Cross site request forgery mitigation in multi-domain integrations
    1.
    发明授权
    Cross site request forgery mitigation in multi-domain integrations 有权
    多域集成中的跨站点请求伪造缓解

    公开(公告)号:US09015820B1

    公开(公告)日:2015-04-21

    申请号:US13931613

    申请日:2013-06-28

    CPC classification number: H04L63/08 H04L9/3213 H04L63/0807 H04L63/1441

    Abstract: Systems and methods for authenticating a request submitted from a client device through a third party content provider to an electronic entity are described. In one embodiment, a method includes providing a trusted script to the third party content provider, passing a trust token to the third party content provider and to the client device, and, in response to a request submitted from the client device through the third party content provider, validating the trust token associated with the request with the token passed to the client device, and processing the request. The trusted script is configured to create a trusted window on the third party Web page displayed on the client computing device, receive a trust token from the electronic entity through the trusted window, and associate the trust token with requests submitted from the client computing device through the third party content provider to the electronic entity.

    Abstract translation: 描述用于认证从客户端设备通过第三方内容提供商提交给电子实体的请求的系统和方法。 在一个实施例中,一种方法包括向第三方内容提供者提供可信脚本,将信任令牌传递到第三方内容提供者和客户端设备,以及响应于通过第三方从客户端设备提交的请求 内容提供商,使用传递给客户端设备的令牌验证与请求相关联的信任令牌,以及处理该请求。 可信脚本被配置为在客户端计算设备上显示的第三方网页上创建可信任窗口,通过可信窗口从电子实体接收信任令牌,并将信任令牌与从客户端计算设备提交的请求相关联,通过 电子实体的第三方内容提供商。

Patent Agency Ranking