首页> 外国专利> Method and apparatus for implementing secure VPN access via modified certificate strings

Method and apparatus for implementing secure VPN access via modified certificate strings

机译:通过修改后的证书字符串实现安全VPN访问的方法和装置

摘要

A mobile or other device (10) connects to a server via a publicly accessible network (14) such as the Internet. After installation upon the device, a virtual private network (VPN) client connects to the server (20) and downloads a VPN profile. In one embodiment the device creates public/private key pairs and requests enrollment of a digital certificate. In another embodiment a digital certificate and public/private key pairs are provided. The device also receives a digital certificate from the server (20) and verifies the server certificate by requesting the user to supply a portion of a fingerprint for the certificate. The invention further includes an automatic content updating (ACU) client that downloads a user profile for the VPN, requests certificate enrollment, and updates the VPN client and other applications when new content is available. A security service manager (SSM)(20) server includes, or is in communication with, a Web server (90), multiple databases (98), an enrollment gateway (22) and an internal certification authority (CA)(28). A VPN policy manager (26) application creates and manages VPN profiles and/or policies and communicates with the SSM server (20). The SSM server (22), which may reside on an enterprise intranet, may further communicate with one or more external CAs (28).
机译:移动设备或其他设备(10)通过公共访问网络(14)(例如Internet)连接到服务器。在设备上安装后,虚拟专用网络(VPN)客户端连接到服务器(20)并下载VPN配置文件。在一个实施例中,该设备创建公钥/私钥对并请求数字证书的注册。在另一个实施例中,提供了数字证书和公共/私人密钥对。该设备还从服务器(20)接收数字证书,并通过请求用户提供证书的指纹的一部分来验证服务器证书。本发明进一步包括自动内容更新(ACU)客户端,该客户端下载用于VPN的用户简档,请求证书注册,并且在新内容可用时更新VPN客户端和其他应用。安全服务管理器(SSM)(20)服务器包括Web服务器(90),多个数据库(98),注册网关(22)和内部证书颁发机构(CA)(28)或与之通信。 VPN策略管理器(26)应用创建并管理VPN配置文件和/或策略,并与SSM服务器(20)通信。可以驻留在企业内联网上的SSM服务器(22)可以进一步与一个或多个外部CA(28)通信。

著录项

  • 公开/公告号EP1494428B1

    专利类型

  • 公开/公告日2007-01-17

    原文格式PDF

  • 申请/专利权人 NOKIA INC;

    申请/专利号EP20040253083

  • 发明设计人 PALOJARVI JARI;KARJALA JARI;

    申请日2004-05-26

  • 分类号H04L29/06;H04Q7/38;

  • 国家 EP

  • 入库时间 2022-08-21 20:49:02

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号