发明名称 ENHANCED SECURITY AND PERFORMANCE OF WEB APPLICATIONS
摘要 A client-side enforcement mechanism may allow application security policies to be specified at a server in a programmatic manner. Servers may specify security policies as JavaScript functions included in a page returned by the server and run before other scripts. At runtime, and during initial loading, the functions are invoked by the client on each page modification to ensure the page conforms to the security policy. As such, before a mutation takes effect, the policy may transform that mutation and the code and data of the page. Replicated code execution may take place at both the client and the server where the server runs its own shadow copy of a client-side application in a trusted execution environment so that the server may check that the method calls coming from the client correspond to a correct execution of the client-side application The redundant execution at the client can be untrusted, but serves to improve the responsiveness and performance of the Web application.
申请公布号 US2009138937(A1) 申请公布日期 2009.05.28
申请号 US20070944460 申请日期 2007.11.23
申请人 MICROSOFT CORPORATION 发明人 ERLINGSSON ULFAR;XIE YINGLIAN;LIVSHITS BEN;FOURNET CEDRIC
分类号 H04L9/00 主分类号 H04L9/00
代理机构 代理人
主权项
地址