首页> 外国专利> Clickjacking prevention

Clickjacking prevention

机译:防止点击劫持

摘要

Systems and methods provide for clickjacking prevention code provided in an embedded webpage to prevent clickjacking when the embedded webpage is called by an embedding webpage determined to be illegitimate. When the embedded webpage is loaded on a user device, the clickjacking prevention code is executed and initially prevents content of the embedded webpage from being rendered. Additionally, the clickjacking prevention code sends a message containing a secret to a known domain that provides legitimate embedding webpages. When the embedding webpage sends a message to the embedded webpage, the message is checked to see if it contains the secret. If the message contains the secret, the embedding webpage is legitimate since it originated from the known domain, and the content of the embedded webpage is rendered. Alternatively, if the message does not contain the secret, the content of the webpage is not rendered.
机译:系统和方法提供了在嵌入式网页中提供的防止点击劫持代码,以防止在嵌入式网页被确定为非法的嵌入网页调用时进行点击劫持。当将嵌入式网页加载到用户设备上时,将执行防点击劫持代码,并且该代码最初会阻止呈现嵌入式网页的内容。此外,防止点击劫持代码将包含机密的消息发送到提供合法嵌入网页的已知域。当嵌入网页将消息发送到嵌入式网页时,将检查该消息以查看其是否包含秘密。如果消息包含秘密,则嵌入网页是合法的,因为它源自已知域,并且呈现了嵌入网页的内容。可替代地,如果消息不包含秘密,则不呈现网页的内容。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号