Session Management Techniques

Session Management Techniques

In this Solution Brief we outline different session management scenarios and solutions you can implement in the Curity Identity Server.

In this solution brief, we outline session management techniques you can use in the Curity Identity Server.

As authentication has grown more complex — with more features added to increase security and reliability — session management has become increasingly critical. It's no longer enough to create a session cookie, let the user log out when they choose, or let the browser clear the cookie on exit. Applications need more sophisticated session management, especially across the different devices used to access the same application.

Certain session management features are becoming common throughout the market. In this document, we take a closer look at three of them: limiting users to one active session, notifying users when a session is revoked elsewhere, and letting users list and revoke their own active sessions.

Table of contents

  • Introduction — 1

  • What is a Session? (What to Revoke) — 2

  • One Active Session — 4

  • Notification on Session Revocation — 7

  • Session Listing and Revoking — 8

  • Conclusion — 10

  • For Further Information — 10

Related resources