IP Library Granted Patent US 10,778,668
Granted Patent B2
US 10,778,668 · App. 15/613,062 · Granted Sep 15, 2020

HTTP session validation module

Inventors: Abhijeet Bhattacharya (Bangalore, IN); Rajeev Arakkal (Kozhikode, IN)
Assignee: Dell Products L.P.
H04L63/083H04L63/0245H04L63/10H04L63/12H04L65/1069H04L67/141H04L67/146H04L63/062H04L63/1483H04L63/168H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,778,668
App. No.
15/613,062
Filed
Jun 2, 2017
Granted
Sep 15, 2020
Kind
B2
Art Unit
2435
USPC
726/7
Abstract

A web server receives a packet including a web request from a browser of a client. The request includes a session cookie comprising a client token and a session identifier. A secret session token is calculated based on the session identifier and header data that includes data from one or more packet header fields. The web request is processed if the secret session token matches the client token and blocked otherwise. Determining the secret session token may include hashing the session identifier, at least a portion of a user agent string included in a user agent header of the web request, and at least a portion of a source IP address included in an IP header of the packet. The secret session token may have been provided to the client as a session cookie included in a response to an initial web request from the client.

Claims (59)

1. A web server, comprising:

a processor;

a network interface to couple the web server to a network; and

a computer readable medium including processor executable instructions that, when executed by the processor, result in operations comprising:

receiving a pre-session request from a web client;

extracting, from the pre-session request, one or more data items indicative of a source of the pre-session request;

generating a session identifier corresponding to the pre-session request;

generating a secret session token based on the one or more data items and the session identifier;

sending a response to the pre-session request, wherein the response includes a tokenized session identifier indicative of the session identifier and the secret session token; wherein the tokenized session identifier comprises a concatenation, wherein the concatenation comprises the session identifier concatenated with and the secret session token;

responsive to receiving an in-session request from the web client, performing a verification of a client token, included with the in-session request, against the secret session token;

responsive to verifying the client token, processing the in-session request; and

responsive to not verifying the client token, blocking the in-session request.

2. The web server of claim 1 , wherein the client token included in the in-session request is included in a session cookie included with the in-session request.

3. The web server of claim 1 , further comprising:

determining, based on a presence or an absence of a session identifier within a particular request, whether the particular request comprises a pre-session request.

4. The web server of claim 1 , wherein the pre-session request comprises a hypertext transfer protocol (HTTP) request and further wherein the pre-session request comprises an HTTP GET request.

5. The web server of claim 4 , wherein extracting the one or more data items comprises, extracting a first data item indicative of a client browser corresponding to the pre-session request.

6. The web server of claim 5 , wherein the first data item comprises user agent data included in a header of the pre-session request.

7. The web server of claim 6 , wherein extracting the one or more data items comprises, extracting a second data item, indicative of a network address, corresponding to the pre-session request.

8. The web server of claim 7 , wherein the second data item comprises a network portion of a source IP address of the pre-session request, wherein the network portion of the source IP address comprises a portion of the IP address that does not vary among requests within a particular session.

9. The web server of claim 8 , wherein generating the secret session token includes performing a hash of:

the network portion of the source IP address;

the user agent data; and

the session identifier.

10. A web server method, comprising:

receiving a pre-session request from a web client;

extracting from the pre-session request one or more data items indicative of a source of the pre-session request;

generating a session identifier corresponding to the pre-session request;

generating a secret session token based on the one or more data items and the session identifier;

sending a response to the pre-session request, wherein the response includes a tokenized session identifier indicative of the session identifier and the secret session token, wherein the tokenized session identifier comprises a concatenation, wherein the concatenation comprises the session identifier concatenated with the secret session token;

responsive to receiving an in-session request from the web client, performing a verification of a client token, included with the in-session request, against the secret session identifier;

responsive to verifying the client token, processing the in-session request; and

responsive to not verifying the client token, blocking the in-session request.

11. The web server method of claim 10 , wherein the client token included in the in-session request is included in a session cookie included with the in-session request.

12. The web server method of claim 10 , further comprising:

determining, based on a presence or absence of a session identifier within a particular web request, whether the particular web request comprises a pre-session request.

13. The web server method of claim 10 , wherein the pre-session request comprises a hypertext transfer protocol (HTTP) request and further wherein the pre-session request comprises an HTTP GET request.

14. The web server method of claim 13 , wherein extracting the one or more data items comprises, extracting a first data item indicative of a client browser corresponding to the pre-session request.

15. The web server method of claim 14 , wherein the first data item comprises user agent data included in a header of the pre-session request.

16. The web server method of claim 15 , wherein extracting the one or more data items comprises, extracting a second data item, indicative of a network address, corresponding to the pre-session request.

17. The web server method of claim 16 , wherein the second data item comprises a network portion of a source IP address of the pre-session request, wherein the network portion of the source IP address comprises a portion of the source IP address that does not vary among requests within a particular session, wherein the portion of the source IP address that does not vary among requests within the particular session comprises a most significant 16 bits of a 32-bit IP address.

18. The web server method of claim 17 , wherein generating the secret session token includes performing a hash of:

the network portion of the source IP address;

the user agent data; and

the session identifier.

19. An information handling system, comprising:

a processor;

a network interface, configured to communicatively couple the processor to a network; and

a computer readable medium including processor executable instructions that, when executed, cause the processor to perform operations comprising:

receiving a packet comprising a web request from a web client, wherein the web request includes a tokenized session identifier, wherein the tokenized session identifier comprises a concatenation of a client token and a session identifier;

determining, based on the session identifier and header data comprising data from one or more header fields of the packet, a secret session token for the web request;

determining whether the secret session token for the web request matches the client token;

processing the web request responsive to the secret session token matching the client token; and

blocking the web request responsive to the secret session token not matching the client token.

20. The information handling system of claim 19 , wherein said determining comprises:

hashing a combination of:

the session identifier;

at least a portion of a user agent string included in a user agent header of the web request; and

a network portion of a source IP address included in an IP header of the packet.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (043775/0082) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060958/0468 →
RELEASE OF SECURITY INTEREST AT REEL 043772 FRAME 0750 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058298/0606 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Sep 6, 2017
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 043772/0750 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Sep 6, 2017
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 043775/0082 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 14, 2017
From: BHATTACHARYA, ABHIJEET; ARAKKAL, RAJEEV
To: DELL PRODUCTS L.P.
Reel/Frame 043286/0480 →
Continuity (1)
Related Publication 20180351936A1 · Dec 6, 2018