The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jan. 27, 2015

Filed:

Oct. 04, 2011
Applicants:

Michael W. Paddon, Tokyo, JP;

Jessica M. Flanagan, Ashfield, AU;

Craig M. Brown, Harbord, AU;

Inventors:

Michael W. Paddon, Tokyo, JP;

Jessica M. Flanagan, Ashfield, AU;

Craig M. Brown, Harbord, AU;

Assignee:

QUALCOMM Incorporated, San Diego, CA (US);

Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); G01S 19/32 (2010.01); G01S 19/24 (2010.01); G01S 19/42 (2010.01); G01S 19/48 (2010.01); H04W 4/02 (2009.01);
U.S. Cl.
CPC ...
G01S 19/32 (2013.01); G01S 19/246 (2013.01); G01S 19/421 (2013.01); G01S 19/48 (2013.01); H04L 63/0815 (2013.01); H04W 4/02 (2013.01);
Abstract

Disclosed is a method for protecting a single sign-on domain from credential leakage. In the method, an authentication server provides an authentication cookie to a browser client. The cookie has at least one user authentication credential for the domain, and is associated with an authentication subdomain of the domain. The server receives the cookie from the browser client. Upon authentication of the user authentication credential in the received cookie, the server responds to the access request by forwarding, to the browser client, a limited-use cookie for the domain. The server receives a request from the content server to validate a session identifier of the limited-use cookie received from the browser client. Upon validation of the session identifier of the limited-use cookie, the server provides a valid session message to the content server for enabling the content server to forward requested content to the browser client.


Find Patent Forward Citations

Loading…