发明名称 METHOD AND APPARATUS FOR SECURELY INVOKING A REST API
摘要 An embodiment of the present invention provides a system that enables a user to securely invoke a REST (Representational State Transfer) API (Application Programming Interface) at an application server. A client can establish a secure communication channel with an application server, and can send a request to the application server to invoke the REST API. The client can then receive a security token from an authentication system in response to authenticating the user with the authentication system. Next, the client can receive a nonce and a timestamp from the application server. The client can then determine a security token digest using the security token, the nonce, and the timestamp. Next, the client can resend the request to the application server to invoke the REST API with the security token digest. The application server can invoke the REST API if the security token digest is valid.
申请公布号 US2009235349(A1) 申请公布日期 2009.09.17
申请号 US20080046579 申请日期 2008.03.12
申请人 INTUIT INC. 发明人 LAI RAY Y.;CHAN KA FU
分类号 G06F21/00;H04L9/32 主分类号 G06F21/00
代理机构 代理人
主权项
地址