What is a login session?¶
A login session is the period of authorised account access that follows authentication.
The login gets you in. The session is what lets the account keep being used afterwards.
That distinction is useful because the activity you care about may happen long after the original login.
One login can support a lot of later activity¶
Imagine this timeline:
S-4812 is created.The message at 18:02 does not require a new login at 18:02.
The useful link is the session.
What records may describe a session?¶
A provider may record:
- session ID;
- account ID;
- creation time;
- last activity;
- application or browser;
- device information;
- source IP addresses;
- authentication method;
- token refreshes;
- expiry; and
- revocation or logout events.
Those fields can connect several account events together.
One account can have several sessions at once¶
A person may be signed in on:
- a phone;
- a laptop;
- a work computer;
- a tablet;
- a connected application.
Each may have its own session.
S-4812Mobile app · active since MondayS-7741Browser · created WednesdayS-9902Connected service · token-basedIf the provider can tell you which session generated the disputed event, that can narrow the investigation quickly.
Session continuity is not automatically user continuity¶
The person who started a session may not be the person who later used it.
A shared device may remain unlocked.
A browser session may be remotely controlled.
Session material may be copied.
So use the session to connect the technical events, then use device and real-world evidence to identify who controlled that session at the relevant time.
Who was actually using the account? is the natural next step.
The practical point is: a session joins a period of account activity together. It is often the bridge between a login event and the later action you are investigating.