首页> 外国专利> PREVENTION OF CROSS SITE REQUEST FORGERY ATTACKS

PREVENTION OF CROSS SITE REQUEST FORGERY ATTACKS

机译:防止跨站点请求伪造攻击

摘要

A method is provided for preventing cross-site request forgery (CSRF) attacks at a server that includes embedding a hidden cryptographic nonce in a response from a server to a client that is authorized to access the server. The response with the hidden cryptographic nonce is sent to the client. A subsequent request is received from the client. The subsequent request is validated or otherwise verified if it includes a hidden cryptographic nonce that matches the hidden cryptographic nonce embedded in the response from the server.
机译:提供了一种用于在服务器处防止跨站点请求伪造(CSRF)攻击的方法,该方法包括在服务器对被授权访问该服务器的客户端的响应中嵌入隐藏的加密随机数。具有隐藏的加密随机数的响应将发送到客户端。从客户端收到后续请求。如果后续请求包括与服务器响应中嵌入的隐藏密码随机数匹配的隐藏密码随机数,则后续请求将被验证或以其他方式验证。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号