Invention Grant
- Patent Title: Network security system to validate a server certificate
-
Application No.: US15157588Application Date: 2016-05-18
-
Publication No.: US10009336B2Publication Date: 2018-06-26
- Inventor: K. Tirumaleswar Reddy , Prashanth Patil , Daniel G. Wing
- Applicant: Cisco Technology, Inc.
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Parker Ibrahim & Berg LLP
- Agent James M. Behmke; Stephen D. LeBarron
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L29/12 ; H04L29/08 ; H04L9/30 ; H04L9/32

Abstract:
In one embodiment, a Domain Name Service (DNS) server pre-fetches domain information regarding a domain that includes certificate information for the domain. The DNS server receives a DNS request that includes a security request for the domain in metadata of a Network Service Header (NSH) of the DNS request. The DNS server retrieves the certificate information for the domain from the pre-fetched information regarding the domain, in response to receiving the security request. The DNS server sends, to a Transport Layer Security (TLS) proxy, a DNS response for the domain that includes the certificate information in metadata of an NSH of the DNS response.
Public/Granted literature
- US20170339130A1 NETWORK SECURITY SYSTEM TO VALIDATE A SERVER CERTIFICATE Public/Granted day:2017-11-23
Information query