IP Library › Granted Patent US 7,974,956
Granted Patent B2
US 7,974,956 · App. 11/491,309 · Granted Jul 5, 2011

Authenticating a site while protecting against security holes by handling common web server configurations

Assignee: Yahoo! Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,974,956
App. No.
11/491,309
Granted
Jul 5, 2011
Kind
B2
Abstract

Techniques are provided through which a user is verified as authorized to modify a website. A web crawler generates a filename and content for the user, who purports to be authorized to modify a particular website. The web crawler sends the filename and content toward the user. The user stores a file with the filename on a server that hosts the website. The user places the content within the file. The web crawler determines whether the file is stored on the server and whether the content is in the file. If so, then the web crawler stores information that indicates that the user is authorized to receive information pertaining to the website, which may be confidential information. If the file is not stored on the server or if the file does not contain the content, then the web crawler does not provide any information to the user pertaining to the website.

Claims (43)

1. A method for authenticating a user that requests information pertaining to a website, the method comprising the steps of:

an entity associated with a web crawler generating a filename and content for the user that is purportedly authorized to modify the website;

the entity sending the filename and the content toward the user without sending said information pertaining to the website toward the user, wherein a file with the filename and the content are not stored on a server that hosts the website when the filename and the content are sent toward the user;

wherein, after the filename and content are sent toward the user, the user creates a file with the filename, causes the file to be stored on a server that hosts the website, and causes the content to be stored in the file;

after sending the filename and content toward the user:

determining whether a file with the filename is stored on a server that hosts the website;

determining whether the file contains the content; and

in response to determining that the file is stored on the server and the file contains the content, the entity storing data that indicates that the user is authorized to receive said information pertaining to the website;

wherein said information pertaining to the website is sent toward the user only after it is determined that the file is stored on the server and the file contains the content;

wherein the steps of generating, sending, and storing are performed on one or more computing devices.

2. The method of claim 1 , wherein the information was generated by an entity that sent the filename and the content toward the user.

3. The method of claim 1 , wherein the steps further comprise before generating the filename and content for the user, receiving login information from the user, wherein the user indicates that the user is purportedly authorized to modify the website.

4. The method of claim 1 , wherein the steps further comprise before determining whether the file with the filename is stored on the server that hosts the website, receiving notification data from the user indicating that the file and content are on the website.

5. The method of claim 1 , wherein the steps further comprise in response to determining a) that the file with the filename is stored on the server that hosts the website, and b) that the file contains the content, associating the user with the website.

6. The method of claim 1 , wherein the step of storing data that indicates that the user is authorized to receive information pertaining to the website includes providing said information to the user.

7. The method of claim 1 , wherein the server is configured to return a soft 404 error message when an entity that generated the filename and content attempts to determine whether a particular file is stored on the server and the particular file is not stored on the server.

8. The method of claim 1 , wherein sending the filename and content toward a user includes instructing the user to store the file with the filename on the server and to store the content in the file.

9. A machine-readable storage medium storing instructions which, when executed by one or more processors, cause performance of the steps of claim 8 .

10. A method for authenticating a user that requests information pertaining to a website, the method comprising the steps of:

receiving login information from the user, wherein the user indicates that the user is purportedly authorized to modify the website;

in response to receiving the login information, generating a filename and content for the user and sending the filename and the content toward the user without sending said information pertaining to the website toward the user, wherein a file with the filename and the content are not stored on a server that hosts the website when the filename and the content are sent toward the user;

wherein, after the filename and content are sent toward the user, the user creates a file with the filename, causes the file to be stored on a server that hosts the website, and causes the content to be stored in the file;

after sending the filename and content toward the user, receiving notification data from the user indicating that a file with the filename and the content are stored on a server that hosts the website;

in response to receiving the notification data:

determining whether a file with the filename is stored on the server that hosts the website; and

determining whether the file contains the content; and

only after determining that the file is stored on the server and that the file contains the content,

associating the user with the website, and

storing data that indicates that the user is authorized to receive said information pertaining to the website;

wherein said information pertaining to the website is sent toward the user only after it is determined that the file is stored on the server and the file contains the content;

wherein the steps of receiving login information, generating, sending, and storing are performed on one or more computing devices.

11. The method of claim 1 , wherein the information pertaining to the website includes at least one of an identification of one or more origins of web traffic to the website or an identification of one or more other websites that link to the website.

12. A machine-readable storage medium storing instructions which, when executed by one or more processors, cause performance of the steps of claim 1 .

13. A machine-readable storage medium storing instructions which, when executed by one or more processors, cause performance of the steps of claim 3 .

14. A machine-readable storage medium storing instructions which, when executed by one or more processors, cause performance of the steps of claim 3 .

15. A machine-readable storage medium storing instructions which, when executed by one or more processors, cause performance of the steps of claim 4 .

16. A machine-readable storage medium storing instructions which, when executed by one or more processors, cause performance of the steps of claim 5 .

17. A machine-readable storage medium storing instructions which, when executed by one or more processors, cause performance of the steps of claim 6 .

18. A machine-readable storage medium storing instructions which, when executed by one or more processors, cause performance of the steps of claim 7 .

19. A machine-readable storage medium storing instructions which, when executed by one or more processors, cause performance of the steps of claim 10 .

20. A machine-readable storage medium storing instructions which, when executed by one or more processors, cause performance of the steps of claim 11 .

21. The method of claim 1 , wherein said information pertaining to said website includes at least one of the following: references to where web traffic to said website originates, references to a plurality of websites that contain a link to said website, or one or more errors of said website.

22. A machine-readable storage medium storing instructions which, when executed by one more processors, cause performance of the steps of claim 21 .

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE ASSIGNOR NAME PREVIOUSLY RECORDED AT REEL: 052853 FRAME: 0153. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Mar 29, 2021
From: R2 SOLUTIONS LLC
To: STARBOARD VALUE INTERMEDIATE FUND LP, AS COLLATERAL AGENT
Reel/Frame 056832/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE NAME PREVIOUSLY RECORDED ON REEL 053654 FRAME 0254. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST GRANTED PURSUANT TO THE PATENT SECURITY AGREEMENT PREVIOUSLY RECORDED. Recorded Dec 30, 2020
From: STARBOARD VALUE INTERMEDIATE FUND LP
To: R2 SOLUTIONS LLC
Reel/Frame 054981/0377 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jul 8, 2020
From: STARBOARD VALUE INTERMEDIATE FUND LP
To: ACACIA RESEARCH GROUP LLC; AMERICAN VEHICULAR SCIENCES LLC; BONUTTI SKELETAL INNOVATIONS LLC; CELLULAR COMMUNICATIONS EQUIPMENT LLC; INNOVATIVE DISPLAY TECHNOLOGIES LLC; LIFEPORT SCIENCES LLC; LIMESTONE MEMORY SYSTEMS LLC; MOBILE ENHANCEMENT SOLUTIONS LLC; MONARCH NETWORKING SOLUTIONS LLC; NEXUS DISPLAY TECHNOLOGIES LLC; PARTHENON UNIFIED MEMORY ARCHITECTURE LLC; R2 SOLUTIONS LLC; SAINT LAWRENCE COMMUNICATIONS LLC; STINGRAY IP SOLUTIONS LLC; SUPER INTERCONNECT TECHNOLOGIES LLC; TELECONFERENCE SYSTEMS LLC; UNIFICATION TECHNOLOGIES LLC
Reel/Frame 053654/0254 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 25, 2020
From: EXCALIBUR IP, LLC
To: R2 SOLUTIONS LLC
Reel/Frame 053459/0059 →
PATENT SECURITY AGREEMENT Recorded Jun 5, 2020
From: ACACIA RESEARCH GROUP LLC; AMERICAN VEHICULAR SCIENCES LLC; BONUTTI SKELETAL INNOVATIONS LLC; CELLULAR COMMUNICATIONS EQUIPMENT LLC; INNOVATIVE DISPLAY TECHNOLOGIES LLC; LIFEPORT SCIENCES LLC; LIMESTONE MEMORY SYSTEMS LLC; MERTON ACQUISITION HOLDCO LLC; MOBILE ENHANCEMENT SOLUTIONS LLC; MONARCH NETWORKING SOLUTIONS LLC; NEXUS DISPLAY TECHNOLOGIES LLC; PARTHENON UNIFIED MEMORY ARCHITECTURE LLC; R2 SOLUTIONS LLC; SAINT LAWRENCE COMMUNICATIONS LLC; STINGRAY IP SOLUTIONS LLC; SUPER INTERCONNECT TECHNOLOGIES LLC; TELECONFERENCE SYSTEMS LLC; UNIFICATION TECHNOLOGIES LLC
To: STARBOARD VALUE INTERMEDIATE FUND LP, AS COLLATERAL AGENT
Reel/Frame 052853/0153 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 3, 2016
From: YAHOO! INC.
To: EXCALIBUR IP, LLC
Reel/Frame 038950/0592 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 1, 2016
From: EXCALIBUR IP, LLC
To: YAHOO! INC.
Reel/Frame 038951/0295 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 18, 2016
From: YAHOO! INC.
To: EXCALIBUR IP, LLC
Reel/Frame 038383/0466 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 21, 2006
From: GARG, PRIYANK S.; KUMAR, AMIT; KARMIRANTZOS, APOSTOLOS; CHANG, DI; TONG, VIVIEN
To: YAHOO! INC.
Reel/Frame 018129/0189 →
Continuity (1)
Related Publication 20080021904A1 · Jan 24, 2008