IP Library Granted Patent US 10,050,792
Granted Patent B1
US 10,050,792 · App. 15/696,151 · Granted Aug 14, 2018

Providing cross site request forgery protection at an edge server

Inventor: Evan Johnson (San Francisco, CA)
Assignee: CLOUDFLARE, INC.
H04L9/3236H04L9/0643H04L9/0872H04L61/2007H04L63/08H04L63/108H04L63/1466H04L67/02H04L67/18
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,050,792
App. No.
15/696,151
Granted
Aug 14, 2018
Kind
B1
Abstract

A request from a computing device for accessing a resource is received by an edge server, where the request includes a cookie containing a first token value and a second token value. The edge server validates the first token value and a second token value using a third token value generated using hashing algorithm with a secret key and one or more other values. The edge server then compares the received token values with the third token value. When the request is validated, the edge server retrieves the request resource.

Claims (50)

1. A method, comprising:

generating, by an edge server, a first token value that includes a hash value generated by hashing a secret key and one or more other values using a hash algorithm;

including the first token value in a first cookie;

sending the first cookie to a client device, wherein the first cookie does not include the secret key;

receiving, from the client device, a request for an action to be performed on a resource that is hosted at an origin server, the request including a second cookie and a second token value;

extracting, from the second cookie, the one or more other values, wherein the one or more other values include an expiration time and one or more metadata, and wherein the one or more metadata includes one or more of an IP address, a browser identifier, a host origin name, geo-location data, a device identifier, a user agent string, and other authentication data;

generating a third token value by hashing the secret key and the extracted one or more other values using the hash algorithm;

comparing the first token value and the third token value to determine whether the first token value matches the third token value;

comparing the second token value and the third token value to determine whether the second token value matches the third token value; and

sending the request to the origin server in response to determining that the first token value and the second token value match the third token value.

2. The method of claim 1 , further comprising:

modifying code of the resource to include a client-side script that, when executed by the client device, causes the client device to transmit the second token value as part of the request.

3. The method of claim 1 , wherein extracting the one or more other values from the second cookie further comprises:

verifying a format of the second cookie matches an expected format.

4. The method of claim 1 , wherein the second token value is included in one of a body of the request and an HTTP request header of the request.

5. The method of claim 1 , wherein the request for the action to be performed is a state-changing request for the resource.

6. A non-transitory machine-readable storage medium that provides instructions that, when executed by a processor, cause said processor to perform operations comprising:

generating, by an edge server, a first token value that includes a hash value generated by hashing a secret key and one or more other values using a hash algorithm;

including the first token value in a first cookie;

sending the first cookie to a client device, wherein the first cookie does not include the secret key;

receiving, from the client device, a request for an action to be performed on a resource that is hosted at an origin server, the request including a second cookie and a second token value;

extracting, from the second cookie, the one or more other values, wherein the one or more other values include an expiration time and one or more metadata, and wherein the one or more metadata includes one or more of an IP address, a browser identifier, a host origin name, geo-location data, a device identifier, a user agent string, and other authentication data;

generating a third token value by hashing the secret key and the extracted one or more other values using the hash algorithm;

comparing the first token value and the third token value to determine whether the first token value matches the third token value;

comparing the second token value and the third token value to determine whether the second token value matches the third token value; and

sending the request to the origin server in response to determining that the first token value and the second token value match the third token value.

7. The non-transitory machine-readable storage medium of claim 6 that provides instructions that, when executed by the processor, cause the processor to further perform operations comprising:

modifying code of the resource to include a client-side script that, when executed by the client device, causes the client device to transmit the second token value as part of the request.

8. The non-transitory machine-readable storage medium of claim 6 , wherein extracting the one or more other values from the second cookie further comprises:

verifying a format of the second cookie matches an expected format.

9. The non-transitory machine-readable storage medium of claim 6 , wherein the second token value is included in one of a body of the request and an HTTP request header of the request.

10. The non-transitory machine-readable storage medium of claim 6 , wherein the request for the action to be performed is a state-changing request for the resource.

11. An apparatus, comprising:

a processor;

a non-transitory machine-readable storage medium coupled with the processor that stores instructions that, when executed by the processor, cause said processor to perform the following:

generate, by an edge server, a first token value that includes a hash value generated by hashing a secret key and one or more other values using a hash algorithm;

include the first token value in a first cookie;

send the first cookie to a client device, wherein the first cookie does not include the secret key;

receive, from the client device, a request for an action to be performed on a resource that is hosted at an origin server, the request including a second cookie and a second token value;

extract, from the second cookie, the one or more other values, wherein the one or more other values is to include an expiration time and one or more metadata, and wherein the one or more metadata is to include one or more of an IP address, a browser identifier, a host origin name, geo-location data, a device identifier, a user agent string, and other authentication data;

generate a third token value by hashing the secret key and the extracted one or more other values using the hash algorithm;

compare the first token value and the third token value to determine whether the first token value matches the third token value;

compare the second token value and the third token value to determine whether the second token value matches the third token value; and

send the request to the origin server in response to determining that the first token value and the second token value match the third token value.

12. The apparatus of claim 11 , wherein the instructions further cause said processor to perform the following:

modify code of the resource to include a client-side script that, when executed by the client device, causes the client device to transmit the second token value as part of the request.

13. The apparatus of claim 11 , wherein extracting the one or more other values from the second cookie further comprises:

verifying a format of the second cookie matches an expected format.

14. The apparatus of claim 11 , wherein the second token value is included in one of a body of the request and an HTTP request header of the request.

15. The apparatus of claim 11 , wherein the request for the action to be performed is a state-changing request for the resource.

Assignments (2)
SECURITY INTEREST Recorded May 20, 2024
From: CLOUDFLARE, INC.
To: CITIBANK, N.A.
Reel/Frame 067472/0246 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 5, 2017
From: JOHNSON, EVAN
To: CLOUDFLARE, INC.
Reel/Frame 043492/0670 →
Continuity (1)
Continuation 15432891 · Feb 14, 2017
Cited By (5)
US 12,401,685 US 12,407,720 US 12,519,827 US 12,627,706 US 12,672,021