发明申请
US20110113481A1 IP SECURITY CERTIFICATE EXCHANGE BASED ON CERTIFICATE ATTRIBUTES
有权
基于证书属性的知识产权安全证书交换
- 专利标题: IP SECURITY CERTIFICATE EXCHANGE BASED ON CERTIFICATE ATTRIBUTES
- 专利标题(中): 基于证书属性的知识产权安全证书交换
-
申请号: US12616789申请日: 2009-11-12
-
公开(公告)号: US20110113481A1公开(公告)日: 2011-05-12
- 发明人: Anatoliy Panasyuk , Dharshan Rangegowda , Abhishek Shukla
- 申请人: Anatoliy Panasyuk , Dharshan Rangegowda , Abhishek Shukla
- 申请人地址: US WA Redmond
- 专利权人: Microsoft Corporation
- 当前专利权人: Microsoft Corporation
- 当前专利权人地址: US WA Redmond
- 主分类号: G06F21/20
- IPC分类号: G06F21/20
摘要:
Architecture that provides Internet Protocol security (IPsec) certificate exchange based on certificate attributes. An IPsec endpoint can validate the security context of another IPsec endpoint certificate by referencing certificate attributes. By facilitating IPsec certificate exchange using certificate attributes rather than solely certificate roots, it is now possible to build multiple isolated network zones using a single certificate authority rather than requiring one certificate authority per zone. Moreover, the ability to use certificate attributes during the IPsec certificate exchange can be leveraged for more focused communications such as QoS (quality of service). Certificate attributes can be utilized to identify the security context of the endpoint. The IPsec certificate use can be locked down to a single IP or group of IPs.
公开/授权文献
信息查询