CN104094554B - 无服务器名称指示(sni)的隐式ssl证书管理 - Google Patents
无服务器名称指示(sni)的隐式ssl证书管理 Download PDFInfo
- Publication number
- CN104094554B CN104094554B CN201380006965.5A CN201380006965A CN104094554B CN 104094554 B CN104094554 B CN 104094554B CN 201380006965 A CN201380006965 A CN 201380006965A CN 104094554 B CN104094554 B CN 104094554B
- Authority
- CN
- China
- Prior art keywords
- ssl
- ssl certificate
- name
- certificate
- host name
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0823—Network architectures or network communication protocols for network security for authentication of entities using certificates
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L61/00—Network arrangements, protocols or services for addressing or naming
- H04L61/45—Network directories; Name-to-address mapping
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/16—Implementing security features at a particular protocol layer
- H04L63/166—Implementing security features at a particular protocol layer at the transport layer
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2101/00—Indexing scheme associated with group H04L61/00
- H04L2101/60—Types of network addresses
- H04L2101/618—Details of network addresses
- H04L2101/663—Transport layer addresses, e.g. aspects of transmission control protocol [TCP] or user datagram protocol [UDP] ports
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/02—Protocols based on web technology, e.g. hypertext transfer protocol [HTTP]
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Computer And Data Communications (AREA)
- Information Transfer Between Computers (AREA)
- Telephonic Communication Services (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Applications Claiming Priority (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US13/359,507 US8738902B2 (en) | 2012-01-27 | 2012-01-27 | Implicit SSL certificate management without server name indication (SNI) |
| US13/359,507 | 2012-01-27 | ||
| PCT/US2013/022352 WO2013112389A1 (en) | 2012-01-27 | 2013-01-21 | Implicit ssl certificate management without server name indication (sni) |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| CN104094554A CN104094554A (zh) | 2014-10-08 |
| CN104094554B true CN104094554B (zh) | 2017-05-03 |
Family
ID=48871366
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| CN201380006965.5A Active CN104094554B (zh) | 2012-01-27 | 2013-01-21 | 无服务器名称指示(sni)的隐式ssl证书管理 |
Country Status (6)
| Country | Link |
|---|---|
| US (1) | US8738902B2 (enExample) |
| EP (1) | EP2807789B1 (enExample) |
| JP (1) | JP6058699B2 (enExample) |
| KR (1) | KR102025960B1 (enExample) |
| CN (1) | CN104094554B (enExample) |
| WO (1) | WO2013112389A1 (enExample) |
Families Citing this family (56)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US9015469B2 (en) | 2011-07-28 | 2015-04-21 | Cloudflare, Inc. | Supporting secure sessions in a cloud-based proxy service |
| WO2013123280A1 (en) * | 2012-02-16 | 2013-08-22 | F5 Network, Inc. | Methods for secure cummunication between network device services and devices thereof |
| US9237168B2 (en) * | 2012-05-17 | 2016-01-12 | Cisco Technology, Inc. | Transport layer security traffic control using service name identification |
| US8782774B1 (en) | 2013-03-07 | 2014-07-15 | Cloudflare, Inc. | Secure session capability using public-key cryptography without access to the private key |
| EP4224342A1 (en) * | 2013-03-15 | 2023-08-09 | Netop Solutions A/S | System and method for secure application communication between networked processors |
| US10524122B2 (en) | 2014-01-31 | 2019-12-31 | Microsoft Technology Licensing, Llc | Tenant based signature validation |
| US9565198B2 (en) * | 2014-01-31 | 2017-02-07 | Microsoft Technology Licensing, Llc | Tenant based signature validation |
| US10389709B2 (en) | 2014-02-24 | 2019-08-20 | Amazon Technologies, Inc. | Securing client-specified credentials at cryptographically attested resources |
| US9332003B2 (en) * | 2014-03-20 | 2016-05-03 | Symantec Corporation | Systems and methods for discovering website certificate information |
| US10178181B2 (en) * | 2014-04-02 | 2019-01-08 | Cisco Technology, Inc. | Interposer with security assistant key escrow |
| US8966267B1 (en) | 2014-04-08 | 2015-02-24 | Cloudflare, Inc. | Secure session capability using public-key cryptography without access to the private key |
| US8996873B1 (en) | 2014-04-08 | 2015-03-31 | Cloudflare, Inc. | Secure session capability using public-key cryptography without access to the private key |
| US9184911B2 (en) * | 2014-04-08 | 2015-11-10 | Cloudflare, Inc. | Secure session capability using public-key cryptography without access to the private key |
| CN103973694B (zh) * | 2014-05-14 | 2017-05-10 | 北京太一星晨信息技术有限公司 | 安全套接层协议实体访问非连续内存的方法及接口装置 |
| US10171532B2 (en) * | 2014-09-30 | 2019-01-01 | Citrix Systems, Inc. | Methods and systems for detection and classification of multimedia content in secured transactions |
| US10303879B1 (en) | 2014-11-06 | 2019-05-28 | Amazon Technologies, Inc. | Multi-tenant trusted platform modules |
| US9525672B2 (en) * | 2014-12-19 | 2016-12-20 | Amazon Technologies, Inc. | Multi-faceted compute instance identity |
| CN105991589B (zh) * | 2015-02-13 | 2019-04-26 | 华为技术有限公司 | 一种用于重定向的方法、装置及系统 |
| US9756106B2 (en) | 2015-02-13 | 2017-09-05 | Citrix Systems, Inc. | Methods and systems for estimating quality of experience (QoE) parameters of secured transactions |
| US10021221B2 (en) | 2015-02-24 | 2018-07-10 | Citrix Systems, Inc. | Methods and systems for detection and classification of multimedia content in secured transactions using pattern matching |
| US20160255047A1 (en) * | 2015-02-26 | 2016-09-01 | Citrix Systems, Inc. | Methods and systems for determining domain names and organization names associated with participants involved in secured sessions |
| JP6471537B2 (ja) * | 2015-02-27 | 2019-02-20 | ブラザー工業株式会社 | 通信機器 |
| US10193698B1 (en) | 2015-06-26 | 2019-01-29 | Juniper Networks, Inc. | Avoiding interdicted certificate cache poisoning for secure sockets layer forward proxy |
| US10291651B1 (en) | 2015-06-26 | 2019-05-14 | Juniper Networks, Inc. | Unified secure socket layer decryption |
| US9893883B1 (en) * | 2015-06-26 | 2018-02-13 | Juniper Networks, Inc. | Decryption of secure sockets layer sessions having enabled perfect forward secrecy using a diffie-hellman key exchange |
| US10305871B2 (en) | 2015-12-09 | 2019-05-28 | Cloudflare, Inc. | Dynamically serving digital certificates based on secure session properties |
| US10505985B1 (en) * | 2016-04-13 | 2019-12-10 | Palo Alto Networks, Inc. | Hostname validation and policy evasion prevention |
| GB2551580A (en) * | 2016-06-24 | 2017-12-27 | Sony Corp | Data communications |
| US10326730B2 (en) | 2016-06-27 | 2019-06-18 | Cisco Technology, Inc. | Verification of server name in a proxy device for connection requests made using domain names |
| JP6668183B2 (ja) * | 2016-07-01 | 2020-03-18 | 株式会社東芝 | 通信装置、通信方法、通信システムおよびプログラム |
| US10320572B2 (en) * | 2016-08-04 | 2019-06-11 | Microsoft Technology Licensing, Llc | Scope-based certificate deployment |
| JP6589223B2 (ja) * | 2016-08-31 | 2019-10-16 | 日本電信電話株式会社 | サービス推定装置、サービス推定方法、及びプログラム |
| US11063758B1 (en) | 2016-11-01 | 2021-07-13 | F5 Networks, Inc. | Methods for facilitating cipher selection and devices thereof |
| CN110036605A (zh) | 2016-11-30 | 2019-07-19 | 日本电气株式会社 | 通信设备、通信方法和程序 |
| US10545940B2 (en) * | 2017-02-22 | 2020-01-28 | Red Hat, Inc. | Supporting secure layer extensions for communication protocols |
| CN107147497B (zh) * | 2017-05-02 | 2018-07-06 | 北京海泰方圆科技股份有限公司 | 信息处理方法和装置 |
| CN107493174B (zh) * | 2017-09-05 | 2020-12-15 | 成都知道创宇信息技术有限公司 | 基于cdn网络的ssl证书智能绑定与管理方法 |
| US11888840B2 (en) * | 2017-11-09 | 2024-01-30 | Mitsubishi Electric Corporation | Apparatus and method for selection and transmission of server certificate |
| US10728238B2 (en) | 2017-12-13 | 2020-07-28 | Paypal, Inc. | Systems and methods encrypting messages using multiple certificates |
| CN108156224B (zh) * | 2017-12-14 | 2020-11-13 | 格尔软件股份有限公司 | 基于tls协议sni机制实现自定义代理隧道协议的方法 |
| US10810279B2 (en) * | 2018-02-07 | 2020-10-20 | Akamai Technologies, Inc. | Content delivery network (CDN) providing accelerated delivery of embedded resources from CDN and third party domains |
| CN110825400B (zh) * | 2018-08-14 | 2024-04-23 | 杭州萤石软件有限公司 | 一种应用程序客户端的证书更新方法和系统 |
| CN109413196A (zh) * | 2018-11-13 | 2019-03-01 | 四川长虹电器股份有限公司 | 一种智能匹配https访问证书的方法 |
| CN110213249A (zh) * | 2019-05-20 | 2019-09-06 | 网宿科技股份有限公司 | 基于请求粒度的证书动态加载方法、装置和服务器 |
| CN111147251A (zh) * | 2019-12-18 | 2020-05-12 | 深圳市任子行科技开发有限公司 | 动态签发证书的方法及装置 |
| US10903990B1 (en) | 2020-03-11 | 2021-01-26 | Cloudflare, Inc. | Establishing a cryptographic tunnel between a first tunnel endpoint and a second tunnel endpoint where a private key used during the tunnel establishment is remotely located from the second tunnel endpoint |
| US11336692B1 (en) * | 2020-05-07 | 2022-05-17 | NortonLifeLock Inc. | Employing SNI hostname extraction to populate a reverse DNS listing to protect against potentially malicious domains |
| US11683301B2 (en) | 2020-07-27 | 2023-06-20 | Red Hat, Inc. | Automatically obtaining a signed digital certificate from a trusted certificate authority |
| WO2022118082A1 (en) * | 2020-12-03 | 2022-06-09 | Bharanishunkkar Shanmugavel | System and method for securing and resolving internet protocol address |
| EP4009602B1 (en) * | 2020-12-07 | 2022-11-09 | Siemens Healthcare GmbH | Providing a first digital certificate and a dns response |
| CN112714184B (zh) * | 2020-12-29 | 2022-07-15 | 杭州迪普科技股份有限公司 | 握手过程处理方法及装置 |
| CN113364795B (zh) * | 2021-06-18 | 2023-03-24 | 北京天空卫士网络安全技术有限公司 | 一种数据传输方法和代理服务器 |
| CN113746856B (zh) * | 2021-09-09 | 2023-04-07 | 上海格尔安全科技有限公司 | Ssl可选验证方法、装置、计算机设备和存储介质 |
| US20230328103A1 (en) * | 2022-04-07 | 2023-10-12 | Citrix Systems, Inc. | Systems and methods for updating microservices secure sockets layer certificate |
| US12413423B2 (en) * | 2023-09-22 | 2025-09-09 | International Business Machines Corporation | Localhost digital certificate discovery and reconciliation |
| CN119519986B (zh) * | 2024-11-20 | 2025-10-14 | 天翼云科技有限公司 | 数字证书处理方法、装置、计算机设备和可读存储介质 |
Citations (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN1756193A (zh) * | 2004-09-30 | 2006-04-05 | 国际商业机器公司 | 更新ssl证书的计算机系统和方法 |
Family Cites Families (16)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US7000108B1 (en) | 2000-05-02 | 2006-02-14 | International Business Machines Corporation | System, apparatus and method for presentation and manipulation of personal information syntax objects |
| US7209479B2 (en) | 2001-01-18 | 2007-04-24 | Science Application International Corp. | Third party VPN certification |
| JP3724564B2 (ja) * | 2001-05-30 | 2005-12-07 | 日本電気株式会社 | 認証システム及び認証方法並びに認証用プログラム |
| US7363353B2 (en) * | 2001-07-06 | 2008-04-22 | Juniper Networks, Inc. | Content service aggregation device for a data center |
| US7305492B2 (en) * | 2001-07-06 | 2007-12-04 | Juniper Networks, Inc. | Content service aggregation system |
| JP2003271553A (ja) * | 2002-03-18 | 2003-09-26 | Matsushita Electric Ind Co Ltd | ウェブサーバ端末とそのネットワークシステム、及びそのアクセス制御方法 |
| US7739494B1 (en) | 2003-04-25 | 2010-06-15 | Symantec Corporation | SSL validation and stripping using trustworthiness factors |
| US7017181B2 (en) | 2003-06-25 | 2006-03-21 | Voltage Security, Inc. | Identity-based-encryption messaging system with public parameter host servers |
| WO2005033868A2 (en) | 2003-09-29 | 2005-04-14 | Ayman, Llc | Delegated certificate authority |
| US7694135B2 (en) * | 2004-07-16 | 2010-04-06 | Geotrust, Inc. | Security systems and services to provide identity and uniform resource identifier verification |
| US8549157B2 (en) | 2007-04-23 | 2013-10-01 | Mcafee, Inc. | Transparent secure socket layer |
| JP2009217676A (ja) * | 2008-03-12 | 2009-09-24 | Oki Electric Ind Co Ltd | 保険金等申請受付装置、保険金等申請受付方法、およびプログラム |
| JP4252620B1 (ja) | 2008-08-27 | 2009-04-08 | グローバルサイン株式会社 | サーバ証明書発行システム |
| US8533333B2 (en) | 2008-09-03 | 2013-09-10 | Microsoft Corporation | Shared hosting using host name affinity |
| US8971539B2 (en) * | 2010-12-30 | 2015-03-03 | Verisign, Inc. | Management of SSL certificate escrow |
| US9015469B2 (en) * | 2011-07-28 | 2015-04-21 | Cloudflare, Inc. | Supporting secure sessions in a cloud-based proxy service |
-
2012
- 2012-01-27 US US13/359,507 patent/US8738902B2/en active Active
-
2013
- 2013-01-21 CN CN201380006965.5A patent/CN104094554B/zh active Active
- 2013-01-21 WO PCT/US2013/022352 patent/WO2013112389A1/en not_active Ceased
- 2013-01-21 JP JP2014554755A patent/JP6058699B2/ja not_active Expired - Fee Related
- 2013-01-21 KR KR1020147020979A patent/KR102025960B1/ko not_active Expired - Fee Related
- 2013-01-21 EP EP13740916.5A patent/EP2807789B1/en active Active
Patent Citations (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN1756193A (zh) * | 2004-09-30 | 2006-04-05 | 国际商业机器公司 | 更新ssl证书的计算机系统和方法 |
Also Published As
| Publication number | Publication date |
|---|---|
| EP2807789B1 (en) | 2019-02-27 |
| CN104094554A (zh) | 2014-10-08 |
| WO2013112389A1 (en) | 2013-08-01 |
| KR102025960B1 (ko) | 2019-09-26 |
| EP2807789A1 (en) | 2014-12-03 |
| JP6058699B2 (ja) | 2017-01-11 |
| US8738902B2 (en) | 2014-05-27 |
| EP2807789A4 (en) | 2015-12-30 |
| KR20140117449A (ko) | 2014-10-07 |
| US20130198511A1 (en) | 2013-08-01 |
| JP2015513810A (ja) | 2015-05-14 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN104094554B (zh) | 无服务器名称指示(sni)的隐式ssl证书管理 | |
| US11750709B2 (en) | Secure in-band service detection | |
| CN103563295B (zh) | 分布关于一个或多个电气装置的信息的方法及其系统 | |
| CN102427484B (zh) | 基于dns来确定设备是否处于网络内部的方法和装置 | |
| US8572691B2 (en) | Selecting a web service from a service registry based on audit and compliance qualities | |
| JP2012235464A (ja) | Dnssec署名サーバ | |
| CN103561121B (zh) | 一种dns的解析方法、装置和浏览器 | |
| US9614833B1 (en) | Automated certificate management for a website associated with multiple certificates | |
| US20180167353A1 (en) | Computer-implemented method, apparatus, and computer-readable medium for processing named entity queries using a cached functionality in a domain name system | |
| KR20140138182A (ko) | 클라우드에서 투명하게 호스팅되는 조직들에 대한 아이덴티티 서비스 | |
| JP2006178929A (ja) | ドメイン名購入のメッセージ・ベースのネットワーク構成 | |
| WO2013143403A1 (zh) | 一种访问网站的方法和系统 | |
| CN109729187B (zh) | 一种代理通信方法、系统、装置及存储介质 | |
| US20070294237A1 (en) | Enterprise-Wide Configuration Management Database Searches | |
| US11438393B1 (en) | Origin server address rotation | |
| US20110004926A1 (en) | Automatically Handling Proxy Server and Web Server Authentication | |
| CN101969426B (zh) | 分布式用户认证系统及其方法 | |
| WO2016155266A1 (zh) | 虚拟桌面的数据共享方法和装置 | |
| WO2024183348A1 (zh) | 基于域名系统dns的区块链服务发现方法及装置 | |
| WO2015117380A1 (zh) | 一种远程桌面协议网关进行路由交换的方法、设备及系统 | |
| JP2003316743A (ja) | ネットワークアクセス方法およびクライアント | |
| GB2450897B (en) | Identifying network hosts running on a computer network | |
| US20100241740A1 (en) | System and method for resolving network addresses | |
| Kónya et al. | The NorduGrid/ARC Information System | |
| CN116032542A (zh) | 查询方法、装置、网络设备及可读存储介质 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| C06 | Publication | ||
| PB01 | Publication | ||
| C10 | Entry into substantive examination | ||
| SE01 | Entry into force of request for substantive examination | ||
| ASS | Succession or assignment of patent right |
Owner name: MICROSOFT TECHNOLOGY LICENSING LLC Free format text: FORMER OWNER: MICROSOFT CORP. Effective date: 20150728 |
|
| C41 | Transfer of patent application or patent right or utility model | ||
| TA01 | Transfer of patent application right |
Effective date of registration: 20150728 Address after: Washington State Applicant after: Micro soft technique license Co., Ltd Address before: Washington State Applicant before: Microsoft Corp. |
|
| GR01 | Patent grant | ||
| GR01 | Patent grant |