发明名称 Process and system providing internet protocol security without secure domain resolution
摘要 A system and method providing Internet protocol security without secure domain name resolution are disclosed. A processor that periodically needs to resolve domain names into network addresses has a local DNS server that includes a secure IPSEC cache, a resolver function, a security policy database, and an IPSEC layer. The cache is readable only by the IPSEC layer. Resolved domain names are cached with process and transaction identifiers that uniquely associate the resolved names with an application process and time. When resolution is needed, the cache is used to ensure that IP addresses are resolved from names that came from the application. As a result, IPSEC connections may be established without use of DNSSEC to provide secure domain name resolution.
申请公布号 US7296155(B1) 申请公布日期 2007.11.13
申请号 US20010023622 申请日期 2001.12.17
申请人 CISCO TECHNOLOGY, INC. 发明人 TROSTLE JONATHAN;GOSSMAN WILLIAM
分类号 H04L9/00 主分类号 H04L9/00
代理机构 代理人
主权项
地址