SYSTEMS AND METHODS FOR PREVENTING SESSION FIXATION OVER DOMAIN PORTAL

In one embodiment, a method includes a system receiving a request from a user's device, the request being directed to a first host. The system may generate a key, a verification token, and an encrypted key. The system may transmit the verification token and the encrypted key to the device from...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: ELLINGSEN ERLING, DUVDEVANI ITAY, HAFIF OREN, UDASSIN ROY
Format: Patent
Sprache:chi ; eng
Schlagworte:
Online-Zugang:Volltext bestellen
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
container_end_page
container_issue
container_start_page
container_title
container_volume
creator ELLINGSEN ERLING
DUVDEVANI ITAY
HAFIF OREN
UDASSIN ROY
description In one embodiment, a method includes a system receiving a request from a user's device, the request being directed to a first host. The system may generate a key, a verification token, and an encrypted key. The system may transmit the verification token and the encrypted key to the device from the first host, and transmit instructions configured to cause (1) the verification token to be stored asa cookie associated with the first host, and (2) the device to transmit the encrypted key to a second host. The system may receive a second request comprising the encrypted key from the device, and decrypt it to obtain the key upon determining that the encrypted key was not previously decrypted. The system may transmit the key to the device from the second host, and instruct the device to store the key as a cookie associated with the second host. 在一个实施例中,方法包括系统从用户的设备接收请求,该请求被定向到第一主机。系统可以生成密钥、验证令牌和加密密钥。系统可以从第一主机向设备传输验证令牌和加密密钥,并且传输指令,指令被配置成使得:(1)验证令牌被存储为与第一主机相关联的cookie,以及(2)设备向第二主机传输加密密钥。系统可以从设备接收包括加密密钥的第二请求,并在确定加密密钥之前未
format Patent
fullrecord <record><control><sourceid>epo_EVB</sourceid><recordid>TN_cdi_epo_espacenet_CN110771112A</recordid><sourceformat>XML</sourceformat><sourcesystem>PC</sourcesystem><sourcerecordid>CN110771112A</sourcerecordid><originalsourceid>FETCH-epo_espacenet_CN110771112A3</originalsourceid><addsrcrecordid>eNrjZHALjgwOcfUNVnD0c1HwdQ3x8HcJVnDzD1IICHINc_UL8fRzVwh2DQ729PdTcPOMcAwBMfzDXIMUXPx9HT39FAL8g0IcfXgYWNMSc4pTeaE0N4Oim2uIs4duakF-fGpxQWJyal5qSbyzn6Ghgbm5oaGhkaMxMWoA13osiw</addsrcrecordid><sourcetype>Open Access Repository</sourcetype><iscdi>true</iscdi><recordtype>patent</recordtype></control><display><type>patent</type><title>SYSTEMS AND METHODS FOR PREVENTING SESSION FIXATION OVER DOMAIN PORTAL</title><source>esp@cenet</source><creator>ELLINGSEN ERLING ; DUVDEVANI ITAY ; HAFIF OREN ; UDASSIN ROY</creator><creatorcontrib>ELLINGSEN ERLING ; DUVDEVANI ITAY ; HAFIF OREN ; UDASSIN ROY</creatorcontrib><description>In one embodiment, a method includes a system receiving a request from a user's device, the request being directed to a first host. The system may generate a key, a verification token, and an encrypted key. The system may transmit the verification token and the encrypted key to the device from the first host, and transmit instructions configured to cause (1) the verification token to be stored asa cookie associated with the first host, and (2) the device to transmit the encrypted key to a second host. The system may receive a second request comprising the encrypted key from the device, and decrypt it to obtain the key upon determining that the encrypted key was not previously decrypted. The system may transmit the key to the device from the second host, and instruct the device to store the key as a cookie associated with the second host. 在一个实施例中,方法包括系统从用户的设备接收请求,该请求被定向到第一主机。系统可以生成密钥、验证令牌和加密密钥。系统可以从第一主机向设备传输验证令牌和加密密钥,并且传输指令,指令被配置成使得:(1)验证令牌被存储为与第一主机相关联的cookie,以及(2)设备向第二主机传输加密密钥。系统可以从设备接收包括加密密钥的第二请求,并在确定加密密钥之前未</description><language>chi ; eng</language><subject>ELECTRIC COMMUNICATION TECHNIQUE ; ELECTRICITY ; TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHICCOMMUNICATION</subject><creationdate>2020</creationdate><oa>free_for_read</oa><woscitedreferencessubscribed>false</woscitedreferencessubscribed></display><links><openurl>$$Topenurl_article</openurl><openurlfulltext>$$Topenurlfull_article</openurlfulltext><thumbnail>$$Tsyndetics_thumb_exl</thumbnail><linktohtml>$$Uhttps://worldwide.espacenet.com/publicationDetails/biblio?FT=D&amp;date=20200207&amp;DB=EPODOC&amp;CC=CN&amp;NR=110771112A$$EHTML$$P50$$Gepo$$Hfree_for_read</linktohtml><link.rule.ids>230,308,778,883,25551,76302</link.rule.ids><linktorsrc>$$Uhttps://worldwide.espacenet.com/publicationDetails/biblio?FT=D&amp;date=20200207&amp;DB=EPODOC&amp;CC=CN&amp;NR=110771112A$$EView_record_in_European_Patent_Office$$FView_record_in_$$GEuropean_Patent_Office$$Hfree_for_read</linktorsrc></links><search><creatorcontrib>ELLINGSEN ERLING</creatorcontrib><creatorcontrib>DUVDEVANI ITAY</creatorcontrib><creatorcontrib>HAFIF OREN</creatorcontrib><creatorcontrib>UDASSIN ROY</creatorcontrib><title>SYSTEMS AND METHODS FOR PREVENTING SESSION FIXATION OVER DOMAIN PORTAL</title><description>In one embodiment, a method includes a system receiving a request from a user's device, the request being directed to a first host. The system may generate a key, a verification token, and an encrypted key. The system may transmit the verification token and the encrypted key to the device from the first host, and transmit instructions configured to cause (1) the verification token to be stored asa cookie associated with the first host, and (2) the device to transmit the encrypted key to a second host. The system may receive a second request comprising the encrypted key from the device, and decrypt it to obtain the key upon determining that the encrypted key was not previously decrypted. The system may transmit the key to the device from the second host, and instruct the device to store the key as a cookie associated with the second host. 在一个实施例中,方法包括系统从用户的设备接收请求,该请求被定向到第一主机。系统可以生成密钥、验证令牌和加密密钥。系统可以从第一主机向设备传输验证令牌和加密密钥,并且传输指令,指令被配置成使得:(1)验证令牌被存储为与第一主机相关联的cookie,以及(2)设备向第二主机传输加密密钥。系统可以从设备接收包括加密密钥的第二请求,并在确定加密密钥之前未</description><subject>ELECTRIC COMMUNICATION TECHNIQUE</subject><subject>ELECTRICITY</subject><subject>TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHICCOMMUNICATION</subject><fulltext>true</fulltext><rsrctype>patent</rsrctype><creationdate>2020</creationdate><recordtype>patent</recordtype><sourceid>EVB</sourceid><recordid>eNrjZHALjgwOcfUNVnD0c1HwdQ3x8HcJVnDzD1IICHINc_UL8fRzVwh2DQ729PdTcPOMcAwBMfzDXIMUXPx9HT39FAL8g0IcfXgYWNMSc4pTeaE0N4Oim2uIs4duakF-fGpxQWJyal5qSbyzn6Ghgbm5oaGhkaMxMWoA13osiw</recordid><startdate>20200207</startdate><enddate>20200207</enddate><creator>ELLINGSEN ERLING</creator><creator>DUVDEVANI ITAY</creator><creator>HAFIF OREN</creator><creator>UDASSIN ROY</creator><scope>EVB</scope></search><sort><creationdate>20200207</creationdate><title>SYSTEMS AND METHODS FOR PREVENTING SESSION FIXATION OVER DOMAIN PORTAL</title><author>ELLINGSEN ERLING ; DUVDEVANI ITAY ; HAFIF OREN ; UDASSIN ROY</author></sort><facets><frbrtype>5</frbrtype><frbrgroupid>cdi_FETCH-epo_espacenet_CN110771112A3</frbrgroupid><rsrctype>patents</rsrctype><prefilter>patents</prefilter><language>chi ; eng</language><creationdate>2020</creationdate><topic>ELECTRIC COMMUNICATION TECHNIQUE</topic><topic>ELECTRICITY</topic><topic>TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHICCOMMUNICATION</topic><toplevel>online_resources</toplevel><creatorcontrib>ELLINGSEN ERLING</creatorcontrib><creatorcontrib>DUVDEVANI ITAY</creatorcontrib><creatorcontrib>HAFIF OREN</creatorcontrib><creatorcontrib>UDASSIN ROY</creatorcontrib><collection>esp@cenet</collection></facets><delivery><delcategory>Remote Search Resource</delcategory><fulltext>fulltext_linktorsrc</fulltext></delivery><addata><au>ELLINGSEN ERLING</au><au>DUVDEVANI ITAY</au><au>HAFIF OREN</au><au>UDASSIN ROY</au><format>patent</format><genre>patent</genre><ristype>GEN</ristype><title>SYSTEMS AND METHODS FOR PREVENTING SESSION FIXATION OVER DOMAIN PORTAL</title><date>2020-02-07</date><risdate>2020</risdate><abstract>In one embodiment, a method includes a system receiving a request from a user's device, the request being directed to a first host. The system may generate a key, a verification token, and an encrypted key. The system may transmit the verification token and the encrypted key to the device from the first host, and transmit instructions configured to cause (1) the verification token to be stored asa cookie associated with the first host, and (2) the device to transmit the encrypted key to a second host. The system may receive a second request comprising the encrypted key from the device, and decrypt it to obtain the key upon determining that the encrypted key was not previously decrypted. The system may transmit the key to the device from the second host, and instruct the device to store the key as a cookie associated with the second host. 在一个实施例中,方法包括系统从用户的设备接收请求,该请求被定向到第一主机。系统可以生成密钥、验证令牌和加密密钥。系统可以从第一主机向设备传输验证令牌和加密密钥,并且传输指令,指令被配置成使得:(1)验证令牌被存储为与第一主机相关联的cookie,以及(2)设备向第二主机传输加密密钥。系统可以从设备接收包括加密密钥的第二请求,并在确定加密密钥之前未</abstract><oa>free_for_read</oa></addata></record>
fulltext fulltext_linktorsrc
identifier
ispartof
issn
language chi ; eng
recordid cdi_epo_espacenet_CN110771112A
source esp@cenet
subjects ELECTRIC COMMUNICATION TECHNIQUE
ELECTRICITY
TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHICCOMMUNICATION
title SYSTEMS AND METHODS FOR PREVENTING SESSION FIXATION OVER DOMAIN PORTAL
url https://sfx.bib-bvb.de/sfx_tum?ctx_ver=Z39.88-2004&ctx_enc=info:ofi/enc:UTF-8&ctx_tim=2025-01-15T18%3A08%3A43IST&url_ver=Z39.88-2004&url_ctx_fmt=infofi/fmt:kev:mtx:ctx&rfr_id=info:sid/primo.exlibrisgroup.com:primo3-Article-epo_EVB&rft_val_fmt=info:ofi/fmt:kev:mtx:patent&rft.genre=patent&rft.au=ELLINGSEN%20ERLING&rft.date=2020-02-07&rft_id=info:doi/&rft_dat=%3Cepo_EVB%3ECN110771112A%3C/epo_EVB%3E%3Curl%3E%3C/url%3E&disable_directlink=true&sfx.directlink=off&sfx.report_link=0&rft_id=info:oai/&rft_id=info:pmid/&rfr_iscdi=true