Invention Grant
- Patent Title: Adaptive timeouts for security credentials
- Patent Title (中): 自适应超时安全凭证
-
Application No.: US14954744Application Date: 2015-11-30
-
Publication No.: US09571488B2Publication Date: 2017-02-14
- Inventor: Gregory B. Roth , Nicholas Alexander Allen , Cristian M. Ilac
- Applicant: Amazon Technologies, Inc.
- Applicant Address: US NV Reno
- Assignee: Amazon Technologies, Inc.
- Current Assignee: Amazon Technologies, Inc.
- Current Assignee Address: US NV Reno
- Agency: Hogan Lovells US LLP
- Main IPC: G06F7/04
- IPC: G06F7/04 ; H04L29/06 ; H04L12/26 ; H04L29/08

Abstract:
Session-specific information stored to a cookie or other secure token can be selected and/or caused to vary over time, such that older copies will become less useful over time. Such an approach reduces the ability of entities obtaining a copy of the cookie from performing unauthorized tasks on a session. A cookie received with a request can contain a timestamp and an operation count for a session that may need to fall within an acceptable range of the current values in order for the request to be processed. A cookie returned with a response can be set to the correct value or incremented from the previous value based on various factors. The allowable bands can decrease with age of the session, and various parameter values such as a badness factor for a session can be updated continually based on the events for the session.
Public/Granted literature
- US20160080367A1 ADAPTIVE TIMEOUTS FOR SECURITY CREDENTIALS Public/Granted day:2016-03-17
Information query