Mitigating forgery of electronic submissions

Information security – Access control or authentication – Network

Reexamination Certificate

Rate now

  [ 0.00 ] – not rated yet Voters 0   Comments 0

Details

Reexamination Certificate

active

08051465

ABSTRACT:
Cross Site Request Forgery (CSRF) and other types of fraudulent submission in an electronic environment can be mitigated using state information that typically is already maintained for various users. Each submission requiring authentication includes a state identifier (ID). The state ID is compared to corresponding a state ID submitted in a relatively secure format, such as in a secure token or cookie. If the state ID matches a state ID in the secure token received from the user, and the state ID is valid, the submission is processed. Otherwise an interstitial page, including the state ID and a secure token, is generated to prompt the user to confirm the submission. A subsequent confirmation submission will contain the proper state ID and the new cookie, and can be processed. If no confirmation is received from the user with a valid state ID, the submission is not processed.

REFERENCES:
patent: 2008/0115201 (2008-05-01), Sturms et al.

LandOfFree

Say what you really think

Search LandOfFree.com for the USA inventors and patents. Rate them and share your experience with other people.

Rating

Mitigating forgery of electronic submissions does not yet have a rating. At this time, there are no reviews or comments for this patent.

If you have personal experience with Mitigating forgery of electronic submissions, we encourage you to share that experience with our LandOfFree.com community. Your opinion is very important and Mitigating forgery of electronic submissions will most certainly appreciate the feedback.

Rate now

     

Profile ID: LFUS-PAI-O-4289500

  Search
All data on this website is collected from public sources. Our data reflects the most accurate information available at the time of publication.