Invention Grant
US09306936B2 Techniques to classify virtual private network traffic based on identity 有权
基于身份对虚拟专用网络流量进行分类的技术

Techniques to classify virtual private network traffic based on identity
Abstract:
Techniques are provided for obtaining first and second digital certificates from a certificate authority database for establishing a secure exchange between network devices. The first digital certificate contains identity information of a first network device, and the second digital certificate contains classification information of the first network device. In one embodiment, a secure key exchange is initiated with the second network device, and the first and second digital certificates are transmitted as a part of the secure key exchange to the second network device. In another embodiment, the first and second digital certificates are received by an intermediate network device. The first digital certificate is encrypted and is not evaluated by the intermediate network device. The second digital certificate is evaluated for classification information of the first network device. Source information associated with the first network device is stored, and encrypted traffic is processed between the network devices.
Information query
Patent Agency Ranking
0/0