IP Library Granted Patent US 12,113,803
Granted Patent B2
US 12,113,803 · App. 17/167,912 · Granted Oct 8, 2024

Securing ordered resource access

Inventors: Barak Mordechai Amar (Ramat Gan, IL); Ben Diamant (Tel Aviv, IL); Ido Safruti (San Francisco, CA); Pablo Ariel Sirota (Ra'anana, IL)
Assignee: PERIMETERX, INC.
H04L63/108G06F21/00G06F21/335G06F21/6218H04L63/068H04L63/0807H04L63/083H04L63/0876
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,113,803
App. No.
17/167,912
Granted
Oct 8, 2024
Kind
B2
Abstract

Ordered access to resources is controlled by restricting access to additional resources that are accessible when a client device provides an authentication provided when accessing an initial resource. When the client device accesses the initial resources, a set of access parameters are identified describing the request and the client device providing the request, and included with an expiration time in generating a token. The token and expiration date are provided in an authorization for the additional resources. When requesting the additional resources, the authorization is provided and verified by comparing the token in the authorization with a test token generated with reference to access parameters of the request for additional resources. When the tokens match, the additional resource is provided to the client device.

Claims (34)

1. A method for securing ordered resource access of an initial and an additional resource, the method comprising:

receiving, at a service provider over a network, a request for the initial resource from a client device;

identifying access parameters of the request for the initial resource, wherein the access parameters are identifiable for a future request from the client device for the additional resource at a resource provider, wherein the access parameters comprise a hostname designated in the request for the initial resource, a user-agent designated in the request for the initial resource, a network address originating the request for the initial resource, a content identifier specific to a content item or a group of content items of the additional resource, a session identifier that describes a session token or session information for the client device, and a salt for a cryptographic signature, such that at least one parameter of the cryptographic signature is not accessible by the client device;

generating, by the service provider, a token for the request, the token derived by applying the access parameters to a hash function using a secret key, the secret key shared with the resource provider over the network for authorizing requests for the additional resource;

providing the token to the client device for inclusion by the client device in the future request for the additional resource, the future request authorized by the resource provider, using the token, by applying the access parameters in the future request to the hash function using the secret key to confirm whether the initial resource was first provided to the client device by the service provider; and

generating, based on the access parameters and a risk score of the client device, an authorization including an authorization token for access to the additional resource, wherein the authorization token encodes the token and an expiration time,

wherein when the content identifier is used, a different authorization is generated for each additional content item to be accessible by the client device.

2. The method of claim 1 , wherein generating the token further comprises: identifying the expiration time for authorized access by the client device to the additional resource after accessing the initial resource; and applying the hash function to the expiration time to generate the token.

3. The method of claim 2 , wherein the expiration time is set by adding a predefined amount of time to a current time.

4. The method of claim 1 , wherein authorization of the future request by the resource provider comprises: identifying the access parameters in the future request; generating a test token for the second request for the second resource from the access parameters; and comparing the test token to the token.

5. The method of claim 1 , wherein the resource provider is a separate computing system relative to the service provider.

6. The method of claim 1 , wherein the initial resource is a containing page including a reference to the additional resource.

7. The method of claim 1 , wherein the additional resource is embedded in the initial resource.

8. The method of claim 1 , wherein the authorization is a modification of a reference to the additional resource.

9. A non-transitory computer-readable storage medium containing computer program code for:

receiving, at a service provider over a network, a request for the initial resource from a client device;

identifying access parameters of the request for the initial resource, wherein the access parameters are identifiable for a future request from the client device for the additional resource at a resource provider, wherein the access parameters comprise a hostname designated in the request for the initial resource, a user-agent designated in the request for the initial resource, a network address originating the request for the initial resource, a content identifier specific to a content item or a group of content items of the additional resource, a session identifier that describes a session token or session information for the client device, and a salt for a cryptographic signature, such that at least one parameter of the cryptographic signature is not accessible by the client device;

generating, by the service provider, a token for the initial request, the token derived by applying the access parameters to a hash function using a secret key, the secret key shared with the resource provider over the network for authorizing requests for the additional resource;

providing the token to the client device for inclusion by the client device in the future request for the additional resource, the future request authorized by the resource provider, using the token, by applying the access parameters in the future request to the hash function using the secret key to confirm whether the initial resource was first provided to the client device by the service provider; and

generating, based on the access parameters and a risk score of the client device, an authorization including an authorization token for access to the additional resource, wherein the authorization token encodes the token and an expiration time,

wherein when the content identifier is used, a different authorization is generated for each additional content item to be accessible by the client device.

10. The storage medium of claim 9 , wherein generating the token further comprises: identifying the expiration time for authorized access by the client device to the additional resource after accessing the initial resource; and applying the hash function to the expiration time to generate the token.

11. The storage medium of claim 9 , wherein authorization of the future request by the resource provider comprises: identifying the access parameters in the future request; generating a test token for the second request for the second resource from the access parameters; and comparing the test token to the token.

12. The storage medium of claim 9 , wherein the resource provider is a separate computing system relative to the service provider.

13. The storage medium of claim 9 , wherein the initial resource is a containing page including a reference to the additional resource.

14. The storage medium of claim 9 , wherein the additional resource is embedded in the initial resource.

15. A method for verifying access to a resource to be accessed subsequent to an initial resource, comprising:

receiving, by a resource provider, a secret key from a service provider over a network;

receiving, by the resource provider from a client device over the network, a resource access request for a first resource, the resource access request including a token generated by the service provider for the resource access request during a previous request for an initial resource and provided by the service provider to the client device responsive to providing the initial resource to the client device;

identifying one or more access parameters of the resource access request, the access parameters identifiable for the previous request for the initial resource, wherein the access parameters comprise a hostname designated in the previous request for the initial resource, a user-agent designated in the previous request for the initial resource, a network address originating the previous request for the initial resource, a content identifier specific to a content item or a group of content items of an additional resource, a session identifier that describes a session token or session information for the client device, and a salt for a cryptographic signature, such that at least one parameter of the cryptographic signature is not accessible by the client device;

generating, by the resource provider, a test token, the test token derived by applying the access parameters to a hash function using the secret key;

comparing the test token to the token in the resource access request to confirm that the initial resource was first provided to the client device by the service provider, wherein the token in the resource access request comprises a risk score of the client device; and

responsive to the test token matching the token in the access request based on the comparison, transmitting the resource to the client device over the network,

wherein when the content identifier is used, a different authorization is received for each additional content item to be accessible by the client device.

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded Aug 5, 2025
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK & TRUST COMPANY
To: HUMAN SECURITY, INC.; SINGULARITY BUYER LLC; PERIMETERX, INC.
Reel/Frame 071935/0486 →
RELEASE OF SECURITY INTEREST Recorded Aug 5, 2025
From: ALTER DOMUS (US) LLC
To: PERIMETERX, INC.
Reel/Frame 071935/0535 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jul 25, 2025
From: PERIMETERX, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 072253/0245 →
SECURITY INTEREST Recorded Aug 9, 2022
From: PERIMETERX, INC.
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 060761/0797 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jul 29, 2022
From: HUMAN SECURITY, INC.; SINGULARITY BUYER LLC; PERIMETERX, INC.
To: SILICON VALLEY BANK
Reel/Frame 061006/0055 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 8, 2021
From: AMAR, BARAK MORDECHAI; DIAMANT, BEN; SAFRUTI, IDO; SIROTA, PABLO ARIEL
To: PERIMETERX, INC.
Reel/Frame 055181/0606 →
Continuity (3)
Continuation 15784114 · Oct 14, 2017
Provisional Application 62408279 · Oct 14, 2016
Related Publication 20210168155A1 · Jun 3, 2021