首页> 外国专利> Systems and methods for proxying encrypted traffic to protect origin servers from internet threats

Systems and methods for proxying encrypted traffic to protect origin servers from internet threats

机译:用于保护加密流量的系统和方法,以保护来自互联网威胁的原点服务器

摘要

This document describes, among other things, systems and methods for more efficiently resuming a client-to-origin TLS session through a proxy layer that fronts the origin in order to provide network security services. At the time of an initial TLS handshake with an unknown client, for example, the proxy can perform a set of security checks. If the client passes the checks, the proxy can transmit a ‘proxy token’ upstream to the origin. The origin can incorporate this token into session state data which is passed back to and stored on the client, e.g., using a TLS session ticket extension field, pre-shared key extension field, or other field. On TLS session resumption, when the client sends the session state data, the proxy can recover its proxy token from the session state data, and upon successful validation, bypass security checks that it would otherwise perform against the client, thereby more efficiently handling known clients.
机译:除其他外,本文档还介绍通过前端原点的代理层更有效地恢复客户端到原点TLS会话的系统和方法,以便提供网络安全服务。例如,在具有未知客户端的初始TLS握手时,代理可以执行一组安全检查。如果客户端通过检查,则代理可以将“代理令牌”传输到原点。原点可以将此标记包含到会话状态数据中,该数据被传递回并存储在客户端上,例如,使用TLS会话故障票扩展字段,预共享密钥扩展字段或其他字段。在TLS会话恢复时,当客户端发送会话状态数据时,代理可以从会话状态数据恢复其代理令牌,并且在成功验证时,绕过安全检查它否则会对客户端执行,从而更有效地处理已知的客户端。

著录项

  • 公开/公告号US11019034B2

    专利类型

  • 公开/公告日2021-05-25

    原文格式PDF

  • 申请/专利权人 AKAMAI TECHNOLOGIES INC.;

    申请/专利号US201816194022

  • 发明设计人 STEPHEN L. LUDIN;MICHAEL A. BISHOP;

    申请日2018-11-16

  • 分类号G06F21;H04L29/06;

  • 国家 US

  • 入库时间 2022-08-24 18:52:36

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号