Citrix Systems, Inc.
PREVENTING HTTP COOKIE STEALING USING COOKIE MORPHING

Last updated:

Abstract:

Described embodiments provide systems and methods for morphing or regenerating validation information. A client can receive, via a device, an authentication cookie for access to a server. The device may maintain a sequence number and a cryptographic secret. The client may use the cryptographic secret and a cookie engine to generate validation cookie information with an updated sequence number. The client may send the authentication cookie to the device via a hypertext transfer protocol (HTTP) message to validate the authentication cookie. The client may send the validation cookie information with the updated sequence number to the device via a HTTP message to validate the authentication cookie

Status:
Application
Type:

Utility

Filling date:

13 Nov 2020

Issue date:

19 May 2022