-
公开(公告)号:US10178181B2
公开(公告)日:2019-01-08
申请号:US14328094
申请日:2014-07-10
Applicant: Cisco Technology, Inc.
Inventor: Eitan Ben-Nun , Michael Zayats , Daniel G. Wing , Kirtesh Patil , Jaideep Padhye , Manohar B. Hungund , Saravanan Agasaveeran
Abstract: An interposer is provided that is configured to interpose into an application security protocol exchange by obtaining application session security state. The interposer does this without holding any private keying material of client or server. An out-of-band Security Assistant Key Escrow service (SAS/SAKE) is also provided. The SAKE resides in the secure physical network perimeter and holds the private keying material required to derive session keys for interposing into application security protocol. During a security protocol handshake, the interposer sends SAKE security protocol handshake messages and in return receives from the SAKE session security state that allows it to participate in application security protocol.
-
公开(公告)号:US20150288679A1
公开(公告)日:2015-10-08
申请号:US14328094
申请日:2014-07-10
Applicant: Cisco Technology, Inc.
Inventor: Eitan Ben-Nun , Michael Zayats , Daniel G. Wing , Kirtesh Patil , Jaideep Padhye , Manohar B. Hungund , Saravanan Agasaveeran
CPC classification number: H04L67/141 , H04L63/0281 , H04L63/0823 , H04L63/168 , H04L67/28
Abstract: An interposer is provided that is configured to interpose into an application security protocol exchange by obtaining application session security state. The interposer does this without holding any private keying material of client or server. An out-of-band Security Assistant Key Escrow service (SAS/SAKE) is also provided. The SAKE resides in the secure physical network perimeter and holds the private keying material required to derive session keys for interposing into application security protocol. During a security protocol handshake, the interposer sends SAKE security protocol handshake messages and in return receives from the SAKE session security state that allows it to participate in application security protocol.
Abstract translation: 提供了一种插入器,其被配置为通过获得应用程序会话安全状态来插入到应用程序安全协议交换中。 插件不需要持有客户端或服务器的任何私有密钥材料即可。 还提供了带外安全助理密钥托管服务(SAS / SAKE)。 SAKE驻留在安全的物理网络周边,并保存导出会话密钥所需的私人密钥材料,以插入到应用安全协议中。 在安全协议握手期间,插入器发送SAKE安全协议握手消息,并返回从SAKE会话安全状态接收,允许其参与应用安全协议。
-