发明授权
- 专利标题: Systems and methods for cross site forgery protection
- 专利标题(中): 跨站点防伪系统和方法
-
申请号: US12645924申请日: 2009-12-23
-
公开(公告)号: US08640216B2公开(公告)日: 2014-01-28
- 发明人: Craig Anderson , Anoop Reddy , Yariv Keinan
- 申请人: Craig Anderson , Anoop Reddy , Yariv Keinan
- 申请人地址: US FL Fort Lauderdale
- 专利权人: Citrix Systems, Inc.
- 当前专利权人: Citrix Systems, Inc.
- 当前专利权人地址: US FL Fort Lauderdale
- 代理机构: Foley & Lardner LLP
- 代理商 Christopher J. McKenna
- 主分类号: G06F17/00
- IPC分类号: G06F17/00 ; H04L29/06
摘要:
The present solution described herein is directed towards systems and methods to prevent cross-site request forgeries based on web form verification using unique identifiers. The present solution tags each form from a server that is served out in the response with a unique and unpredictable identifier. When the form is posted, the present solution enforces that the identifier being returned is the same as the one that was served out to the user. This prevents malicious unauthorized third party users from submitting a form on a user's behalf since they cannot guess the value of this unique identifier that was inserted.
公开/授权文献
- US20110154473A1 SYSTEMS AND METHODS FOR CROSS SITE FORGERY PROTECTION 公开/授权日:2011-06-23
信息查询