IP Library Granted Patent US 12,477,013
Granted Patent B2
US 12,477,013 · App. 18/227,089 · Granted Nov 18, 2025

Dynamic source values for content security policies

Inventors: Jonathan Kulisz (San Antonio, TX); Shutanshu (Campbell, CA); Sudip Chakrabarty (San Jose, CA); Srinivas Hariharan (Bengaluru, IN); Piyush Pattanayak (Fremont, CA); Nishant Kumar Das Pattanaik (Bengaluru, IN); Anuj Kaul (Dublin, CA)
Assignee: eBay Inc.
H04L63/205H04L63/1433H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,477,013
App. No.
18/227,089
Granted
Nov 18, 2025
Kind
B2
Abstract

Systems and methods dynamically generate content security policy (CSP) headers using CSP definitions having dynamic source values. When a request for a web application is received, a CSP definition corresponding to the web application and having a dynamic source value is retrieved from a repository of CSP definitions. A CSP header is generated based on the CSP definition. The CSP header includes a source value dynamically generated based on the dynamic source value and a domain associated with the requested web application. The CSP header is provided as a response header for the requested web application.

Claims (38)

1 . A computer-implemented method comprising:

receiving a request for a web application;

retrieving, from a repository of content security policy (CSP) definitions, a CSP definition corresponding to the requested web application, the CSP definition including a dynamic source value;

generating a CSP header for the request using the CSP definition, the CSP header including a source value identifying a valid source for one or more resources for the web application, the source value dynamically generated using the dynamic source value and a domain associated with the requested web application; and

providing the CSP header as a response header for the requested web application.

2 . The computer-implemented method of claim 1 , wherein the domain associated with the requested web application comprises a top-level domain, a second-level domain, or a subdomain.

3 . The computer-implemented method of claim 1 , wherein the dynamic source value includes a wildcard character and the source value in the CSP header is dynamically generated to include the wildcard character.

4 . The computer-implemented method of claim 1 , wherein the CSP definition includes a static source value; and wherein the CSP header is generated to include the static source value.

5 . The computer-implemented method of claim 1 , wherein the CSP definition includes a second dynamic source value, and wherein the CSP header includes a second source value dynamically generated based on the second dynamic source value and the domain associated with the requested web application.

6 . The computer-implemented method of claim 5 , wherein the source value corresponds to a first directive of the CSP header and the second source value corresponds to a second directive of the CSP header.

7 . The computer-implemented method of claim 1 , wherein the method further comprises:

identifying a geographical region associated with the requested web application; and

determining the domain associated with the requested web application based on the geographical region.

8 . One or more computer storage media storing computer-useable instructions that, when used by a computing device, cause the computing device to perform operations, the operations comprising:

receiving a request for a web application;

retrieving, from a repository of content security policy (CSP) definitions, a CSP definition corresponding to the requested web application, the CSP definition including a dynamic source value that includes a placeholder portion to be dynamically determined when generating CSP headers using the CSP definition;

generating a CSP header for the request using the CSP definition, the CSP header including a source value dynamically generated by replacing the placeholder portion of the dynamic source value with a corresponding portion of a domain associated with the requested web application; and

providing the CSP header as a response header for the requested web application.

9 . The one or more computer storage media of claim 8 , wherein the corresponding portion of the domain associated with the requested web application comprises a top-level domain, a second-level domain, or a subdomain.

10 . The one or more computer storage media of claim 8 , wherein the dynamic source value includes a wildcard character and the source value in the CSP header is dynamically generated to include the wildcard character.

11 . The computer-implemented method of claim 1 , wherein the CSP definition includes a static source value; and wherein the CSP header is generated to include the static source value.

12 . The one or more computer storage media of claim 8 , wherein the CSP definition includes a second dynamic source value, and wherein the CSP header includes a second source value dynamically generated based on the second dynamic source value and the domain associated with the requested web application.

13 . The one or more computer storage media of claim 12 , wherein the source value corresponds to a first directive of the CSP header and the second source value corresponds to a second directive of the CSP header.

14 . The one or more computer storage media of claim 8 , wherein the operations further comprise:

identifying a geographical region associated with the requested web application; and

determining the corresponding portion of the domain associated with the requested web application based on the geographical region.

15 . A computer system comprising:

one or more processors; and

one or more computer storage media storing computer-useable instructions that, when used by the one or more processors, causes the one or more processors to perform operations comprising:

receiving a request for a web application;

retrieving, from a repository of content security policy (CSP) definitions, a CSP definition corresponding to the requested web application, the CSP definition including a dynamic source value;

generating a CSP header for the request using the CSP definition, the CSP header including a source value identifying a valid source for one or more resources for the web application, the source value dynamically generated using the dynamic source value and a domain associated with the requested web application; and

providing the CSP header as a response header for the requested web application.

16 . The computer system of claim 15 wherein the domain associated with the requested web application comprises a top-level domain, a second-level domain, or a subdomain.

17 . The computer system of claim 15 , wherein the dynamic source value includes a wildcard character and the source value in the CSP header is dynamically generated to include the wildcard character.

18 . The computer system of claim 15 , wherein the CSP definition includes a static source value; and wherein the CSP header is generated to include the static source value.

19 . The computer system of claim 18 , wherein the CSP definition includes a second dynamic source value, and wherein the CSP header includes a second source value dynamically generated based on the second dynamic source value and the domain associated with the requested web application.

20 . The computer system of claim 19 , wherein the source value corresponds to a first directive of the CSP header and the second source value corresponds to a second directive of the CSP header.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2023
From: KULISZ, JONATHAN; SHUTANSHU, SHUTANSHU; CHAKRABARTY, SUDIP; HARIHARAN, SRINIVAS; PATTANAYAK, PIYUSH; DAS PATTANAIK, NISHANT KUMAR; KAUL, ANUJ
To: EBAY INC.
Reel/Frame 064422/0328 →
Priority Claims (1)
IN 202311049317 · Jul 21, 2023 · national
Continuity (1)
Related Publication 20250030738A1 · Jan 23, 2025
References Cited (45)
US 8543667B2 · Hluchyj et al. · 2013 [cited by applicant]
US 8918359B2 · Ahuja et al. · 2014 [cited by applicant]
US 9015844B1 · Franklin et al. · 2015 [cited by applicant]
US 9154492B2 · Chu et al. · 2015 [cited by applicant]
US 9558017B2 · Plate · 2017 [cited by applicant]
US 10432662B2 · Sethi et al. · 2019 [cited by applicant]
US 10509914B1 · Desai et al. · 2019 [cited by applicant]
US 10581878B2 · Ng et al. · 2020 [cited by applicant]
US 10678910B2 · Ng et al. · 2020 [cited by applicant]
US 10778687B2 · Rajahram et al. · 2020 [cited by applicant]
US 10817424B1 · Amrani · 2020 [cited by examiner]
US 10868802B2 · Westerlund et al. · 2020 [cited by applicant]
US 11057432B2 · Ni et al. · 2021 [cited by applicant]
US 11128639B2 · Bergbom et al. · 2021 [cited by applicant]
US 11144342B2 · Schulze et al. · 2021 [cited by applicant]
US 11528301B1 · Saraf et al. · 2022 [cited by applicant]
US 20100064342A1 · Nakagawa · 2010 [cited by applicant]
US 20110093768A1 · Panwar · 2011 [cited by applicant]
US 20150047051A1 · Johns · 2015 [cited by examiner]
US 20170208370A1 · Ray et al. · 2017 [cited by applicant]
US 20190238544A1 · Rajahram et al. · 2019 [cited by applicant]
US 20200092333A1 · Šebesta · 2020 [cited by applicant]
US 20220116787A1 · Balan et al. · 2022 [cited by applicant]
US 20220337630A1 · Kipp et al. · 2022 [cited by applicant]
US 20220345497A1 · Bhatkar et al. · 2022 [cited by applicant]
US 20230122784A1 · Khan · 2023 [cited by examiner]
CN 114830092A · 2022 [cited by applicant]
WO 2020055484A1 · 2020 [cited by applicant]
Content Security Policy (CSP) violation error during Proxy Now, SAP Knowledge Base Article, Retrieved from Internet URL:<https://userapps.support.sap.com/sap/support/knowledge/en/3059464>, Accessed on May 12, 2023, 3 pa… [cited by applicant]
CSP violation report, Retrieved from Internet URL:<https://csplite.com/csp66/#violation-report>, Accessed on May 12, 2023, 6 pages. [cited by applicant]
Banach,“Using Content Security Policy (CSP) to Secure Web Applications”, Invicti, Retrieved from Internet URL:<https://www.invicti.com/blog/web-security/content-security-policy/>, Mar. 27, 2020, 13 pages. [cited by applicant]
Calzavara et al., “Content Security Problems? Evaluating the Effectiveness of Content Security Policy in the Wild”, Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, Oct. 24, 2016, p… [cited by applicant]
Google,“Create custom headers in backend services”, GoogleCloud, Load Balancing, Retrieved from Internet URL:<https://cloud.google.com/load-balancing/docs/https/custom-headers>, Accessed on May 12, 2023, 10 pages. [cited by applicant]
Marsh,“Modifying HTTP response headers with Transform Rules”, Cloudflare, Retrieved from Internet URL:<https://blog.cloudflare.com/transform-http-response-headers/>, Nov. 18, 2021, 11 pages. [cited by applicant]
Rothenberg, “HTTP::CSPHeader—manage dynamic content security policy headers”, Metacpan, Retrieved from Internet URL:<https://metacpan.org/pod/HTTP::CSPHeader>, Accessed on May 12, 2023, 5 pages. [cited by applicant]
Anonymous : “Content Security Policy Wildcards?—Stack Overflow”, Available at : <https://stackoverflow.com/questions/73615828/content-security-policy-wildcards>, Sep. 6, 2022, 2 pages. [cited by applicant]
Calzavara et al., “Semantics-Based Analysis of Content Security Policy Deployment”, ACM Transactions on the Web, vol. 1, No. 1, 2017, 36 pages. [cited by applicant]
EP Communication received for European Application No. 24189666.1, mailed on Jan. 27, 2025, 2 pages. [cited by applicant]
EP Communication received for European Application No. 24189682.8 , mailed on Jan. 27, 2025, 2 pages. [cited by applicant]
Extended European Search Report received for European Application No. 24189666.1, mailed on Dec. 3, 2024, 10 pages. [cited by applicant]
Extended European Search Report received for European Application No. 24189682.8, mailed on Dec. 6, 2024, 11 pages. [cited by applicant]
Hausknecht et al., “May I?—Content Security Policy Endorsement for Browser Extensions”, Advances in Visual Computing, 2015, 20 pages. [cited by applicant]
Non-Final Office Action received for U.S. Appl. No. 18/227,099, mailed on Apr. 10, 2025, 13 pages. [cited by applicant]
Steve, B., “How to Create a Content Security Policy (CSP Header)” Available online at: <https://gridpane.com/kb/how-to-create-a-content-security-policy-csp-header/#create-customize-csp>, Jun. 23, 2020, 15 pages. [cited by applicant]
Notice of Allowance received for U.S. Appl. No. 18/227,099, mailed on Aug. 4, 2025, 7 pages. [cited by applicant]