发明名称 Adaptive timeouts for security credentials
摘要 Session-specific information stored to a cookie or other secure token can be selected and/or caused to vary over time, such that older copies will become less useful over time. Such an approach reduces the ability of entities obtaining a copy of the cookie from performing unauthorized tasks on a session. A cookie received with a request can contain a timestamp and an operation count for a session that may need to fall within an acceptable range of the current values in order for the request to be processed. A cookie returned with a response can be set to the correct value or incremented from the previous value based on various factors. The allowable bands can decrease with age of the session, and various parameter values such as a badness factor for a session can be updated continually based on the events for the session.
申请公布号 US9571488(B2) 申请公布日期 2017.02.14
申请号 US201514954744 申请日期 2015.11.30
申请人 Amazon Technologies, Inc. 发明人 Roth Gregory B.;Allen Nicholas Alexander;Ilac Cristian M.
分类号 G06F7/04;H04L29/06;H04L12/26;H04L29/08 主分类号 G06F7/04
代理机构 Hogan Lovells US LLP 代理人 Hogan Lovells US LLP
主权项 1. A system for managing session information, comprising: at least one processor; and memory storing instructions that, when executed by the at least one processor, cause the system to: receive a request from a client, the request seeking access to at least one resource, the request including at least one security credential; authenticate a source of the request based at least in part on the at least one security credential; initiate a session and send the client a session token for the session, the session token including a timestamp indicating a time at which the session was initiated; receive a second request from the client, the second request including the session token; determine a confidence value, the confidence value being based at least in part on a comparison between a time indicated by the timestamp in the session token and a current time; process the second request upon a determination that the confidence value meets a threshold value; and send a response to the client, the response including an updated session token including an updated timestamp, the updated timestamp differing from the current time by an amount based at least in part on the confidence value.
地址 Reno NV US