Patent · US Active

Dealing with web attacks using cryptographically signed HTTP cookies

US8448233B2 · kind B2 · utility

8Cited by
8References
73Claims
0Family size

Assignee

Inventors

Key dates

Filing dateAug 25, 2011
Grant dateMay 21, 2013
Priority date
Expiry dateSep 29, 2031

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L67/02
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

According to one embodiment, a security gateway (SG) is coupled between a hypertext transport protocol (HTTP) client and a web application server. Responsive to a first HTTP message being transmitted between the HTTP client and the web application server as part of an HTTP session, the SG generates security gateway session security state information (SGI) based on a policy. The SG also generates a digital signature (SGS) from the SGI, creates an SG signed session security state information cookie (SGC), and sends the SGC to the HTTP client for storage instead of storing the SGI in the SG. Responsive to a second HTTP message of the HTTP session, the SG attempts to validate a claim made in the second HTTP request using at least the policy and the SGC that is supposed to be returned with the second HTTP message.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.