Patent · US Active

Scalable session management

US7890634B2 · kind B2 · utility

20Cited by
3References
17Claims
0Family size

Assignee

Inventors

Key dates

Filing dateMar 18, 2005
Grant dateFeb 15, 2011
Priority date
Expiry dateJan 31, 2028

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F21/6218
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Scalable session management is achieved by generating a cookie that includes an encrypted session key and encrypted cookie data. The cookie data is encrypted using the session key. The session key is then signed and encrypted using one or more public/private key pairs. The encrypted session key can be decrypted and verified using the same private/public key pair(s). Once verified, the decrypted session key can then be used to decrypt and verify the encrypted cookie data. A first server having the private/public key pair(s) may generate the cookie using a randomly generated session key. A second server having the same private/public key pair(s) may decrypt and verify the cookie even if the session key is not initially installed on the second server. A session key cache may be used to provide session key lookup to save public/private key operations on the servers.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.