Invention Grant
US08261318B2 Method and apparatus for passing security configuration information between a client and a security policy server
有权
在客户端和安全策略服务器之间传递安全配置信息的方法和装置
- Patent Title: Method and apparatus for passing security configuration information between a client and a security policy server
- Patent Title (中): 在客户端和安全策略服务器之间传递安全配置信息的方法和装置
-
Application No.: US12888289Application Date: 2010-09-22
-
Publication No.: US08261318B2Publication Date: 2012-09-04
- Inventor: Geoffrey Huang , Jan Vilhuber
- Applicant: Geoffrey Huang , Jan Vilhuber
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Hickman Palermo Truong Becker Bingham Wong LLP
- Agent Adam C. Stone
- Main IPC: H04L9/00
- IPC: H04L9/00

Abstract:
Techniques for passing security configuration information between a security policy server and a client includes the client forming a request for security configuration information that configures the client for secure communications. The client is separated by an untrusted network from a trusted network that includes the security policy sever. A tag is generated that indicates a generic security configuration attribute. An Internet Security Association and Key Management Protocol (ISAKMP) configuration mode request message is sent to a security gateway on an edge of the trusted network connected to the untrusted network. The message includes the request in association with the tag. The gateway sends the request associated with the tag to the security policy server on the trusted network and does not interpret the request. The techniques allow client configuration extensions to be added by modifying the policy server or security client, or both, without modifying the gateway.
Public/Granted literature
Information query