白丝美女被狂躁免费视频网站,500av导航大全精品,yw.193.cnc爆乳尤物未满,97se亚洲综合色区,аⅴ天堂中文在线网官网

Method to monitor sensitive web embedded code authenticity

專利號
US11997079B2
公開日期
2024-05-28
申請人
THALES DIS FRANCE SAS(FR Meudon)
發(fā)明人
Olivier Tesson; Patrick George; Sridhar Bhupathiraju; Anthony Ferrari
IPC分類
H04L9/40; H04L67/02
技術(shù)領(lǐng)域
broker,token,provider,end,brk,identity,front,contextual,user,script
地域: Meudon

摘要

Mechanism to enable an Identity Provider having an authorization gateway and an authentication interface to control the download and the execution of an authentication script component managed by a broker or by a service provider.

說明書

1 2 3 4 5 6 7 8 9 10 11 12 13

The monitoring of the authentication front-end by the authorization gateway using a simple status flag is an economical and efficient implementation.

According to a first implementation, the front-end delivery is in the broker trust boundaries.

This implementation corresponds to the situation where the broker is allowed to create the authentication front-end by the identity provider. However the identity provider has the possibility to check the allocated random token, the contextual information and the broker identifier.

According to a second implementation, the front-end delivery is on the identity provider's core service back-end which is the back-end for the services as proposed by the identity provider.

In such an implementation, the identity provider generates itself the authentication front-end script and thus has further the control of the creation of the script.

According to an advantageous feature, the broker, when embedding the URL of the authentication front-end, also embeds integrity data in the web application login page to enable a sub resource integrity check.

The presence of integrity data enables to check, when needed, the integrity of the authentication front-end as created at the front end delivery.

Advantageously, the method comprises an additional step of, for the user agent, validating the authentication front-end integrity using a sub resource integrity check after reception of the authentication front-end.

Such a check of the integrity enables the user agent to be sure that the right authentication front end as previously created by the front-end delivery is well the one that it has received.

權(quán)利要求

1
微信群二維碼
意見反饋