会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 1. 发明申请
    • TRANSACTION VERIFICATION
    • 交易验证
    • US20140006780A1
    • 2014-01-02
    • US13919883
    • 2013-06-17
    • NetAuthority, Inc.
    • Talbot HARTYDono HARJANTOKarim KADDOURAPrakash CHANDRA
    • H04L29/06
    • H04L63/0428H04L63/12
    • A client computer returns to a server, not only form data entered by the user representing an action to be taken by the server, but also a hash of the form data that is generated by a cryptographic hash function prior to returning the form data. As a result, the hash is generated before any man-in-the-browser proxy has the opportunity to modify the form data. The server receives the hash of the form data generated before any man-in-the-browser proxy had access to the form data. If a hash of the form data does not match the received hash, the server detects modification of the form data, perhaps by a man-in-the-browser proxy, and accordingly declines to perform the requested action.
    • 客户端计算机返回到服务器,不仅形成由用户输入的表示服务器将采取的动作的数据,而且还返回由返回表单数据之前由密码散列函数生成的表单数据的散列。 因此,在任何浏览器代理程序有机会修改表单数据之前生成散列。 服务器接收在任何浏览器代理程序访问表单数据之前生成的表单数据的哈希值。 如果表单数据的散列与接收到的散列不匹配,则服务器可能会检测到表单数据的修改,也许是由浏览器代理人,因此拒绝执行请求的操作。