Invention Grant
US09306936B2 Techniques to classify virtual private network traffic based on identity
有权
基于身份对虚拟专用网络流量进行分类的技术
- Patent Title: Techniques to classify virtual private network traffic based on identity
- Patent Title (中): 基于身份对虚拟专用网络流量进行分类的技术
-
Application No.: US14532131Application Date: 2014-11-04
-
Publication No.: US09306936B2Publication Date: 2016-04-05
- Inventor: Kunal Patel , Yixin Sun , Puneet Gupta , Vinod Arjun , David McGrew
- Applicant: Cisco Technology, Inc.
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Edell, Shapiro & Finnan, LLC
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L9/32

Abstract:
Techniques are provided for obtaining first and second digital certificates from a certificate authority database for establishing a secure exchange between network devices. The first digital certificate contains identity information of a first network device, and the second digital certificate contains classification information of the first network device. In one embodiment, a secure key exchange is initiated with the second network device, and the first and second digital certificates are transmitted as a part of the secure key exchange to the second network device. In another embodiment, the first and second digital certificates are received by an intermediate network device. The first digital certificate is encrypted and is not evaluated by the intermediate network device. The second digital certificate is evaluated for classification information of the first network device. Source information associated with the first network device is stored, and encrypted traffic is processed between the network devices.
Public/Granted literature
- US20150067337A1 Techniques to Classify Virtual Private Network Traffic Based on Identity Public/Granted day:2015-03-05
Information query