发明授权
- 专利标题: Method and device for preventing CSRF attack
- 专利标题(中): 防止CSRF攻击的方法和设备
-
申请号: US13621238申请日: 2012-09-15
-
公开(公告)号: US08997222B2公开(公告)日: 2015-03-31
- 发明人: Dikran S. Meliksetian , Gang Niu , Qiang Guo Tong
- 申请人: Dikran S. Meliksetian , Gang Niu , Qiang Guo Tong
- 申请人地址: US NY Armonk
- 专利权人: International Business Machines Corporation
- 当前专利权人: International Business Machines Corporation
- 当前专利权人地址: US NY Armonk
- 代理机构: Yudell Isidore PLLC
- 代理商 Parashos Kalaitzis
- 优先权: CN201010580357 20101130
- 主分类号: G06F17/30
- IPC分类号: G06F17/30 ; G06F12/14 ; G08B23/00 ; H04L29/08 ; H04L29/06 ; H04N7/167
摘要:
The disclosure provides method for preventing CSRF attacks, in which the method provides: intercepting request sent from a client browser to a server; generating a token; generating a response to the request; inserting the token into the response to the request; and sending the response to the request to the client browser with the token inserted into the response. With the method of the disclosure, it is assured that a token is inserted into all the requests made by a user through a client browser for accessing a resource. And it can be assured that the request is issued by the user himself by verifying whether the token in the request is valid, thereby preventing a CSRF attack.
公开/授权文献
- US20130019308A1 Method and Device for Preventing CSRF Attack 公开/授权日:2013-01-17
信息查询