IP Library › Granted Patent US 12,592,914
Granted Patent B2
US 12,592,914 · App. 18/437,480 · Granted Mar 31, 2026

Systems and methods for inline hypertext transfer protocol (HTTP) cookie encryption

Inventor: Yaroslav Rosomakho (Thatcham, GB)
Assignee: Zscaler, Inc.
H04L63/0428
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,592,914
App. No.
18/437,480
Granted
Mar 31, 2026
Kind
B2
Abstract

Systems and methods for inline HTTP cookie encryption include responsive to a user authenticating to a web service, intercepting a response form the web service; encrypting an HTTP cookie in the response; and forwarding the response to the user, the response comprising the encrypted HTTP cookie. Responsive to intercepting a subsequent request from the user to the web service, wherein the subsequent request includes the encrypted HTTP cookie; decrypting the encrypted HTTP cookie; and forwarding the subsequent request to the web service with the decrypted HTTP cookie.

Claims (44)

1 . A method comprising steps of:

responsive to a user authenticating to a web service, at a cloud-based security node having one or more processors, intercepting a response form the web service;

encrypting, via an inline encryption engine of the cloud-based security node, a Hypertext Transfer Protocol (HTTP) cookie contained in the response, the encrypting rendering the HTTP session cookie opaque to an endpoint device of the user by applying an HTTPOnly flag and storing the original cookie in secure memory inaccessible to the endpoint device;

forwarding the response to the user, the response comprising the encrypted HTTP cookie; and

enforcing zero trust access policies during subsequent requests from the endpoint device by intercepting the subsequent requests at the cloud-based security node, decrypting the encrypted HTTP session cookie using a tenant-specific key, and conditionally forwarding the decrypted HTTP session cookie to the web service only when the zero trust access policies, wherein the user does not receive, and does not have access to the HTTP cookie in the response, the response comprising an encrypted cookie with an HTTPOnly flag such that no application programming interface of the endpoint device can access the cookie.

2 . The method of claim 1 , wherein the steps comprise:

performing inline monitoring via the cloud-based security node in a cloud-based system of traffic between (i) a user device associated with the user, and (ii) the web service.

3 . The method of claim 1 , wherein the intercepting is via the cloud-based security node configured to terminate every connection for inspection, including encrypted traffic, and wherein the cloud-based security node is adapted to enforce one or more web security solutions.

4 . The method of claim 1 , wherein the steps further comprise:

intercepting a subsequent request from the user to the web service, wherein the subsequent request includes the encrypted HTTP cookie;

decrypting the encrypted HTTP cookie; and

forwarding the subsequent request to the web service with the decrypted HTTP cookie.

5 . The method of claim 4 , wherein the steps further comprise:

enforcing one or more web security solutions on the subsequent request; and

forwarding the subsequent request and the decrypted HTTP cookie to the web service based thereon.

6 . The method of claim 1 , wherein prior to the encrypting, the steps comprise:

enabling HTTP session cookie encryption via an interface.

7 . The method of claim 1 , wherein the web service is any of a Software-as-a-Service (SaaS) application, an enterprise file share, a web application, and a private application.

8 . The method of claim 1 , wherein the web service does not receive, and does not have access to contents of the encrypted HTTP cookie, the web service receiving only a decrypted cookie from the cloud-based security node and lacking access to the original issued cookie.

9 . The method of claim 1 , wherein the steps comprise:

authenticating the user for the web service, wherein the authenticating includes determining if the user belongs to one or more user groups; and

performing the encrypting based on the user belonging to one or more user groups.

10 . A non-transitory computer-readable medium comprising instructions that, when executed by one or more processors of a cloud-based security node, cause the one or more processors to perform steps of:

responsive to a user authenticating to a web service, intercepting a response form the web service;

encrypting, via an inline encryption engine of the cloud-based security node, a Hypertext Transfer Protocol (HTTP) cookie contained in the response, including applying an HTTPOnly flag to ensure that the encrypted cookie is opaque to endpoint applications and inaccessible to the user;

forwarding the response to the user, the response comprising the encrypted HTTP cookie; and

intercepting subsequent requests from the user, decrypting the encrypted HTTP session cookie using a key stored in secure memory of the cloud-based security node, enforcing one or more zero trust access policies based on user group membership or device context, and forwarding the decrypted cookie with the request to the web service only if the zero trust access policies are satisfied, wherein the user does not receive, and does not have access to the HTTP cookie in the response, the response comprising an encrypted cookie with an HTTPOnly flag such that no application programming interface of the endpoint device can access the cookie.

11 . The non-transitory computer-readable medium of claim 10 , wherein the steps comprise:

performing inline monitoring via the cloud-based security node in a cloud-based system of traffic between (i) a user device associated with the user, and (ii) the web service.

12 . The non-transitory computer-readable medium of claim 10 , wherein the intercepting is via the cloud-based security node configured to terminate every connection for inspection, including encrypted traffic, and wherein the cloud-based security node is adapted to enforce one or more web security solutions.

13 . The non-transitory computer-readable medium of claim 10 , wherein the steps further comprise:

intercepting a subsequent request from the user to the web service, wherein the subsequent request includes the encrypted HTTP cookie;

decrypting the encrypted HTTP cookie; and

forwarding the subsequent request to the web service with the decrypted HTTP cookie.

14 . The non-transitory computer-readable medium of claim 13 , wherein the steps further comprise:

enforcing one or more web security solutions on the subsequent request; and

forwarding the subsequent request and the decrypted HTTP cookie to the web service based thereon.

15 . The non-transitory computer-readable medium of claim 10 , wherein prior to the encrypting, the steps comprise:

enabling HTTP session cookie encryption via an interface.

16 . The non-transitory computer-readable medium of claim 10 , wherein the web service is any of a Software-as-a-Service (SaaS) application, an enterprise file share, a web application, and a private application.

17 . The non-transitory computer-readable medium of claim 10 , wherein the web service does not receive, and does not have access to the encrypted HTTP cookie, the web service receiving only a decrypted cookie from the cloud-based security node and lacking access to the original issued cookie.

18 . The non-transitory computer-readable medium of claim 10 , wherein the steps comprise:

authenticating the user for the web service, wherein the authenticating includes determining if the user belongs to one or more user groups; and

performing the encrypting based on the user belonging to one or more user groups.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 9, 2024
From: ROSOMAKHO, YAROSLAV
To: ZSCALER, INC.
Reel/Frame 066426/0233 →
Continuity (1)
Related Publication 20250260674A1 · Aug 14, 2025
References Cited (16)
US 7043455B1 · Cuomo · 2006 [cited by examiner]
US 8219687B2 · Huang · 2012 [cited by examiner]
US 8281021B1 · Smith · 2012 [cited by examiner]
US 8448233B2 · Shulman · 2013 [cited by examiner]
US 9286471B2 · Qureshi · 2016 [cited by examiner]
US 9602537B2 · Petty · 2017 [cited by examiner]
US 10897458B1 · Coral · 2021 [cited by examiner]
US 12132708B2 · Nilekar · 2024 [cited by examiner]
US 12132788B2 · Kauffman · 2024 [cited by examiner]
US 20070245137A1 · Bhagat · 2007 [cited by examiner]
US 20150012751A1 · Forster · 2015 [cited by examiner]
US 20150113604A1 · Oyman · 2015 [cited by examiner]
US 20160112375A1 · Cohen · 2016 [cited by examiner]
US 20220158831A1 · Wing · 2022 [cited by examiner]
US 20240089250A1 · Conway · 2024 [cited by examiner]
US 20250039173A1 · Azrielant · 2025 [cited by examiner]