Invention Grant
- Patent Title: Secure client-side key storage for web applications
- Patent Title (中): 为Web应用程序提供安全的客户端密钥存储
-
Application No.: US13647593Application Date: 2012-10-09
-
Publication No.: US08694784B1Publication Date: 2014-04-08
- Inventor: Sebastian Lekies , Martin Johns
- Applicant: Sebastian Lekies , Martin Johns
- Applicant Address: DE Walldorf
- Assignee: SAP AG
- Current Assignee: SAP AG
- Current Assignee Address: DE Walldorf
- Agency: Fish & Richardson P.C.
- Main IPC: H04L9/32
- IPC: H04L9/32

Abstract:
Implementations of the present disclosure include methods, systems, and computer-readable storage mediums for secure client-side key storage for authentication tracking. Implementations include actions of determining, at a browser executed on a client-side computing device, that an application is authentic, the application being executed on a server-side computing device, in response to determining that the application is authentic, receiving a session signing key (SSK) at a sub-domain of an application domain, the sub-domain including a static script that handles the SSK and that selectively provides request signatures, receiving, at the sub-domain, a message requesting a request signature, determining that the message originated from an authentic origin, and in response to determining that the message originated from an authentic origin, providing a request signature to a source of the message, the request signature being based on the SSK.
Public/Granted literature
- US20140101446A1 SECURE CLIENT-SIDE KEY STORAGE FOR WEB APPLICATIONS Public/Granted day:2014-04-10
Information query