The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Oct. 10, 2023

Filed:

Mar. 16, 2021
Applicant:

Cisco Technology, Inc., San Jose, CA (US);

Inventors:

Iain Maclachlan Hamilton, Argyll & Bute, GB;

Kousik Nandy, Karnataka, IN;

Assignee:

Cisco Technology, Inc., San Jose, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 9/40 (2022.01); G06F 9/54 (2006.01); H04L 9/32 (2006.01); H04W 12/06 (2021.01);
U.S. Cl.
CPC ...
H04L 63/0807 (2013.01); G06F 9/547 (2013.01); H04L 9/3213 (2013.01); H04L 63/029 (2013.01); H04L 63/0853 (2013.01); H04W 12/06 (2013.01);
Abstract

Techniques are described for providing an application programming interface (API) architecture that is capable of supporting cross-site request forgery (CSRF) protection with an attribute flag in a cookie, for client devices that utilize a stateless user session to interface with an API gateway. A client device may transmit session requests received by an API gateway. The API gateway may generate a session, and a cookie including session properties associated with the session. The cookie may further include the attribute flag associated with a CSRF token. By transmitting the cookie with the attribute flag to the client device, the client device may receive and insert the cookie into subsequent requests to indicate a requirement that the subsequent requests be accompanied by the CSRF token. In this way, the API gateway may utilize the attribute flag indicating the requirement for the CSRF token to protect the client device from malicious attacks.


Find Patent Forward Citations

Loading…