首页> 外国专利> Transparently converting a TLS session connection to facilitate session resumption

Transparently converting a TLS session connection to facilitate session resumption

机译:透明地转换TLS会话连接以促进会话恢复

摘要

A network-based appliance includes a mechanism to provide TLS inspection with session resumption, but without requiring that a session cache be maintained. To this end, the inspector is configured to cause the TLS client to participate in maintaining the session context, in effect on behalf of the TLS inspector. In operation, when the inspector first receives a session ID from the TLS server, the inspector generates and issues to the client a session ticket that includes the original session ID and other session context information. In this manner, the inspector converts the Session ID-based connection to a Session Ticket-based connection. The session ticket is encrypted by the inspector to secure the session information. When the TLS client presents the session ticket to resume the TLS connection, the inspector decrypts the ticket and retrieves the session ID from it directly. The inspector then uses the original session ID to resume the TLS session.
机译:基于网络的设备包括一种机制,该机制可提供具有会话恢复功能的TLS检查,但无需维护会话缓存。为此,检查器被配置为代表TLS检查器,使TLS客户端参与维护会话上下文。在操作中,当检查员首先从TLS服务器接收会话ID时,检查员会生成会话票据并将其发行给客户端,该会话票据包括原始会话ID和其他会话上下文信息。以这种方式,检查器将基于会话ID的连接转换为基于会话票证的连接。会话票证由检查员加密以保护会话信息。当TLS客户端提供会话票证以恢复TLS连接时,检查器解密该票证并直接从中获取会话ID。然后,检查器使用原始会话ID恢复TLS会话。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号