Prevention of forgery of web requests to a server

US9780951B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9780951-B2
Application numberUS-201313931120-A
CountryUS
Kind codeB2
Filing dateJun 28, 2013
Priority dateMar 14, 2013
Publication dateOct 3, 2017
Grant dateOct 3, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Technologies for prevention of forgery of a network communication request to a server include a system for security of a network communication request. The system includes a communication module configured to receive the network communication request from a client. The network communication request may have a content parameter. The communication module may be configured to generate a string of content parameters comprising the content parameters and a hash of the content parameter, and communicate portions of a result of the network communication request to the client incorporating the encrypted string of content parameters. Furthermore, the communication module may receive a subsequent request from the client. The subsequent request may be associated with the network communication request. As a result of authenticating the subsequent request, the communication module may complete the network communication request.

First claim

Opening claim text (preview).

What is claimed is: 1. A system for security of a network communication request comprising a processor, a memory, an encrypt/decrypt module, and a communication module, the system configured to: receive the network communication request from a client, the network communication request having a content parameter; generate a hash of the content parameter; subsequent to generation of the hash of the content parameter, append the hash of the content parameter to the content parameter to generate a string of content parameters comprising the content parameter and the hash of the content parameter; generate a session variable that is unique to the client, wherein the session variable is a random variable, and wherein only the communication module is provided access to the session variable; encrypt the string of content parameters using the session variable; communicate portions of a result of the network communication request to the client incorporating the encrypted string of content parameters; receive a subsequent request from the client, the subsequent request associated with the network communication request; authenticate the subsequent request by verifying that the encrypted string of content parameters returns with the subsequent request; and as a result of authenticating the subsequent request, complete the network communication request. 2. The system of claim 1 , wherein the network communication request is a web request. 3. The system of claim 1 , wherein the session variable is further associated with the network communication request. 4. The system of claim 1 , wherein the subsequent request is an asynchronous JavaScript and extensible markup language (AJAX) request. 5. The system of claim 1 , wherein the hash is a cryptographic hash. 6. A method for network communications, comprising: receiving, at a server, a network communication request from a client, the network communication request comprising a request for a content parameter; generating a hash of the content parameter; subsequent to generating the hash of the content parameter, appending the hash of the content parameter to the content parameter to generate, at the server, a string of content parameters comprising the content parameter and the hash of the content parameter; generating, at the server, a session variable that is unique to the client, wherein the session variable is a random variable, and wherein only the server is provided access to the session variable; encrypting, at the server, the string of content parameters using the session variable; communicating portions of a result of the network communication request to the client incorporating the encrypted string of content parameters; receiving, at the server, a subsequent request from the client, the subsequent request associated with the network communication request; authenticating the subsequent request by verifying that the encrypted string of content parameters returns with the subsequent request; and as a result of authenticating the subsequent request, completing the network communication request. 7. The method of claim 6 , wherein the network communication request is a web request. 8. The method of claim 6 , wherein the session variable is further associated with the network communication request. 9. The method of claim 6 , wherein the subsequent request is an asynchronous JavaScript and extensible markup language (AJAX) request. 10. The method of claim 6 , wherein the hash is a cryptographic hash. 11. One or more non-transitory computer readable storage medium, comprising computer-executable instructions carried on the one or more computer readable storage medium, the instructions readable by a processor, the instructions, when read and executed, causing the processor to: receive a network communication request from a client, the network communication request comprising a request for a content parameter; generate a hash of the content parameter; subsequent to generation of the hash of the content parameter, append the hash of the content parameter to the content parameter to generate a string of content parameters comprising the content parameter and the hash of the content parameter; generate a session variable that is unique to the client, wherein the session variable is a random variable, and wherein only the processor is provided access to the session variable; encrypt the string of content parameters using the session variable; communicate portions of a result of the network communication request to the client incorporating the encrypted string of content parameters; receive a subsequent request from the client, the subsequent request associated with the network communication request; authenticate the subsequent request by verifying that the encrypted string of content parameters returns with the subsequent request; and as a result of authenticating the subsequent request, complete the network communication request. 12. The medium of claim 11 , wherein the network communication request is a web request. 13. The medium of claim 11 , wherein the session variable is further associated with the network communication request. 14. The medium of claim 11 , wherein the subsequent request is an asynchronous JavaScript and extensible markup language (AJAX) request.

Assignees

Inventors

Classifications

  • Applying verification of the received information (cryptographic mechanisms or cryptographic arrangements for data integrity or data verification H04L9/32) · CPC title

  • for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title

  • H04L9/3223Primary

    Electricity · mapped topic

  • wherein the data content is protected, e.g. by encrypting or encapsulating the payload · CPC title

  • H04L9/3236Primary

    using cryptographic hash functions · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9780951B2 cover?
Technologies for prevention of forgery of a network communication request to a server include a system for security of a network communication request. The system includes a communication module configured to receive the network communication request from a client. The network communication request may have a content parameter. The communication module may be configured to generate a string of …
Who is the assignee on this patent?
Hunt Simon, Singh Balbir, Munjal Nitin, and 2 more
What technology area does this patent fall under?
Primary CPC classification H04L9/3223. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Oct 03 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).