-
公开(公告)号:US20220255937A1
公开(公告)日:2022-08-11
申请号:US17169086
申请日:2021-02-05
Applicant: Cisco Technology, Inc.
Inventor: Hendrikus GP Bosch , Jeffrey Michael Napper , Alessandro Duminuco , Sape Jurrien Mullender , Julien Barbot , Vinny Parla
Abstract: This disclosure describes techniques including, by a domain name service (DNS), receiving a name resolution request from a client computing device and, by the DNS, providing a nonce to the client computing device, wherein a service is configured to authorize a connection request from the client computing device based at least in part on processing the nonce. This disclosure further describes techniques include a method of validating a connection request from a client computing device, including receiving the connection request, the connection request including a nonce. The techniques further include determining that the nonce is a valid nonce. The techniques further include, based at least in part on determining that the nonce is a valid nonce, authorizing the connection request and disabling the nonce.
-
公开(公告)号:US11683309B2
公开(公告)日:2023-06-20
申请号:US17169086
申请日:2021-02-05
Applicant: Cisco Technology, Inc.
Inventor: Hendrikus GP Bosch , Jeffrey Michael Napper , Alessandro Duminuco , Sape Jurrien Mullender , Julien Barbot , Vinny Parla
IPC: H04L9/40 , H04L61/4511
CPC classification number: H04L63/10 , H04L61/4511 , H04L63/0876 , H04L63/20 , H04L63/0272
Abstract: This disclosure describes techniques including, by a domain name service (DNS), receiving a name resolution request from a client computing device and, by the DNS, providing a nonce to the client computing device, wherein a service is configured to authorize a connection request from the client computing device based at least in part on processing the nonce. This disclosure further describes techniques include a method of validating a connection request from a client computing device, including receiving the connection request, the connection request including a nonce. The techniques further include determining that the nonce is a valid nonce. The techniques further include, based at least in part on determining that the nonce is a valid nonce, authorizing the connection request and disabling the nonce.
-
公开(公告)号:US20230283608A1
公开(公告)日:2023-09-07
申请号:US18197895
申请日:2023-05-16
Applicant: Cisco Technology, Inc.
Inventor: Hendrikus GP Bosch , Jeffrey Michael Napper , Alessandro Duminuco , Sape Jurrien Mullender , Julien Barbot , Vinny Parla
IPC: H04L9/40 , H04L61/4511
CPC classification number: H04L63/10 , H04L61/4511 , H04L63/0876 , H04L63/20 , H04L63/0272
Abstract: This disclosure describes techniques including, by a domain name service (DNS), receiving a name resolution request from a client computing device and, by the DNS, providing a nonce to the client computing device, wherein a service is configured to authorize a connection request from the client computing device based at least in part on processing the nonce. This disclosure further describes techniques include a method of validating a connection request from a client computing device, including receiving the connection request, the connection request including a nonce. The techniques further include determining that the nonce is a valid nonce. The techniques further include, based at least in part on determining that the nonce is a valid nonce, authorizing the connection request and disabling the nonce.
-
公开(公告)号:US12261847B2
公开(公告)日:2025-03-25
申请号:US18197895
申请日:2023-05-16
Applicant: Cisco Technology, Inc.
Inventor: Hendrikus G P Bosch , Jeffrey Michael Napper , Alessandro Duminuco , Sape Jurrien Mullender , Julien Barbot , Vinny Parla
IPC: H04L9/40 , H04L61/4511
Abstract: This disclosure describes techniques including, by a domain name service (DNS), receiving a name resolution request from a client computing device and, by the DNS, providing a nonce to the client computing device, wherein a service is configured to authorize a connection request from the client computing device based at least in part on processing the nonce. This disclosure further describes techniques include a method of validating a connection request from a client computing device, including receiving the connection request, the connection request including a nonce. The techniques further include determining that the nonce is a valid nonce. The techniques further include, based at least in part on determining that the nonce is a valid nonce, authorizing the connection request and disabling the nonce.
-
公开(公告)号:US11516260B2
公开(公告)日:2022-11-29
申请号:US17166921
申请日:2021-02-03
Applicant: Cisco Technology, Inc.
Inventor: Alessandro Duminuco , Hendrikus G. P. Bosch , Jeffrey Michael Napper , Vinny Parla , Julien Barbot , Sape Jurrien Mullender
IPC: G06F17/00 , H04L9/40 , H04L67/141 , H04L67/146 , H04L61/4511 , H04L67/01
Abstract: Techniques for utilizing an enterprise traffic interception service (TIS) to enforce policies that mandate how clients access software as a service (SaaS) offered by service providers and selectively intercept enterprise network traffic utilizing a domain name service (DNS) and a single sign-on (SSO) service on a per-client per-service basis. The TIS may include a DNS server, an identity provider service, a TLS inspecting proxy, and/or a policy server. The DNS server may handle requests to resolve an address of a service, and identify a policy, stored in the policy server, to redirect the client based on the identity of the client and the service. The identity provider service may later query the policy server during client authorization for the service to verify that the client request is in line with the policy and allow or deny access to the service.
-
公开(公告)号:US20220247791A1
公开(公告)日:2022-08-04
申请号:US17166921
申请日:2021-02-03
Applicant: Cisco Technology, Inc.
Inventor: Alessandro Duminuco , Hendrikus G.P. Bosch , Jeffrey Michael Napper , Vinny Parla , Julien Barbot , Sape Jurrien Mullender
Abstract: Techniques for utilizing an enterprise traffic interception service (TIS) to enforce policies that mandate how clients access software as a service (SaaS) offered by service providers and selectively intercept enterprise network traffic utilizing a domain name service (DNS) and a single sign-on (SSO) service on a per-client per-service basis. The TIS may include a DNS server, an identity provider service, a TLS inspecting proxy, and/or a policy server. The DNS server may handle requests to resolve an address of a service, and identify a policy, stored in the policy server, to redirect the client based on the identity of the client and the service. The identity provider service may later query the policy server during client authorization for the service to verify that the client request is in line with the policy and allow or deny access to the service.
-
-
-
-
-