IP Library Granted Patent US 9,313,024
Granted Patent B1
US 9,313,024 · App. 13/917,049 · Granted Apr 12, 2016

Keyed communication token

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,313,024
App. No.
13/917,049
Granted
Apr 12, 2016
Kind
B1
Abstract

Systems and methods for keyed communication tokens. A method may include receiving a key and a seed at a computing device, calculating a pseudo-random value based, at least in part, upon the seed, creating a concatenated string using the key and the pseudo-random value, hashing the concatenated string into a token, and adding the token to a user agent issued by a web browser as part of a command transmitted by the computing device. A computer system may be configured to identify a key and a seed, generate a pseudo-random value using the seed, create a concatenated string using the key and the pseudo-random value, hash the concatenated string into a token, and allow a web command in response to the web command including a user agent having the token or block the web command in response to the web command not including a user agent having the token.

Claims (59)

1. A method, comprising:

receiving a key and a seed at a computing device;

calculating a pseudo-random value based, at least in part, upon the seed;

creating a concatenated string using the key and the pseudo-random value;

hashing the concatenated string into a token;

adding the token to a user agent issued by a web browser as part of a command transmitted by the computing device;

advancing the seed to a subsequent seed at the expiration of a time period;

calculating a subsequent pseudo-random value based upon the subsequent seed;

creating a subsequent concatenated string using the key and the subsequent pseudo-random value;

hashing the subsequent concatenated string into a subsequent token;

adding the subsequent token to a user agent issued by the web browser as part of a subsequent command transmitted by the computing device; and

receiving, at the computing device, initial time information and time interval information, wherein the initial time information represents a time at which a firewall begins allowing commands having user agents that include the token, and wherein the time interval information represents the time period after which the firewall stops allowing commands having user agents that include the token and begins allowing commands having user agents that include the subsequent token.

2. The method of claim 1 , wherein the key, the seed, the pseudo-random value, and the token are alphanumeric strings different from one another.

3. The method of claim 1 , wherein the command is a Hypertext Transfer Protocol (HTTP) command selected from the group consisting of: GET, HEAD, PUT, POST, DELETE, LINK, and UNLINK.

4. The method of claim 1 , wherein the user agent is configured to identify the web browser originating the command and includes at least one piece of information selected from the group consisting of: a browser's name, a browser's version, computing device identification, operating system information, and identification of the computing device's processor.

5. The method of claim 1 , further comprising receiving, at the computing device, an indication of a predetermined number of commands, wherein the indication represents a number of commands for which a firewall accepts user agents that include the token, wherein the firewall is configured to block commands having user agents that include the token after having received the predetermined number of commands, and wherein the firewall is configured to begin allowing commands having user agents that include a subsequent token after having received the predetermined number of commands.

6. The method of claim 5 , wherein the predetermined number of commands is one.

7. The method of claim 5 , wherein the predetermined number of commands is two or more.

8. The method of claim 5 , further comprising:

advancing the present seed to a subsequent seed after the predetermined number of commands is issued by the computing device;

calculating a subsequent pseudo-random value based upon the subsequent seed;

creating a subsequent concatenated string using the key and the subsequent pseudo-random value;

hashing the subsequent concatenated string into the subsequent token; and

adding the subsequent token to a user agent issued by the web browser as part of a subsequent command transmitted by the computing device.

9. A computing system, comprising:

a memory configured to store program instructions; and

processing circuitry operably coupled to the memory, the processing circuitry configured to execute the program instructions to cause the computing system to:

identify a key and a seed;

generate a pseudo-random value using the seed;

create a concatenated string using the key and the pseudo-random value;

hash the concatenated string into a token;

at least one of:

allow a web command in response to the web command including a user agent having the token; or

block the web command in response to the web command not including a user agent having the token;

identifying initial time information and time interval information, wherein the initial time information represents a time at which the computing system begins allowing web commands having user agents that include the token, and wherein the time interval information represents the time period after which the computing systems stops allowing web commands having user agents that include the token and begins allowing web commands having user agents that include the subsequent token;

advance the seed to a subsequent seed value at the expiration of a time period;

generate a subsequent pseudo-random value using the subsequent seed;

create a subsequent concatenated string using the key and the subsequent pseudo-random value;

hash the subsequent concatenated string into a subsequent token; and at least one of:

allow another web command in response to the other web command including a user agent having the subsequent token; or

block the other web command in response to the other web command not including a user agent having the subsequent token.

10. The computing system of claim 9 , wherein the computing system includes a firewall, wherein the web command is issued by one or more web browsers executed by one or more client devices, and wherein allowing the web command includes removing the token from the web command prior to forwarding the web command to a specified destination.

11. The computing system of claim 9 , the processing circuitry further configured to execute the program instructions to cause the computing system to:

identify a predetermined number of web commands from a given client device for which the computing system accepts user agents that include the token;

block web commands from the given client device having user agents that include the token after having received the predetermined number of web commands from the given client device; and

allow web commands from the given client device having user agents that include a subsequent token after having received the predetermined number of web commands from the given client device.

12. The computing system of claim 11 , the processing circuitry further configured to execute the program instructions to cause the computing system to:

advance the seed to a subsequent seed value after the predetermined number of web commands is received from the given client device;

generate a subsequent pseudo-random value using the subsequent seed;

create a subsequent concatenated string using the key and the subsequent pseudo-random value; and

hash the subsequent concatenated string into the subsequent token.

13. A non-transitory computer-readable storage medium having program instructions stored thereon that, upon execution by a processor within a computing system, cause the computing system to:

identify a key and a seed;

generate a pseudo-random value using the seed;

create a concatenated string using the key and the pseudo-random value; hash the concatenated string into a token;

add the token to a string transmitted as part of a request issued by the computing system;

update the seed, generate an updated pseudo-random value, create an updated concatenated string using the key and the updated pseudo-random value, and hash the updated concatenated string to create an updated token in response to at least one of: an expiration of a time period, or a number of requests having been issued by the computing system; and

identify initial time information and time interval information, wherein the initial time information represents a time at which the computing system begins allowing web commands having user agents that include the token, and wherein the time interval information represents the time period after which the computing systems stops allowing web commands having user agents that include the token and begins allowing web commands having user agents that include the subsequent token.

14. The non-transitory computer-readable storage medium of claim 13 , wherein the request is a web command, and wherein the string is transmitted as part of a web browser's user agent.

Assignments (13)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT REEL 040996, FRAME 0851 Recorded Oct 7, 2021
From: ANTARES CAPITAL LP
To: MASERGY COMMUNICATIONS, INC.
Reel/Frame 057750/0201 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT REEL 040996, FRAME 0851 Recorded Oct 7, 2021
From: JEFFERIES FINANCE LLC
To: MASERGY COMMUNICATIONS, INC.
Reel/Frame 057886/0687 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Dec 16, 2016
From: MASERGY COMMUNICATIONS, INC.
To: JEFFERIES FINANCE LLC, AS ADMINISTRATIVE AGENT
Reel/Frame 040996/0851 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Dec 16, 2016
From: MASERGY COMMUNICATIONS, INC.
To: ANTARES CAPITAL LP, AS ADMINISTRATIVE AGENT
Reel/Frame 040996/0869 →
RELEASE OF SECURITY INTEREST Recorded Dec 15, 2016
From: ANTARES CAPITAL LP, AS SUCCESSOR AGENT
To: MASERGY COMMUNICATIONS, INC.
Reel/Frame 040986/0376 →
CORRECTIVE ASSIGNMENT TO CORRECT THE NATURE OF CONVEYANCE TO ASSIGNMENT OF PATENT SECURITY AGREEMENT. PREVIOUSLY RECORDED AT REEL: 03641 FRAME: 0790. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Oct 14, 2015
From: GENERAL ELECTRIC CAPITAL CORPORATION, AS RETIRING AGENT
To: ANTARES CAPITAL LP, AS SUCCESSOR AGENT
Reel/Frame 036855/0197 →
SECURITY INTEREST Recorded Aug 25, 2015
From: GENERAL ELECTRIC CAPITAL CORPORATION, AS RETIRING AGENT
To: ANTARES CAPITAL LP, AS SUCCESSOR AGENT
Reel/Frame 036417/0790 →
SECURITY INTEREST Recorded Sep 19, 2014
From: MASERGY COMMUNICATIONS, INC.
To: GENERAL ELECTRIC CAPITAL CORPORATION, AS AGENT
Reel/Frame 033781/0827 →
RELEASE OF SECURITY INTEREST Recorded Sep 19, 2014
From: GENERAL ELECTRIC CAPITAL CORPORATION, AS GRANTEE
To: MASERGY COMMUNICATIONS, INC.
Reel/Frame 033781/0601 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 28, 2014
From: GLOBAL DATAGUARD, INC.
To: MASERGY COMMUNICATIONS, INC.
Reel/Frame 032769/0948 →
SECURITY INTEREST Recorded Apr 2, 2014
From: MASERGY COMMUNICATIONS, INC.
To: GENERAL ELECTRIC CAPITAL CORPORATION, AS AGENT
Reel/Frame 032589/0865 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 2, 2014
From: GLOBAL DATAGUARD, INC., A TEXAS CORPORATION
To: MASERGY COMMUNICATIONS, INC., A DELAWARE CORPORATION
Reel/Frame 032582/0393 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 13, 2013
From: STUTE, MICHAEL ROY
To: GLOBAL DATAGUARD, INC.
Reel/Frame 030607/0307 →