发明名称 Method and system for secure server-based session management using single-use HTTP cookies
摘要 A methodology for providing secure session management is presented. After a single-use token has been issued to a client, it presents the token, and the server may identify the client based upon the presented token. However, the token may be used only once without being refreshed prior to re-use, thereby causing the token to be essentially reissued upon each use. The token comprises a session identifier that allows the issuer of the token to perform session management with respect to the receiving entity. Tokens can be classified into two types: domain tokens and service tokens. Domain tokens represent a client identity to a secure domain, and service tokens represent a client identity to a specific service. A domain token may be used with any service within a domain that recognizes the domain token, but a service token is specific to the service from which it was obtained.
申请公布号 US8005965(B2) 申请公布日期 2011.08.23
申请号 US20010896195 申请日期 2001.06.30
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 WILLIAMS RONALD B.
分类号 G06F15/16;H04L29/06 主分类号 G06F15/16
代理机构 代理人
主权项
地址