Invention Grant
- Patent Title: Mitigating forgery for active content
- Patent Title (中): 减轻活动内容的伪造
-
Application No.: US12575393Application Date: 2009-10-07
-
Publication No.: US09003540B1Publication Date: 2015-04-07
- Inventor: Jesper M. Johansson , Eric J. Martin , Brandon M. Knight
- Applicant: Jesper M. Johansson , Eric J. Martin , Brandon M. Knight
- Applicant Address: US NV Reno
- Assignee: Amazon Technologies, Inc.
- Current Assignee: Amazon Technologies, Inc.
- Current Assignee Address: US NV Reno
- Agency: Kilpatrick Townsend & Stockton
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L9/32

Abstract:
Cross Site Request Forgery (CSRF) and other types of fraudulent submission can be mitigated using state information that typically is already maintained for various users. Each submission requiring authentication can include a state identifier (ID). The state ID can be compared to a corresponding secure state ID stored in a secure location, such as in a secure token or cookie or in a variable on a page that can only be accessed by code executing in the same security context as the site to which the request is made. If the received state ID is valid and matches the secure state ID, the submission is processed. Otherwise, an interstitial element is generated to prompt the user to confirm the prior submission. A subsequent confirmation submission confirming the prior submission and containing the proper state ID can be processed. If no such confirmation is received, the submission is not processed.
Information query