会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 10. 发明申请
    • Method and Apparatus for Protecting a Single Sign-on Domain from Credential Leakage
    • 用于保护单个登录域免受凭据泄漏的方法和装置
    • US20130086656A1
    • 2013-04-04
    • US13252931
    • 2011-10-04
    • Michael W. PaddonJessica M. FlanaganCraig M. Brown
    • Michael W. PaddonJessica M. FlanaganCraig M. Brown
    • G06F21/00
    • G01S19/32G01S19/246G01S19/421G01S19/48H04L63/0815H04W4/02
    • Disclosed is a method for protecting a single sign-on domain from credential leakage. In the method, an authentication server provides an authentication cookie to a browser client. The cookie has at least one user authentication credential for the domain, and is associated with an authentication subdomain of the domain. The server receives the cookie from the browser client. Upon authentication of the user authentication credential in the received cookie, the server responds to the access request by forwarding, to the browser client, a limited-use cookie for the domain. The server receives a request from the content server to validate a session identifier of the limited-use cookie received from the browser client. Upon validation of the session identifier of the limited-use cookie, the server provides a valid session message to the content server for enabling the content server to forward requested content to the browser client.
    • 公开了一种保护单点登录域免受凭据泄漏的方法。 在该方法中,认证服务器向浏览器客户端提供认证cookie。 该cookie具有至少一个域的用户认证证书,并且与域的认证子域相关联。 服务器从浏览器客户端接收cookie。 在接收到的cookie中的用户认证凭证的认证之后,服务器通过向浏览器客户端转发该域的有限使用的cookie来响应该访问请求。 服务器接收来自内容服务器的请求,以验证从浏览器客户端接收的有限用途的cookie的会话标识符。 在验证有限用途cookie的会话标识符之后,服务器向内容服务器提供有效的会话消息,以使内容服务器能够将所请求的内容转发给浏览器客户端。