Invention Grant
- Patent Title: Method for session security
- Patent Title (中): 会话安全的方法
-
Application No.: US11765360Application Date: 2007-06-19
-
Publication No.: US07849318B2Publication Date: 2010-12-07
- Inventor: Kai Zhang , Linlong Jiang
- Applicant: Kai Zhang , Linlong Jiang
- Applicant Address: US CA Sunnyvale
- Assignee: Yahoo! Inc.
- Current Assignee: Yahoo! Inc.
- Current Assignee Address: US CA Sunnyvale
- Agency: Martine Penilla & Gencarella, LLP
- Main IPC: H04L9/32
- IPC: H04L9/32 ; H04L29/06 ; H04K1/00 ; H04L9/00 ; H04L9/28

Abstract:
A secret string is established so as to be known only to a client computing system and a server computing system. A non-encrypted version of a message, a message counter value, and first hash value are received by the server computing system from the client computing system. The first hash value, based on a content of the message, the message counter value, and the secret string, is generated at the client computing system using a first hash algorithm. Using the first hash algorithm, the server generates second hash value based on the content of the received message, the received message counter value, and the secret string. The server computing system accepts the received non-encrypted version of the message as authentic upon determining that the received message counter value is greater than a previously received message counter value and that the second hash value matches the first hash value.
Public/Granted literature
- US20080320307A1 Method for Session Security Public/Granted day:2008-12-25
Information query