发明名称 MULTIFACTOR VALIDATION OF REQUESTS TO THW ART DYNAMIC CROSS-SITE ATTACKS
摘要 An apparatus and a method for validating requests to thwart cross-site attacks is described. A user identifier token, a request identifier token, and a timestamp, are generated at a web application of a server. A Message Authentication Code (MAC) value is formed based on the user identifier token, the request identifier token, and the timestamp using a secret key of the web application. Names of the form elements are enciphered. Fake form elements can also be added to the dynamic form. The entire page also can be enciphered. The dynamic form is sent with the MAC value and the time stamp to a client. A completed form comprising a returned MAC value and a returned timestamp is received from the client. The completed form is validated at the server based on the returned MAC value and the returned timestamp.
申请公布号 US2011131416(A1) 申请公布日期 2011.06.02
申请号 US20090628121 申请日期 2009.11.30
申请人 发明人 SCHNEIDER JAMES PAUL
分类号 H04L9/32 主分类号 H04L9/32
代理机构 代理人
主权项
地址