US2004243852A1PendingUtilityA1
Method, system and software for state signing of internet resources
Priority: May 28, 2003Filed: May 28, 2004Published: Dec 2, 2004
Est. expiryMay 28, 2023(expired)· nominal 20-yr term from priority
Inventors:Adam Rosenstein
G06F 21/606G06F 21/645H04L 63/123
26
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A method, system, and software for state signing of Internet resources is presented in which web pages and other Internet resources are signed after the insertion of metadata indicating intended and authorized uses. In one embodiment, the signing is accomplished through use of a cryptographic signature added to any data item passed to a client that is likely to be passed back to the server later, such as a cookie, URL, or data integrity item. Enabling/disabling of state signing for various data items can be controlled through policies tied to URL prefixes.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for monitoring transmissions between a network application server and a client, the method comprising:
incorporating security metadata in a server transmission from a network application server to a client, wherein the security metadata includes a description of the intended network application semantics; receiving a client transmission from the client, wherein the client transmission includes returned metadata; and determining, using the returned metadata, whether the client transmission conforms to the intended network application semantics.
2 . The method of claim 1 , wherein the security metadata is transmitted with application data.
3 . The method of claim 1 , wherein the security metadata is transmitted separate from application data.
4 . The method of claim 1 , wherein the security metadata further comprises authorization information for client transmissions, wherein the authorization information indicates which client transmissions are authorized.
5 . A method applied between a network application server and a client to ensure data security:
intercepting a transmission of application data from a network application server to a client; identifying one or more Uniform Resource Locators (URLs) embedded in the transmission; generating security metadata containing constraints on the manner in which the client requests the one or more URLs; and transmitting the transmission of application data and the security metadata to the client.
6 . The method of claim 5 , further comprising:
receiving a client transmission from the client, wherein the client transmission includes a URL request and the security metadata; and validating the URL request against the security metadata to ensure that the URL request fits within the constraints on the manner in which the client requests the one or more URLs.
7 . The method of claim 5 , further comprising generating a cryptographic signature over the predicted form of the client request containing the one or more URLs previously transmitted by the application server, and wherein transmitting further comprises transmitting the cryptographic signature to the client.
8 . The method of claim 7 , further comprising:
receiving a transmission from the client, wherein the transmission from the client includes a URL request and the security metadata; validating the URL request against the security metadata to ensure that the URL request fits within the constraints on the manner in which the client requests the one or more URLs; and verifying the cryptographic signature.
9 . An apparatus for monitoring transmissions between a network application server and a client, the apparatus comprising:
a transmitter for incorporating security metadata in one or more server transmissions from a network application server to a client, wherein the security metadata includes a description of the intended network application semantics; a receiver for receiving one or more client transmissions from the client, wherein the one or more client transmissions include returned metadata; and an analyzer for determining, using the returned metadata, whether the one or more client transmissions conform to the intended network application semantics.
10 . The apparatus of claim 9 , wherein the security metadata is transmitted with the application data.
11 . The apparatus of claim 9 , wherein the security metadata is transmitted separate from the application data.
12 . The apparatus of claim 9 , wherein the security metadata further comprises authorization information for client transmissions, wherein the authorization information indicates which client transmissions are authorized.
13 . An apparatus for insuring data security, comprising:
a receiver for intercepting a transmission of application data from a network application server to a client; a parser for identifying one or more URLs embedded in the transmission; a metadata generator for generating security metadata containing constraints on the manner in which the client requests the one or more URLs; and a transmitter for transmitting the transmission of application data and the security metadata to the client.
14 . The apparatus of claim 13 , further comprising:
a second receiver for receiving a client transmission from the client, wherein the client transmission includes a URL request and the security metadata; and a validator for validating the URL request against the security metadata to ensure that the URL request fits within the constraints on the manner in which the client requests the one or more URLs.
15 . The apparatus of claim 13 , further comprising a generator for generating a cryptographic signature over the predicted form of the client request containing the one or more URLs previously transmitted by the application server, and wherein the transmitter further transmits the cryptographic signature to the client.
16 . The method of claim 15 , further comprising:
a second receiver for receiving a transmission from the client, wherein the transmission from the client includes a URL request and the security metadata; a validator for validating the URL request against the security metadata to ensure that the URL request fits within the constraints on the manner in which the client requests the one or more URLs; and a verifier for verifying the cryptographic signature.
17 . A system for performing state signing of network resources, comprising:
a first subsystem for receiving one or more resource requests from a client to an application server; and a state signing subsystem for signing responses to resource requests delivered to a client from the application server, wherein the resource requests are signed to indicate authenticity.
18 . The system of claim 17 , wherein the state signing subsystem includes a cryptographic signature for the generation of a cryptographic signature over at least a portion of the response to the resource request.
19 . The system of claim 18 , wherein the state signing subsystem further includes a verification subsystem for the determination as to whether a resource request has been altered.
20 . A computer program embodied on a computer-readable medium for signing the state of application data transmitted over a network, the computer program comprising:
a source code segment for intercepting a transmission of application data from an application server to a client; a source code segment for identifying one or more URLs embedded in the transmission; a source code segment for generating security metadata containing constraints on the manner in which the client requests the one or more URLs; a source code segment for transmitting the transmission of application data and the security metadata to the client.
21 . The computer program of claim 20 , further comprising:
a source code segment for receiving a client transmission from the client, wherein the client transmission includes a URL request and the security metadata; and a source code segment for validating the URL request against the security metadata to ensure that the URL request fits within the constraints on the manner in which the client requests the one or more URLs.
22 . The computer program of claim 20 , further comprising a source code segment for generating a cryptographic signature over the predicted form of the client request containing the one or more URLs previously transmitted by the application server, and wherein the source code segment for transmitting further transmits the cryptographic signature to the client.
23 . The computer program of claim 22 , further comprising:
a source code segment for receiving a client transmission from the client, wherein the client transmission includes a URL request and the security metadata; a source code segment for validating the URL request against the security metadata to ensure that the URL request fits within the constraints on the manner in which the client requests the one or more URLs; and a source code segment for verifying the cryptographic signature.Join the waitlist — get patent alerts
Track US2004243852A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.