首页> 外国专利> Public key of a host operating behind a reverse proxy is associated with the proxy's Host Identity in a Host Identity Protocol session

Public key of a host operating behind a reverse proxy is associated with the proxy's Host Identity in a Host Identity Protocol session

机译:在反向代理后面运行的主机的公钥在主机身份协议会话中与代理的主机身份相关联

摘要

Utilising the normal Host Identity Protocol (HIP) it is difficult to establish a secure session with a host operating from behind a reverse proxy, such as a server in a web cluster. To overcome this the host sends its public key to the reverse proxy, which then binds the key to its own host identity (HI). An external host will then establish a communication link with the reverse proxy's HI using the original host's public key. The reverse proxy forwards these message to the original host, which deals with them in the normal fashion, except that replies are also directed to the reverse proxy's HI, with the reverse proxy forwarding the communication after replacing the original host's signature with its own. This arrangement allows the establishment of a secure HIP session between the hosts without the need for the reverse proxy to de/re-encrypt the communications.
机译:利用普通的主机身份协议(HIP),很难与从反向代理后面运行的主机(例如Web群集中的服务器)建立安全会话。为了克服这个问题,主机将其公共密钥发送给反向代理,然后反向代理将密钥绑定到其自己的主机身份(HI)。然后,外部主机将使用原始主机的公钥与反向代理的HI建立通信链接。反向代理将这些消息转发给原始主机,该主机以正常方式对其进行处理,所不同的是,回复也将定向到反向代理的HI,而反向代理在将原始主机的签名替换为自己的签名后将转发通信。这种安排允许在主机之间建立安全的HIP会话,而无需反向代理对通信进行解密/重新加密。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号