发明名称 Communication security system
摘要 An approach for secure application-to-application communication over the Internet uses a combination of application message interception, centralized policy management, and generic secure data connectivity layer for applications. Intercepting messages at an application layer enables use of application-specific security policies prior to the messages for different applications merging at lower levels of a communication protocol stack, and enables securing of the application messages as early as possible in the path to a peer application. The centralized policy management enables enforcement of security policies on multiple computers, both within and outside and enterprise network and protects against circumvention of security features specified by the policies. Data is transported between applications executing on different computers using a generic connectivity layer, which enables communication through firewalls that limit to particular ports and protocols, for example, allowing only HTTP-based communication on standard IP ports. Optionally, the approach complements VPN solutions by passing application-specific control information to VPN endpoints to enable those endpoints to perform application-specific processing while maintaining confidentiality of the application messages themselves.
申请公布号 US2003131245(A1) 申请公布日期 2003.07.10
申请号 US20030337180 申请日期 2003.01.06
申请人 LINDERMAN MICHAEL 发明人 LINDERMAN MICHAEL
分类号 H04L29/06;(IPC1-7):H04L9/00 主分类号 H04L29/06
代理机构 代理人
主权项
地址