IP Library › Granted Patent US 12,627,660
Granted Patent B2
US 12,627,660 · App. 17/739,271 · Granted May 12, 2026

Cross-origin resource handling for web content

Inventor: Subramanian Krishnan (Bangalore, IN)
H04L63/0876H04L63/0236H04L63/20H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,627,660
App. No.
17/739,271
Granted
May 12, 2026
Kind
B2
Abstract

One disclosed method involves receiving, by a browser and from a first origin, preauthorization data identifying a plurality of other origins that are permitted to send instructions to the browser that cause the browser to access one or more resources at the first origin, determining, by the browser, that data received from a second origin includes a first instruction to access a first resource at the first origin, determining, by the browser, that the second origin is included among the plurality of other origins identified by the preauthorization data, and accessing, by the browser and based at least in part on the second origin being included among the plurality of other origins, the first resource at the first origin based on the first instruction.

Claims (62)

1 . A method, comprising:

receiving, by a browser and from a first origin, preauthorization data identifying a plurality of other origins that are permitted to send instructions to the browser that cause the browser to access one or more resources at the first origin;

determining, by the browser, that data received from a second origin includes a first instruction to access a first resource at the first origin;

determining, by the browser, that the second origin is included among the plurality of other origins identified by the preauthorization data; and

accessing, by the browser and based at least in part on the second origin being included among the plurality of other origins, the first resource at the first origin based on the first instruction;

receiving, by the browser, additional data from a third origin, the additional data including a second instruction to access a second resource at the first origin;

determining, by the browser, that the third origin is unrepresented in the plurality of other origins identified in the preauthorization data;

in response to determining that the third origin is unrepresented in the plurality of other origins, sending, by the browser, a pre-access request to the first origin, the pre-access request including an indication of the third origin and the second instruction to access the second resource;

receiving, by the browser and from the first origin, an approval in response to the preaccess request; and

in response to receiving the approval, accessing, by the browser, the second resource at the first origin based on the second instruction.

2 . The method of claim 1 , further comprising:

in response to receiving the data from the second origin, determining that the preauthorization data for the first origin is unavailable at the browser;

causing the browser to download of the preauthorization data from the first origin; and

storing the preauthorization data in a memory of a computing device on which the browser is being accessed.

3 . The method of claim 1 , further comprising:

receiving, by the browser, a user input indicative of at least the first origin, receipt of the user input causing the browser to download the preauthorization data from the first origin.

4 . The method of claim 3 , further comprising:

receiving, by the browser, an additional user input indicative of a time period when the preauthorization data from the first origin is to be updated;

determining, by the browser, that time elapsed since previous download of the preauthorization data from the first origin satisfies the time period; and

in response to the time elapsed satisfying the time period, causing the browser to download updated preauthorization data from the first origin.

5 . The method of claim 1 , wherein the preauthorization data further identifies at least one Hypertext-Transfer-Protocol (HTTP) request method permitted to be used by at least one of the plurality of other origins to send instructions to the browser.

6 . The method of claim 1 , wherein the second origin is identified in the preauthorization data using a domain.

7 . The method of claim 1 , wherein the first origin is identified in the preauthorization data using a Uniform Resource Locator (URL).

8 . A system, comprising:

at least one processor; and

at least one computer-readable medium encoded with instructions which, when executed by the at least one processor, cause the system to:

receive, by a browser and from a first origin, preauthorization data identifying a plurality of other origins that are permitted to send instructions to the browser that cause the browser to access one or more resources at the first origin;

determine, by the browser, that data received from a second origin includes a first instruction to access a first resource at the first origin;

determine, by the browser, that the second origin is included among the plurality of other origins identified by the preauthorization data; and

access, by the browser and based at least in part on the second origin being included among the plurality of other origins, the first resource at the first origin based on the first instruction;

receive, by the browser, additional data from a third origin, the additional data including a second instruction to access a second resource at the first origin,

determine, by the browser, that the third origin is unrepresented in the plurality of other origins identified in the preauthorization data;

in response to determining that the third origin is unrepresented in the plurality of other origins, send, by the browser, a pre-access request to the first origin, the pre-access request including an indication of the third origin and the second instruction to access the second resource;

receive, by the browser and from the first origin, an approval in response to the preaccess request, and

in response to receiving the approval, access, by the browser, the second resource at the first origin based on the second instruction.

9 . The system of claim 8 , wherein the at least one computer-readable medium is further encoded with additional instructions which, when executed by the at least one processor, further cause the system to:

in response to receiving the data from the second origin, determine that the preauthorization data for the first origin is unavailable at the browser;

cause the browser to download of the preauthorization data from the first origin; and

store the preauthorization data in a memory of the system on which the browser is being accessed.

10 . The system of claim 8 , wherein the at least one computer-readable medium is further encoded with additional instructions which, when executed by the at least one processor, further cause the system to:

receive, by the browser, a user input indicative of at least the first origin, receipt of the user input causing the browser to download the preauthorization data from the first origin.

11 . The system of claim 10 , wherein the at least one computer-readable medium is further encoded with additional instructions which, when executed by the at least one processor, further cause the system to:

receive, by the browser, an additional user input indicative of a time period when the preauthorization data from the first origin is to be updated;

determine, by the browser, that time elapsed since previous download of the preauthorization data from the first origin satisfies the time period; and

in response to the time elapsed satisfying the time period, cause the browser to download updated preauthorization data from the first origin.

12 . The system of claim 8 , wherein the preauthorization data further identifies at least one Hypertext-Transfer-Protocol (HTTP) request method permitted to be used by at least one of the plurality of other origins to send instructions to the browser.

13 . The system of claim 8 , wherein the second origin is identified in the preauthorization data using a domain.

14 . The system of claim 8 , wherein the first origin is identified in the preauthorization data using a Uniform Resource Locator (URL).

15 . At least one non-transitory computer-readable medium encoded with instructions which, when executed by at least one processor of a system, cause the system to:

receive, by a browser and from a first origin, preauthorization data identifying a plurality of other origins that are permitted to send instructions to the browser that cause the browser to access one or more resources at the first origin;

determine, by the browser, that data received from a second origin includes a first instruction to access a first resource at the first origin;

determine, by the browser, that the second origin is included among the plurality of other origins identified by the preauthorization data;

access, by the browser and based at least in part on the second origin being included among the plurality of other origins, the first resource at the first origin based on the first instruction;

receive, by the browser, additional data from a third origin, the additional data including a second instruction to access a second resource at the first origin;

determine, by the browser, that the third origin is unrepresented in the plurality of other origins identified in the preauthorization data;

in response to determining that the third origin is unrepresented in the plurality of other origins, send, by the browser, a pre-access request to the first origin, the pre-access request including an indication of the third origin and the second instruction to access the second resource;

receive, by the browser and from the first origin, an approval response to the preaccess request; and

in response to receiving the approval, access, by the browser, the second resource at the first origin based on the second instruction.

16 . The at least one non-transitory computer-readable medium of claim 15 , further encoded with additional instructions which, when executed by the at least one processor, further cause the system to:

in response to receiving the data from the second origin, determine that the preauthorization data for the first origin is unavailable at the browser;

cause the browser to download of the preauthorization data from the first origin; and

store the preauthorization data in a memory of the system on which the browser is being accessed.

Assignments (3)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 9, 2022
From: KRISHNAN, SUBRAMANIAN
To: CITRIX SYSTEMS, INC.
Reel/Frame 059867/0519 →
Continuity (1)
Related Publication 20230362160A1 · Nov 9, 2023
References Cited (16)
US 7984170B1 · Shalla · 2011 [cited by examiner]
US 8667573B2 · Lawrence · 2014 [cited by examiner]
US 10084794B2 · Goldfarb · 2018 [cited by examiner]
US 10827023B1 · Yan · 2020 [cited by examiner]
US 11582131B2 · Chauhan · 2023 [cited by examiner]
US 11658822B1 · Engers · 2023 [cited by examiner]
US 20080178264A1 · Keohane · 2008 [cited by examiner]
US 20090049557A1 · Friedman · 2009 [cited by examiner]
US 20100251270A1 · Dale · 2010 [cited by examiner]
US 20140157369A1 · Mischook · 2014 [cited by examiner]
US 20150143223A1 · Kolam · 2015 [cited by examiner]
US 20150143467A1 · Hebert · 2015 [cited by examiner]
US 20150180846A1 · Nguyen · 2015 [cited by examiner]
US 20200065505A1 · Wall · 2020 [cited by examiner]
US 20200137120A1 · Frisbie · 2020 [cited by examiner]
US 20220035613A1 · Wada · 2022 [cited by examiner]