Client-side encryption of form data
Abstract
Disclosed are various embodiments that facilitate client-side encryption of form data. A network page is sent to a client. The network page includes executable encryption code configured to encrypt a form data item. The client is configured to receive the form data item via a form field of the network page. In response to receiving the form data item from the client, it is determined whether the form data item that has been received has been encrypted in the client by the executable encryption code. The form data item is then encrypted when the form data item that has been received has not been encrypted in the client by the executable encryption code. However, the form data item is not encrypted when the form data item that has been received has been encrypted in the client by the executable encryption code.
Claims
exact text as granted — not AI-modifiedTherefore, the following is claimed:
1 . A non-transitory computer-readable medium embodying a program executable in at least one computing device, comprising:
code that sends a network page to a client, the network page including executable encryption code configured to encrypt a form data item, wherein the client is configured to receive the form data item via a form field of the network page; code that, in response to receiving the form data item from the client over a separately encrypted channel, determines whether the form data item that has been received has been encrypted in the client by the executable encryption code; and code that encrypts the form data item in response to determining that the form data item that has been received has not been encrypted in the client by the executable encryption code, wherein the code that encrypts is configured to refrain from encrypting the form data item in response to determining that the form data item that has been received has been encrypted in the client by the executable encryption code.
2 . The non-transitory computer-readable medium of claim 1 , further comprising code that sends the form data item in an encrypted state to a server over an internal network.
3 . The non-transitory computer-readable medium of claim 2 , wherein a firewall is interposed between the internal network and the server to protect the server from the internal network.
4 . The non-transitory computer-readable medium of claim 1 , wherein the executable encryption code is configured to encrypt a subset of a plurality of form data items received via a plurality of form fields of the network page, the form data item being a member of the subset.
5 . The non-transitory computer-readable medium of claim 1 , wherein the form data item includes private data.
6 . The non-transitory computer-readable medium of claim 1 , wherein the executable encryption code and the code that encrypts are configured to encrypt the form data item using a particular public key.
7 . The non-transitory computer-readable medium of claim 1 , wherein the code that determines whether the form data item that has been received has been encrypted in the client by the executable encryption code further comprises:
code that determines a first form parameter name corresponding to the form data item being encrypted in the client and a second form parameter name corresponding to the form data item not being encrypted in the client; and code that determines whether the form data item is received under the first form parameter name or the second form parameter name.
8 . A system, comprising:
at least one computing device; and at least one application executed in the at least one computing device, the at least one application comprising:
logic that sends a network page to a client, the network page including executable encryption code configured to encrypt a form data item, wherein the client is configured to receive the form data item via a form field of the network page;
logic that, in response to receiving the form data item from the client, determines whether the form data item that has been received has been encrypted in the client by the executable encryption code; and
logic that encrypts the form data item in response to determining that the form data item that has been received has not been encrypted in the client by the executable encryption code, wherein the logic that encrypts is configured to refrain from encrypting the form data item in response to determining that the form data item that has been received has been encrypted in the client by the executable encryption code.
9 . The system of claim 8 , wherein the form data item is received over a separately encrypted channel.
10 . The system of claim 8 , wherein the at least one application further comprises logic that sends the form data item in an encrypted state to a server over an internal network, wherein a firewall is interposed between the internal network and the server to protect the server from the internal network.
11 . The system of claim 8 , wherein the executable encryption code is configured to encrypt fewer than all of a plurality of form data items received via a plurality of form fields of the network page.
12 . The system of claim 8 , wherein both the logic that encrypts and the executable encryption code are configured to perform encryption using a particular public key.
13 . The system of claim 8 , wherein the at least one application further comprises logic that determines whether the form data item is received under a first form parameter name or a second form parameter name.
14 . The system of claim 8 , wherein the form data item corresponds to user-provided private data.
15 . A method, comprising:
sending, via at least one of one or more computing devices, a network page to a client, the network page including executable encryption code configured to encrypt a user-provided private data item; receiving, via at least one of the one or more computing devices, the user-provided private data item from the client; determining, via at least one of the one or more computing devices, that the user-provided private data item has not been encrypted in the client by the executable encryption code; and encrypting, via at least one of the one or more computing devices, the user-provided private data item.
16 . The method of claim 15 , further comprising wherein determining that the user-provided private data item has not been encrypted by the executable encryption code further comprises determining that the user-provided private data item has been provided under a first form parameter name instead of a second form parameter name.
17 . The method of claim 15 , wherein the encrypting and the executable encryption code are configured to employ a particular public key for encryption.
18 . The method of claim 15 , wherein receiving the user-provided private data item from the client further comprises receiving the user-provided private data item from the client via a separately encrypted channel.
19 . The method of claim 15 , wherein the executable encryption code is configured to refrain from encrypting another user-provided data item.
20 . The method of claim 15 , wherein the client is configured to refrain from executing the executable encryption code.Join the waitlist — get patent alerts
Track US2015312217A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.