首页> 外国专利> Hybrid SSL/IPSec network management system

Hybrid SSL/IPSec network management system

机译:混合SSL / IPSec网络管理系统

摘要

System and method for operating, via the Internet, a distributed network in which an SSL VPN is employed to establish and manage an IPSec VPN. During network creation, an SSL VPN is first established between a master server and each node. Using a common routing table and a common SSL key table maintained by the master server, each node may selectively establish an IPSec VPN with other nodes. Once established, each node maintains a respective segment of a distributed IPSec key table. Periodically, each client and each server, other than the master server, cooperates with the master server to refresh the master and local copies of the common routing and common SSL key tables, and the local segment of the distributed IPSec key table. In the event a change has occurred in either the routing or key information for any server, all pending IPSec VPN connections with that server must be reestablished, using the information in the refreshed local copies of the common routing and common SSL key tables The master server controls the network configuration by assigning to each node permissible IPSec connections. By updating and maintaining copies of the common routing and common SSL key tables at multiple nodes in the network, and local segments of the distributed IPSec key table, the network can quickly recover and rebuild itself in the event that an SSL or IPSec connection with any node is lost.
机译:用于经由因特网操作分布式网络的系统和方法,其中采用SSL VPN来建立和管理IPSec VPN。在网络创建期间,首先在主服务器和每个节点之间建立SSL VPN。使用主服务器维护的公用路由表和公用SSL密钥表,每个节点可以与其他节点选择性地建立IPSec VPN。一旦建立,每个节点将维护分布式IPSec密钥表的相应段。除主服务器外,每个客户端和每个服务器还定期与主服务器合作,以刷新公用路由和公用SSL密钥表的主副本和本地副本以及分布式IPSec密钥表的本地段。如果任何服务器的路由或密钥信息发生了变化,则必须使用刷新后的公共路由和公共SSL密钥表本地副本中的信息重新建立与该服务器的所有未决IPSec VPN连接。通过为每个节点分配允许的IPSec连接来控制网络配置。通过更新和维护网络中多个节点上的公共路由和公共SSL密钥表以及分布式IPSec密钥表的本地段的副本,在与任何其他SSL或IPSec连接发生连接的情况下,网络可以快速恢复并重建自身节点丢失。

著录项

  • 公开/公告号US2006230446A1

    专利类型

  • 公开/公告日2006-10-12

    原文格式PDF

  • 申请/专利权人 LAN NGOC VU;

    申请/专利号US20050100304

  • 发明设计人 LAN NGOC VU;

    申请日2005-04-06

  • 分类号G06F15/16;

  • 国家 US

  • 入库时间 2022-08-21 21:48:07

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号