×

Cross-site timed out authentication management

  • US 20040073660A1
  • Filed: 10/15/2002
  • Published: 04/15/2004
  • Est. Priority Date: 10/15/2002
  • Status: Active Grant
First Claim
Patent Images

1. A method for monitoring Web browsing activity across a network of affiliated sites and for enabling said sites to detect and to force re-authentication upon users who have had a period of network-wide inactivity longer than a site-specific maximum allowable inactivity period, wherein said network comprises at least one network authentication server (NAS) which maintains a network-wide activity tracking (NATr) cookie, said NATr cookie comprising a set of network-wide activity tracking (NATr) parameters for each registered user, and wherein each of said sites maintains a site-specific activity tracking (SATr) cookie which comprises a set of site-specific activity tracking (SATr) parameters for each registered user, the method comprising the steps of:

  • updating the user'"'"'s NATr parameters in said NATr cookie upon performance of each activity indicating event by the user in the network;

    updating the user'"'"'s SATr parameters in said SATr cookie upon performance of each activity indicating event by the user in the site;

    determining upon request the maximum period of site-specific inactivity experienced by the user since his last network authentication;

    checking the user'"'"'s network-wide inactivity if the maximum period of site-specific inactivity exceeds a predefined threshold;

    determining upon request the maximum period of network-wide inactivity experienced by the user since his last network authentication; and

    re-authenticating the user if the maximum period of network-wide inactivity exceeds the predefined threshold.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×