Citrix Systems, Inc.
PREVENTING HTTP COOKIE STEALING USING COOKIE MORPHING
Last updated:
Abstract:
Described embodiments provide systems and methods for morphing or regenerating validation information. A client can receive, via a device, an authentication cookie for access to a server. The device may maintain a sequence number and a cryptographic secret. The client may use the cryptographic secret and a cookie engine to generate validation cookie information with an updated sequence number. The client may send the authentication cookie to the device via a hypertext transfer protocol (HTTP) message to validate the authentication cookie. The client may send the validation cookie information with the updated sequence number to the device via a HTTP message to validate the authentication cookie
Status:
Application
Type:
Utility
Filling date:
13 Nov 2020
Issue date:
19 May 2022