Mixed-mode authentication
    1.
    发明授权
    Mixed-mode authentication 有权
    混合模式认证

    公开(公告)号:US08566915B2

    公开(公告)日:2013-10-22

    申请号:US12910411

    申请日:2010-10-22

    IPC分类号: H04L29/06

    摘要: Techniques for mixed-mode authentication are described. In one or more embodiments, an authentication service may be implemented to selectively configure and issue authentication tokens based upon an optional secure mode that enables enhanced security. Clients may be provided with an option to choose between an insecure mode and a secure mode for authentications. Based on this choice, tokens may be configured to include an indication of whether the secure mode is disabled or enabled. When secure mode is disabled, an insecure token valid for both secure sites and other sites is issued to a client when the client is authenticated. When the optional secure mode is enabled, both secure and insecure tokens are provided to the client. The authentication services and/or other services may be configured to reject an insecure token when secure mode is enabled to prevent unauthorized use of a stolen token to access secure resources.

    摘要翻译: 描述混合模式认证的技术。 在一个或多个实施例中,可以实现认证服务以基于能够增强安全性的可选安全模式来选择性地配置和发布认证令牌。 可以向客户提供在不安全模式和用于认证的安全模式之间进行选择的选项。 基于该选择,令牌可以被配置为包括是否禁用或启用安全模式的指示。 当禁用安全模式时,当客户端进行身份验证时,会向客户端发出对安全站点和其他站点有效的不安全令牌。 当启用可选的安全模式时,将向客户端提供安全和不安全的令牌。 认证服务和/或其他服务可以被配置为当启用安全模式以防止未授权使用被盗令牌来访问安全资源时拒绝不安全令牌。

    Mixed-Mode Authentication
    3.
    发明申请
    Mixed-Mode Authentication 有权
    混合模式认证

    公开(公告)号:US20120102553A1

    公开(公告)日:2012-04-26

    申请号:US12910411

    申请日:2010-10-22

    IPC分类号: H04L9/32 H04L29/06

    摘要: Techniques for mixed-mode authentication are described. In one or more embodiments, an authentication service may be implemented to selectively configure and issue authentication tokens based upon an optional secure mode that enables enhanced security. Clients may be provided with an option to choose between an insecure mode and a secure mode for authentications. Based on this choice, tokens may be configured to include an indication of whether the secure mode is disabled or enabled. When secure mode is disabled, an insecure token valid for both secure sites and other sites is issued to a client when the client is authenticated. When the optional secure mode is enabled, both secure and insecure tokens are provided to the client. The authentication services and/or other services may be configured to reject an insecure token when secure mode is enabled to prevent unauthorized use of a stolen token to access secure resources.

    摘要翻译: 描述混合模式认证的技术。 在一个或多个实施例中,可以实现认证服务以基于能够增强安全性的可选安全模式来选择性地配置和发布认证令牌。 可以向客户提供在不安全模式和用于认证的安全模式之间进行选择的选项。 基于该选择,令牌可以被配置为包括是否禁用或启用安全模式的指示。 当禁用安全模式时,当客户端进行身份验证时,会向客户端发出对安全站点和其他站点有效的不安全令牌。 当启用可选的安全模式时,将向客户端提供安全和不安全的令牌。 认证服务和/或其他服务可以被配置为当启用安全模式以防止未授权使用被盗令牌来访问安全资源时拒绝不安全令牌。

    Using encoding to detect security bugs
    5.
    发明授权
    Using encoding to detect security bugs 有权
    使用编码来检测安全漏洞

    公开(公告)号:US08332821B2

    公开(公告)日:2012-12-11

    申请号:US12410482

    申请日:2009-03-25

    IPC分类号: G06F9/44

    CPC分类号: G06F11/3688

    摘要: A system that facilitates detecting security flaws in a web site that receives and transmits untrusted content is described herein. The system includes a receiver component that receives test content that corresponds to a field on a web page that, when the web site is online, is configured to receive user-generated content, wherein the test content includes non-malicious data. An encoder component encodes each character of the test content regardless of form or content of the test content to generate encoded content. A display component displays encoded content and non-encoded content of the web page to a tester on a computer screen, wherein the display component causes the encoded content to be displayed in a visually distinct manner from the non-encoded content.

    摘要翻译: 本文描述了一种便于检测接收和发送不可信内容的网站中的安全漏洞的系统。 所述系统包括接收器组件,其接收对应于网页上的字段的测试内容,所述测试内容当所述网站在线时被配置为接收用户生成的内容,其中所述测试内容包括非恶意数据。 编码器组件对测试内容的每个字符进行编码,而不管测试内容的形式或内容如何,​​以生成编码的内容。 显示组件将网页的编码内容和非编码内容显示在计算机屏幕上的测试者,其中显示组件使经编码的内容以与视频不同的方式从非编码内容显示。

    USING ENCODING TO DETECT SECURITY BUGS
    7.
    发明申请
    USING ENCODING TO DETECT SECURITY BUGS 有权
    使用编码来检测安全BUGS

    公开(公告)号:US20100251216A1

    公开(公告)日:2010-09-30

    申请号:US12410482

    申请日:2009-03-25

    IPC分类号: G06F9/44

    CPC分类号: G06F11/3688

    摘要: A system that facilitates detecting security flaws in a web site that receives and transmits untrusted content is described herein. The system includes a receiver component that receives test content that corresponds to a field on a web page that, when the web site is online, is configured to receive user-generated content, wherein the test content includes non-malicious data. An encoder component encodes each character of the test content regardless of form or content of the test content to generate encoded content. A display component displays encoded content and non-encoded content of the web page to a tester on a computer screen, wherein the display component causes the encoded content to be displayed in a visually distinct manner from the non-encoded content.

    摘要翻译: 本文描述了一种便于检测接收和发送不可信内容的网站中的安全漏洞的系统。 所述系统包括接收器组件,其接收对应于网页上的字段的测试内容,所述测试内容当所述网站在线时被配置为接收用户生成的内容,其中所述测试内容包括非恶意数据。 编码器组件对测试内容的每个字符进行编码,而不管测试内容的形式或内容如何,​​以生成编码的内容。 显示组件将网页的编码内容和非编码内容显示在计算机屏幕上的测试者,其中显示组件使经编码的内容以与视频不同的方式从非编码内容显示。