发明名称 Centralized deployment of IPSec policy information
摘要 A method of network security policy administration for a network client uses a finite state machine to maintain the security policy information of the network client. Security policy information may originate in a remote source such a directory storage as well as, or alternatively, locally in cache and local store locations. The finite state machine has four states, Initial, DS, Cache, and Local, and transitions between states responsive to the availability of security policy information from the various policy information sources. Furthermore, security policy updates occur via a differencing mechanism, wherein only filters that have changed are updated, minimizing impact on unchanged policy filters and the traffic protected by them, and minimizing lulls in policy coverage.
申请公布号 US6697857(B1) 申请公布日期 2004.02.24
申请号 US20000591567 申请日期 2000.06.09
申请人 MICROSOFT CORPORATION 发明人 DIXON WILLIAM H.;GANUGAPATI KRISHNA;ABHISHEK ABHISHEK
分类号 H04L29/06;(IPC1-7):G06F15/173 主分类号 H04L29/06
代理机构 代理人
主权项
地址