首页> 外国专利> Providing forward secrecy in a terminating SSL/TLS connection proxy using ephemeral Diffie-Hellman key exchange

Providing forward secrecy in a terminating SSL/TLS connection proxy using ephemeral Diffie-Hellman key exchange

机译:使用临时Diffie-Hellman密钥交换在终止的SSL / TLS连接代理中提供前向保密性

摘要

An infrastructure delivery platform provides a proxy service as an enhancement to the TLS/SSL protocol to off-load to an external server the generation of a digital signature, the digital signature being generated using a private key that would otherwise have to be maintained on a terminating server. Using this service, instead of digitally signing (using the private key) “locally,” the terminating server proxies given public portions of ephemeral key exchange material to the external server and receives, in response, a signature validating the terminating server is authorized to continue with the key exchange. In this manner, a private key used to generate the digital signature (or, more generally, to facilitate the key exchange) does not need to be stored in association with the terminating server. Rather, that private key is stored only at the external server, and there is no requirement for the pre-master secret to travel (on the wire).
机译:基础设施交付平台提供了代理服务,作为对TLS / SSL协议的增强,可以将生成的数字签名卸载到外部服务器,数字签名是使用私钥生成的,否则必须将其保留在服务器上。终止服务器。使用此服务,而不是在本地进行数字签名(使用私钥),而是将临时密钥交换材料的公共部分提供给外部服务器,然后将终结服务器代理到外部服务器,并作为响应,接收验证终结服务器的签名以继续与密钥交换。以这种方式,不需要与终止服务器相关联地存储用于生成数字签名(或更普遍地,以促进密钥交换)的私钥。而是,该私钥仅存储在外部服务器上,并且不需要(通过有线方式)传输预主密钥。

著录项

  • 公开/公告号US2019253261A1

    专利类型

  • 公开/公告日2019-08-15

    原文格式PDF

  • 申请/专利权人 AKAMAI TECHNOLOGIES INC.;

    申请/专利号US201916391411

  • 申请日2019-04-23

  • 分类号H04L9/32;H04L9/14;H04L29/06;H04L9/30;H04L9/08;

  • 国家 US

  • 入库时间 2022-08-21 12:10:00

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号