- Patent Title: Web application session security with protected session identifiers
-
Application No.: US16002399Application Date: 2018-06-07
-
Publication No.: US10992759B2Publication Date: 2021-04-27
- Inventor: Martin Johns
- Applicant: SAP SE
- Applicant Address: DE Walldorf
- Assignee: SAP SE
- Current Assignee: SAP SE
- Current Assignee Address: DE Walldorf
- Agency: Schwegman Lundberg & Woessner, P.A.
- Main IPC: H04L29/08
- IPC: H04L29/08 ; H04L29/06

Abstract:
Various examples are directed to systems and methods for secure communication sessions between a web application and a server. A session vault routine executing at a computing device may receive a first request message directed to a server computing device. The first request message may comprise a client session identifier at a session identifier field of the first request message. The session vault routine may access supplemental session identifier data from a session vault persistence at the data storage. The session vault routine may write the supplemental session identifier data to a second field of the first request message, and initiate sending the first request message to the server computing device.
Information query