首页> 外国专利> Avoiding interdicted certificate cache poisoning for secure sockets layer forward proxy

Avoiding interdicted certificate cache poisoning for secure sockets layer forward proxy

机译:避免安全套接字层正向代理的中断证书缓存中毒

摘要

A device may receive a message, associated with establishing a secure session, including a first certificate chain associated with a server device. The device may generate a first certificate fingerprint associated with the first certificate chain and determine a policy identifier associated with a security policy on which the first certificate chain is to be validated. The device may identify a second certificate fingerprint associated with a second certificate chain that has been validated based on the security policy. The device may determine whether the first certificate fingerprint matches the second certificate fingerprint. The device may provide a stored interdicted certificate chain, associated with the second certificate chain, based on determining that the first certificate fingerprint matches the second certificate fingerprint, or provide a generated interdicted certificate chain, associated with the first certificate chain, based on determining that the first certificate fingerprint does not match the second certificate fingerprint.
机译:设备可以接收与建立安全会话相关联的消息,该消息包括与服务器设备相关联的第一证书链。设备可以生成与第一证书链相关联的第一证书指纹,并确定与要在其上验证第一证书链的安全策略相关联的策略标识符。设备可以识别与基于安全策略已被验证的第二证书链相关联的第二证书指纹。设备可以确定第一证书指纹是否与第二证书指纹匹配。该设备可以基于确定第一证书指纹与第二证书指纹相匹配来提供与第二证书链相关联的存储的被禁证书链,或者基于确定该证书可以提供与第一证书链相关联的所生成的被禁证书链。第一证书指纹与第二证书指纹不匹配。

著录项

  • 公开/公告号US10193698B1

    专利类型

  • 公开/公告日2019-01-29

    原文格式PDF

  • 申请/专利权人 JUNIPER NETWORKS INC.;

    申请/专利号US201514751332

  • 发明设计人 PREMENJIT DAS;RAJEEV CHAUBEY;

    申请日2015-06-26

  • 分类号H04L9/32;H04L29/06;

  • 国家 US

  • 入库时间 2022-08-21 12:09:51

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号