首页> 外国专利> SSL step-up

SSL step-up

机译:SSL升级

摘要

A process is provided that allows an exportable SSL client to negotiate an encrypted session using strong encryption with a server if the server is allowed to use strong encryption. With this process, the SSL client is normally limited to export strength encryption. But, when it is communicating with an approved server, it is able to expand the available set of encryption algorithms to include stronger algorithms/key lengths. The process involves performing an SSL handshake twice. The process begins when a client, i.e. a user, wants to establish a session with a server. The client first initiates a network connection to the server. The first handshake between an export client and an approved server results in an SSL session that uses export strength encryption. This establishes a connection using an exportable cipher suite. The client examines the server's certificate obtained as part of the first handshake. If the server is not approved, the SSL session transfers application data that are protected by the export cipher. If the server is approved, then the client initiates a second handshake, this time allowing stronger cipher suites. The result of the second handshake is an SSL session that uses strong encryption. The SSL session may then be used to transfer application data that are protected by the strong cipher suite. At this point, the process is complete.
机译:提供了一种过程,如果允许服务器使用强加密,则该过程允许可导出的SSL客户端与服务器使用强加密来协商加密会话。通过此过程,SSL客户端通常仅限于导出强度加密。但是,当它与批准的服务器通信时,它能够扩展可用的加密算法集以包括更强的算法/密钥长度。该过程涉及执行两次SSL握手。当客户端,即用户,想要与服务器建立会话时,该过程开始。客户端首先启动与服务器的网络连接。导出客户端和批准的服务器之间的第一次握手将导致使用导出强度加密的SSL会话。这使用可导出的密码套件建立连接。客户端检查作为第一次握手的一部分获得的服务器证书。如果未批准服务器,则SSL会话将传输受导出密码保护的应用程序数据。如果服务器被批准,则客户端将发起第二次握手,这一次允许使用更强大的密码套件。第二次握手的结果是使用强加密的SSL会话。然后,可以使用SSL会话来传输受强密码套件保护的应用程序数据。至此,该过程完成。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号