发明公开
EP3085008A4 PROVIDING FORWARD SECRECY IN A TERMINATING TLS CONNECTION PROXY
审中-公开
在EINER ABSCHLIESSENDEN TLS-PROXY-VERBINDUNG中使用贝塞斯蒂诺EINERVORWÄRTSSICHERHEIT
- 专利标题: PROVIDING FORWARD SECRECY IN A TERMINATING TLS CONNECTION PROXY
- 专利标题(中): 在EINER ABSCHLIESSENDEN TLS-PROXY-VERBINDUNG中使用贝塞斯蒂诺EINERVORWÄRTSSICHERHEIT
-
申请号: EP14871587申请日: 2014-12-18
-
公开(公告)号: EP3085008A4公开(公告)日: 2017-06-21
- 发明人: GERO CHARLES E , LISIECKI PHILIP A
- 申请人: AKAMAI TECH INC
- 专利权人: AKAMAI TECH INC
- 当前专利权人: AKAMAI TECH INC
- 优先权: US201361917677 2013-12-18; US201414573894 2014-12-17
- 主分类号: H04L9/20
- IPC分类号: H04L9/20 ; H04L9/06 ; H04L9/08 ; H04L9/30 ; H04L9/32 ; H04L29/06
摘要:
An infrastructure delivery platform provides a RSA proxy service as an enhancement to the TLS/SSL protocol to off-load, from an edge server to an external cryptographic server, the decryption of an encrypted pre-master secret. The technique provides forward secrecy in the event that the edge server is compromised, preferably through the use of a cryptographically strong hash function that is implemented separately at both the edge server and the cryptographic server. To provide the forward secrecy for this particular leg, the edge server selects an ephemeral value, and applies a cryptographic hash the value to compute a server random value, which is then transmitted back to the requesting client. That server random value is later re-generated at the cryptographic server to enable the cryptographic server to compute a master secret. The forward secrecy is enabled by ensuring that the ephemeral value does not travel on the wire.
信息查询