Personally, I'd reccomend instead of just fopening the file, I'd pass along an encoded version of the session in $_GET form.
For example:
$link = "http://www.blahdeblah.com/index.php?session=".session_encode();
And on the fopened page, use session_decode to check the credentials.
But, there is no real way to keep the session alive, as the client is not accessing the site. Secondly, sessions are unique to one domain, and if you're fopen'ing, then I assume this is on another domain altogether.