IP Library Granted Patent US 12,388,652
Granted Patent B2
US 12,388,652 · App. 17/325,356 · Granted Aug 12, 2025

Header for conveying trustful client address

Inventors: Gang Tang (Nanjing, CN); Liang Rong (Suzhou, CN); Guo Xing He (Suzhou, CN); Ming Shuang Xian (Wuxi, CN)
Assignee: International Business Machines Corporation
H04L9/3247H04L9/3263H04L9/3297H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,388,652
App. No.
17/325,356
Granted
Aug 12, 2025
Kind
B2
Abstract

Described are techniques including a computer-implemented method comprising appending a HyperText Transfer Protocol (HTTP) header to a HTTP request, wherein the HTTP header includes a source Internet Protocol (IP) address of a client generating the HTTP request, a universally unique identifier (UUID) of the HTTP request, a timestamp, a lifetime, a Universal Resource Locator (URL) of the HTTP request, and a signature. The method further comprises transmitting the HTTP request with the HTTP header to a web server.

Claims (42)

1. A method comprising:

receiving, at a web server and from a proxy server, a HyperText Transfer Protocol (HTTP) request including a HTTP header, wherein the HTTP header includes a source Internet Protocol (IP) address of a client generating the HTTP request, a universally unique identifier (UUID) of the HTTP request, a timestamp, a lifetime, a Universal Resource Locator (URL) of the HTTP request, and a hash based on the source IP address, the UUID, the timestamp, the lifetime, and the URL;

validating the UUID in response to determining that there is no UUID in a UUID cache that matches the UUID in the HTTP header;

implementing the HTTP request;

adding the UUID to the UUID cache;

invalidating, after adding the UUID to the UUID cache and before an expiration of the lifetime, a future HTTP request with a future HTTP header containing the UUID based on the UUID being stored in the UUID cache;

purging the UUID from the UUID cache upon the expiration of the lifetime; and

validating, after purging the UUID from the UUID cache after the expiration of the lifetime, a second future HTTP request with a second future HTTP header containing the UUID based on the UUID not being in the UUID cache.

2. The method of claim 1 , wherein validating the HTTP header further comprises:

validating the hash by comparing the hash in the HTTP header to a generated hash, wherein the generated hash is generated by hashing the source IP address, the UUID, the timestamp, the lifetime, and the URL using a hash function that is shared between the web server and the client.

3. The method of claim 1 , wherein validating the HTTP header further comprises:

validating the lifetime by determining whether the expiration of the lifetime is after a current time.

4. The method of claim 1 , wherein the method is performed by one or more computers according to software that is downloaded to the one or more computers from a remote data processing system.

5. The method of claim 4 , wherein the method further comprises:

metering a usage of the software; and

generating an invoice based on metering the usage.

6. A computer program product comprising one or more computer readable storage media, and program instructions collectively stored on the one or more computer readable storage media, the program instructions comprising instructions configured to cause one or more processors to perform a method comprising:

receiving, at a web server and from a proxy server, a HyperText Transfer Protocol (HTTP) request including a HTTP header, wherein the HTTP header includes a source Internet Protocol (IP) address of a client generating the HTTP request, a universally unique identifier (UUID) of the HTTP request, a timestamp, a lifetime, a Universal Resource Locator (URL) of the HTTP request, and a hash based on the source IP address, the UUID, the timestamp, the lifetime, and the URL;

validating the UUID in response to determining that there is no UUID in a UUID cache that matches the UUID in the HTTP header;

implementing the HTTP request;

adding the UUID to the UUID cache;

invalidating, after adding the UUID to the UUID cache and before an expiration of the lifetime, a future HTTP request with a future HTTP header containing the UUID based on the UUID being stored in the UUID cache;

purging the UUID from the UUID cache upon the expiration of the lifetime; and

validating, after purging the UUID from the UUID cache after the expiration of the lifetime, a second future HTTP request with a second future HTTP header containing the UUID based on the UUID not being in the UUID cache.

7. The computer program product of claim 6 , wherein validating the HTTP header further comprises:

validating the hash by comparing the hash in the HTTP header to a generated hash, wherein the generated hash is generated by hashing the source IP address, the UUID, the timestamp, the lifetime, and the URL using a hash function that is shared between the web server and the client.

8. The computer program product of claim 6 , wherein validating the HTTP header further comprises:

validating the lifetime by determining whether the expiration of the lifetime is after a current time.

9. A system comprising:

one or more processors; and

one or more computer readable storage media storing program instructions which, when executed by the one or more processors, are configured to cause the one or more processors to perform a method comprising:

receiving, at a web server and from a proxy server, a HyperText Transfer Protocol (HTTP) request including a HTTP header, wherein the HTTP header includes a source Internet Protocol (IP) address of a client generating the HTTP request, a universally unique identifier (UUID) of the HTTP request, a timestamp, a lifetime, a Universal Resource Locator (URL) of the HTTP request, and a hash based on the source IP address, the UUID, the timestamp, the lifetime, and the URL;

validating the UUID in response to determining that there is no UUID in a UUID cache that matches the UUID in the HTTP header;

implementing the HTTP request;

adding the UUID to the UUID cache;

invalidating, after adding the UUID to the UUID cache and before an expiration of the lifetime, a future HTTP request with a future HTTP header containing the UUID based on the UUID being stored in the UUID cache;

purging the UUID from the UUID cache upon the expiration of the lifetime; and

validating, after purging the UUID from the UUID cache after the expiration of the lifetime, a second future HTTP request with a second future HTTP header containing the UUID based on the UUID not being in the UUID cache.

10. The system of claim 9 , wherein validating the HTTP header further comprises:

validating the hash by comparing the hash in the HTTP header to a generated hash, wherein the generated hash is generated by hashing the source IP address, the UUID, the timestamp, the lifetime, and the URL using a hash function that is shared between the web server and the client.

11. The system of claim 9 , wherein validating the HTTP header further comprises:

validating the lifetime by determining whether the expiration of the lifetime is after a current time.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 20, 2021
From: TANG, GANG; RONG, LIANG; HE, GUO XING; XIAN, MING SHUANG
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 056298/0378 →
Continuity (1)
Related Publication 20220376924A1 · Nov 24, 2022
References Cited (28)
US 7606915B1 · Calinov · 2009 [cited by examiner]
US 8799641B1 · Seidenberg · 2014 [cited by examiner]
US 8881248B2 · Liu · 2014 [cited by applicant]
US 9088611B2 · Jagadeeswaran et al. · 2015 [cited by applicant]
US 9396330B2 · Muthiah · 2016 [cited by applicant]
US 9589282B2 · Fan · 2017 [cited by examiner]
US 9853875B1 · Oztaskent · 2017 [cited by examiner]
US 10742768B2 · Seo et al. · 2020 [cited by applicant]
US 20100235632A1 · Iyengar et al. · 2010 [cited by applicant]
US 20120124384A1 · Livni · 2012 [cited by examiner]
US 20140258465A1 · Li · 2014 [cited by applicant]
US 20150120914A1 · Wada · 2015 [cited by examiner]
US 20150326398A1 · Modarresi · 2015 [cited by examiner]
US 20160285861A1 · Chester · 2016 [cited by examiner]
US 20160315956A1 · Giladi · 2016 [cited by examiner]
US 20160323409A1 · Kolhi et al. · 2016 [cited by applicant]
US 20180034913A1 · Matthieu · 2018 [cited by examiner]
US 20200084239A1 · Sherif · 2020 [cited by examiner]
US 20200211409A1 · Latorre · 2020 [cited by examiner]
US 20200258118A1 · Kovvali · 2020 [cited by examiner]
US 20200374568A1 · Kalish · 2020 [cited by examiner]
US 20210306369A1 · Pastore · 2021 [cited by examiner]
CN 108400955B · 2020 [cited by applicant]
Menezes et al. Handbook of Applied Cryptography CRC Press 1997 (Year: 1997). [cited by examiner]
Petersson et al., “Forwarded HTTP Extension”, Internet Engineering Task Force (IETF), Request for Comments: 7239, ISSN: 2070-1721, Jun. 2014, 16 pages, <https://tools.ietf.org/html/rfc7239>. [cited by applicant]
Leach et al., “A Universally Unique IDentifier (UUID) URN Namespace”, Network Working Group, Request for Comments: 4122, Jul. 2005, 32 pages, <https://tools.ietf.org/html/rfc4122>. [cited by applicant]
Klyne et al., “Date and Time on the Internet: Timestamps”, Network Working Group, Request for Comments: 3339, Jul. 2002, 18 pages, <https://tools.ietf.org/html/rfc3339>. [cited by applicant]
Mell et al., “The NIST Definition of Cloud Computing”, Recommendations of the National Institute of Standards and Technology, Sep. 2011, 7 pages. [cited by applicant]