A1 · Zhu · 2012 [cited by examiner]
US 20130061284A1 · Berengoltz · 2013 [cited by applicant]
US 20140019753A1 · Lowry · 2014 [cited by applicant]
US 20150095645A1 · Eldar · 2015 [cited by examiner]
US 20170041296A1 · Ford · 2017 [cited by applicant]
US 20170048252A1 · Straub · 2017 [cited by applicant]
US 20170063883A1 · Franzoni Martinez · 2017 [cited by applicant]
US 20170099344A1 · Hadfield · 2017 [cited by applicant]
US 20170235965A1 · Balinsky · 2017 [cited by applicant]
US 20170264619A1 · Narayanaswamy · 2017 [cited by applicant]
US 20170302635A1 · Humphries · 2017 [cited by examiner]
US 20180316674A1 · Shaked · 2018 [cited by applicant]
US 20190075130A1 · Petry · 2019 [cited by applicant]
US 20190213342A1 · Acharya · 2019 [cited by applicant]
US 20190289371A1 · Mok · 2019 [cited by examiner]
US 20200042837A1 · Skinner · 2020 [cited by applicant]
US 20200106842A1 · Chauhan · 2020 [cited by applicant]
US 20200186343A1 · Stuntebeck · 2020 [cited by examiner]
US 20200267167A1 · Venkataswami · 2020 [cited by applicant]
US 20200404000A1 · Hayes · 2020 [cited by examiner]
US 20210200866A1 · Strogov · 2021 [cited by examiner]
US 20210377219A1 · Finchelstein · 2021 [cited by applicant]
US 20210377303A1 · Bui · 2021 [cited by applicant]
US 20210377304A1 · Ma · 2021 [cited by applicant]
US 20230110049A1 · Bhalerao · 2023 [cited by examiner]
US 20230247238A1 · Ganesan · 2023 [cited by examiner]
Alkilani et al., Data Exfiltration Techniques and Data Loss Prevention System, 2019 International Arab Conference on Information Technology (ACIT), 2019, pp. 124-127, doi: 10.1109/ACIT47987.2019.8991131 (Year : 2019). [cited by applicant]