Electrical computers and digital processing systems: support – System access control based on user identification by...
Reexamination Certificate
2005-04-05
2005-04-05
Morse, Gregory (Department: 2134)
Electrical computers and digital processing systems: support
System access control based on user identification by...
C713S152000, C713S182000, C709S228000, C707S793000
Reexamination Certificate
active
06877095
ABSTRACT:
Without actually storing session-state information, the described exemplary implementations of session-state manager identify a user, validate the user's current logon state, and determine whether the user's session should expire. User identification and logon validation are checked by a server in a stateless network by generating a mathematically session-state token and sending that token to a user. Subsequently, the server receives a mathematically session-state token from the user and checks that token. If that token checks out, then the user is allowed continuing access under the same session. If it doesn't check out, then the user may be forced to start a new session by logging-on again. Alternatively, the server may check to see if the token would check out if it had come at an earlier time block. The session-state tokens are mathematical encoded and are generated using a one-way encryption scheme. Such a one-way encrypted token is scientifically impossible to reverse-engineer. Furthermore, logon expiration is checked by the server using the same mathematically session-state token. The token is checked to determine whether a predetermined number of time blocks have past. If so, then the server will terminate the user's session.
REFERENCES:
patent: 5491752 (1996-02-01), Kaufman et al.
patent: 5542046 (1996-07-01), Carlson et al.
patent: 5835724 (1998-11-01), Smith
patent: 5907621 (1999-05-01), Bachman et al.
patent: 6041357 (2000-03-01), Kunzelman et al.
patent: 6065117 (2000-05-01), White
patent: 6496824 (2002-12-01), Wilf
patent: WO 9740457 (1997-10-01), None
Ho Thomas
Lee & Hayes PLLC
Microsoft Corporation
Morse Gregory
LandOfFree
Session-state manager does not yet have a rating. At this time, there are no reviews or comments for this patent.
If you have personal experience with Session-state manager, we encourage you to share that experience with our LandOfFree.com community. Your opinion is very important and Session-state manager will most certainly appreciate the feedback.
Profile ID: LFUS-PAI-O-3393546