- Patent Title: IP security certificate exchange based on certificate attributes
-
Application No.: US12616789Application Date: 2009-11-12
-
Publication No.: US09912654B2Publication Date: 2018-03-06
- Inventor: Anatoliy Panasyuk , Dharshan Rangegowda , Abhishek Shukla
- Applicant: Anatoliy Panasyuk , Dharshan Rangegowda , Abhishek Shukla
- Applicant Address: US WA Redmond
- Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
- Current Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
- Current Assignee Address: US WA Redmond
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L9/32

Abstract:
Architecture that provides Internet Protocol security (IPsec) certificate exchange based on certificate attributes. An IPsec endpoint can validate the security context of another IPsec endpoint certificate by referencing certificate attributes. By facilitating IPsec certificate exchange using certificate attributes rather than solely certificate roots, it is now possible to build multiple isolated network zones using a single certificate authority rather than requiring one certificate authority per zone. Moreover, the ability to use certificate attributes during the IPsec certificate exchange can be leveraged for more focused communications such as QoS (quality of service). Certificate attributes can be utilized to identify the security context of the endpoint. The IPsec certificate use can be locked down to a single IP or group of IPs.
Public/Granted literature
- US20110113481A1 IP SECURITY CERTIFICATE EXCHANGE BASED ON CERTIFICATE ATTRIBUTES Public/Granted day:2011-05-12
Information query