IP Library › Granted Patent US 12,592,918
Granted Patent B2
US 12,592,918 · App. 18/545,251 · Granted Mar 31, 2026

Browser extension for validating communications

Inventors: Andrew Paul Montgomery (London, GB); Sanjay Bhanu (Camberley, GB); Stuart David Ford (Slapton, GB); Ricardo Varanda (Reading, GB)
Assignee: Bank of America Corporation
H04L63/0823H04L67/02H04L67/141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,592,918
App. No.
18/545,251
Granted
Mar 31, 2026
Kind
B2
Abstract

A computing device comprising a secure browser extension for a web browser monitors for satisfaction of one or more operating conditions to identify whether one or more unauthorized applications are intercepting web browser communications. Based on satisfaction of at least one operating condition, the secure browser extension of the computing device sends an HTTPS request to a known service via the web browser. The secure browser extension receives an HTTPS response to the HTTPS request via the web browser. The secure browser extension determines whether the certificate included in the HTTPS response is trusted by the secure browser extension. Based on determining the certificate is not trusted, the secure browser extension terminates the web browser session and generates a notification for display at the computing device that indicates web browser communications are compromised.

Claims (64)

1 . A system comprising:

a server hosting a trusted service, wherein the trusted service provides a trusted certified certificate; and

a computing device, comprising:

a processor;

a communication interface communicatively coupled to the processor; and

non-transitory memory storing computer-readable instructions that, when executed by the processor, cause the computing device to:

identify, by a secure extension of a web browser, an outgoing connection request to a remote service, wherein the trusted service is identified in a secure extension configuration;

send, based on the outgoing connection request to the remote service and by the secure extension, a Hypertext Transfer Protocol Secure (HTTPS) request to the trusted service, wherein the trusted service is different than the remote service;

receive, by the web browser, an HTTPS response to the HTTPS request wherein the HTTPS response comprises a second certificate;

identify, by the secure extension and based on a difference between the second certificate and the trusted certificate, operation of a middle agent; and

display, by the secure extension and based on the difference between the trusted certificate and the second certificate, an indication that enterprise network communications are compromised by the middle agent.

2 . The system of claim 1 , wherein the instructions further cause the computing device to:

monitor, by the secure extension, for an expiration of a time duration, wherein the time duration is defined in the configuration of the secure extension; and

send, via the network based on an indication of the expiration of the time duration and by the secure extension, the HTTPS request to the trusted service.

3 . The system of claim 1 , wherein the instructions further cause the computing device to:

identify, by the secure extension and based on the second certificate, an indication of certificate validity comprising: a valid response signature, an active certificate validity period, an active certificate, and a valid certificate authority; and

cause, by the secure extension and via the web browser based on an identified certificate validity indication, display of a second notification, wherein the second notification comprises an indication that communications via the web browser are secure.

4 . The system of claim 1 , wherein the instructions further cause the computing device to monitor, by the secure extension and based on the HTTPS request, communications received by the web browser for the HTTPS response at the web browser.

5 . The system of claim 1 , wherein the instructions further cause the computing device to deactivate, based on an indication of certificate replacement, the web browser.

6 . The system of claim 1 , wherein the instructions further cause the computing device to generate, by the secure extension, an indication of certificate replacement based on an identification of one or more of:

an invalid response signature;

an inactive certificate validity period;

a certificate revocation; and

an invalid certificate authority.

7 . The system of claim 1 , wherein the configuration of the secure extension is defined by a developer associated with the secure extension or by an enterprise organization associated with the computing device.

8 . A method, comprising:

identifying, by a secure extension of a web browser and from outgoing enterprise network connections, a connection request to a remote service;

requesting, based on an indication of the connection request to the remote service and by the secure extension, a Hypertext Transfer Protocol Secure (HTTPS) request to a trusted service identified in a secure extension configuration, wherein the trusted service is different than the remote service;

receiving, by the web browser, an HTTPS response to the HTTPS request wherein the HTTPS response comprises a second certificate;

identifying, by the secure extension and based on the second certificate of the HTTPS response being different than a trusted certificate of the trusted service, operation of a middle agent; and

displaying, by the secure extension and via the web browser, an indication that enterprise network communications are compromised by the middle agent.

9 . The method of claim 8 , further comprising:

monitoring, by the secure extension, for an activation of the web browser; and

sending, via the network based on an indication of the activation of the web browser and by the secure extension, the HTTPS request to the trusted service.

10 . The method of claim 8 , further comprising:

identifying, by the secure extension and based on the second certificate, a difference between the trusted certificate and the second certificate based on a response signature, an active certificate validity period, an active certificate, and a valid certificate authority.

11 . The method of claim 8 , further comprising:

monitoring, by the secure extension and based on the HTTPS request, communications received by the web browser for the HTTPS response at the web browser.

12 . The method of claim 8 , further comprising deactivating, based on an identification of a replacement certificate, networked communications via the web browser.

13 . The method of claim 8 , further comprising generating, by the secure extension, an indication of a replacement certificate based on an identification of one or more of:

an invalid response signature;

an inactive certificate validity period;

a certificate revocation; and

an invalid certificate authority.

14 . The method of claim 8 , wherein the trusted service is accessible via network and wherein the trusted service is hosted at a server computing device.

15 . A computing device comprising

a processor; and

one or more non-transitory computer-readable media storing instructions that, when executed by a computing device, cause the computing device to:

identify, by a secure extension of a web browser, a connection request from an enterprise network to a remote service, wherein a secure extension configuration comprises an indication of a trusted service different than the remote service;

send, based on an indication of the connection request to the remote service and by the secure extension, a Hypertext Transfer Protocol Secure (HTTPS) request to the trusted service;

receive, by the secure extension, one of an HTTPS response or an HTTP response to the HTTPS request;

identify, by the secure extension and based on receipt of the HTTPS response comprising a second certificate different the trusted certificate associated with the trusted service, operation of a middle agent; and

display, by the secure extension, an indication that enterprise network communications are compromised by the middle agent.

16 . The computing device of claim 15 , wherein the trusted service is an HTTPS service or a configured domain, wherein the configured domain is identified in the configuration of the secure extension, and wherein the configuration of the secure extension is defined by a developer associated with the secure extension or by an enterprise organization associated with the computing device.

17 . The computing device of claim 15 , wherein the instructions further cause the computing device to:

identify, by the secure extension and based on the second certificate, an indication of certificate validity comprising: a valid response signature, an active validity period, an active certificate, and a valid certificate authority; and

cause display, by the secure extension and via the web browser based on an identification that the second certificate is valid, of a second notification, wherein the second notification comprises an indication that communications via the web browser are secure.

18 . The computing device of claim 15 , wherein the instructions further cause the computing device to monitor, by the secure extension and based on the HTTPS request, communications received by the web browser for the HTTPS response at the web browser.

19 . The computing device of claim 15 , wherein the instructions further cause the computing device to deactivate, based on a certificate invalidity indication, the web browser.

20 . The computing device of claim 15 , wherein the instructions further cause the computing device to generate, by the secure extension, a certificate invalidity indication based on an identification of one or more of:

an invalid response signature;

an inactive certificate validity period;

a certificate revocation; and

an invalid certificate authority.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 19, 2023
From: MONTGOMERY, ANDREW PAUL; BHANU, SANJAY; FORD, STUART DAVID; VARANDA, RICARDO
To: BANK OF AMERICA CORPORATION
Reel/Frame 065911/0729 →
Continuity (3)
Continuation 18068652 · Dec 20, 2022
Continuation 17143817 · Jan 7, 2021
Related Publication 20240121235A1 · Apr 11, 2024
References Cited (50)
US 7373662B2 · Foster et al. · 2008 [cited by applicant]
US 7558564B2 · Wesby · 2009 [cited by applicant]
US 7630986B1 · Herz et al. · 2009 [cited by applicant]
US 7908656B1 · Mu · 2011 [cited by applicant]
US 8448241B1 · Kadakia · 2013 [cited by examiner]
US 8457622B2 · Wesby · 2013 [cited by applicant]
US 8549298B2 · Rouskov et al. · 2013 [cited by applicant]
US 8566901B2 · Kay et al. · 2013 [cited by applicant]
US 8566919B2 · Meisel · 2013 [cited by applicant]
US 8838973B1 · Yung et al. · 2014 [cited by applicant]
US 9225803B2 · Nanduri et al. · 2015 [cited by applicant]
US 9407624B1 · Myers et al. · 2016 [cited by applicant]
US 9578044B1 · Sharma et al. · 2017 [cited by applicant]
US 9589118B2 · Agarwal · 2017 [cited by applicant]
US 9691051B2 · Rexer et al. · 2017 [cited by applicant]
US 10157280B2 · Amir et al. · 2018 [cited by applicant]
US 10462216B1 · Vysotsky et al. · 2019 [cited by applicant]
US 11036864B2 · Rangaraj · 2021 [cited by applicant]
US 11132425B1 · Cohen et al. · 2021 [cited by applicant]
US 20030105971A1 · Angelo et al. · 2003 [cited by applicant]
US 20060085421A1 · Backhouse et al. · 2006 [cited by applicant]
US 20080140442A1 · Warner · 2008 [cited by examiner]
US 20090170532A1 · Lee et al. · 2009 [cited by applicant]
US 20090253408A1 · Fitzgerald et al. · 2009 [cited by applicant]
US 20090282485A1 · Bennett · 2009 [cited by applicant]
US 20090292925A1 · Meisel · 2009 [cited by applicant]
US 20100275024A1 · Abdulhayoglu · 2010 [cited by examiner]
US 20120185910A1 · Miettinen et al. · 2012 [cited by applicant]
US 20130007465A1 · Movassaghi · 2013 [cited by applicant]
US 20130019092A1 · Levow · 2013 [cited by applicant]
US 20130173455A1 · Adams et al. · 2013 [cited by applicant]
US 20140331285A1 · Desai · 2014 [cited by applicant]
US 20160142438A1 · Pastore et al. · 2016 [cited by applicant]
US 20160254954A1 · King et al. · 2016 [cited by applicant]
US 20170026363A1 · Sauve · 2017 [cited by examiner]
US 20170034166A1 · Sonoda et al. · 2017 [cited by applicant]
US 20170257393A1 · De Barros et al. · 2017 [cited by applicant]
US 20180288026A1 · Callaghan · 2018 [cited by applicant]
US 20180295137A1 · Zager et al. · 2018 [cited by applicant]
US 20190215304A1 · Yang et al. · 2019 [cited by applicant]
US 20190222588A1 · Marzorati et al. · 2019 [cited by applicant]
US 20200082124A1 · Pedersen · 2020 [cited by applicant]
US 20200250316A1 · Rickerd et al. · 2020 [cited by applicant]
US 20200356661A1 · Stoletny et al. · 2020 [cited by applicant]
US 20200394326A1 · Maruyama et al. · 2020 [cited by applicant]
EP 2854365A1 · 2015 [cited by examiner]
E. Lawrence, “Avoiding the Not Secure Warning in Chrome”, published Dec. 2020, The Wayback Machine—https://web.archineve.org/web/20201212211208/ visited on Aug. 28, 2021, pp. 4. [cited by applicant]
J. White, “Improve Your Privacy and Security with HTTPS Everywhere”, published Aug. 25, 2017, https://mediam.com, visited on Aug. 28, 2021, pp. 5. [cited by applicant]
Serge Truth, How to Test for Man-in-the-Middle VulnerabilitiesHow Vulnerabilities, Published Jun. 21, 2011 by securityinnovation.com, pp. 1-23. [cited by applicant]
Amos Kingatua, 6 HTTP MITM Attack Tools for Security Researchers, Published Jul. 7, 2021 by geekflare.com, pp. 1-21. [cited by applicant]