Unlock instant, AI-driven research and patent intelligence for your innovation.

SSL VPN authentication method, client and gateway, and server

An authentication method and client technology, applied in the network field, can solve problems such as potential safety hazards

Active Publication Date: 2019-03-19
NEW H3C TECH CO LTD
View PDF8 Cites 9 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0004] However, when SSL VPN clients and SSL VPN gateways send usernames and passwords, they send them to the AAA server based on attribute information such as the address and name of the AAA server, and these attribute information are easily used by counterfeit phishing websites to send illegal usernames and passwords to the AAA server. The password has been verified, and there is a big security risk

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • SSL VPN authentication method, client and gateway, and server
  • SSL VPN authentication method, client and gateway, and server
  • SSL VPN authentication method, client and gateway, and server

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0067] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only some, not all, embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by persons of ordinary skill in the art without making creative efforts belong to the protection scope of the present invention.

[0068] In order to improve the security of SSL VPN authentication, an embodiment of the present invention provides an SSL VPN authentication method and device, an SSL VPN client, an AAA server, an SSL VPN gateway, and a machine-readable storage medium. Firstly, the SSL VPN authentication method provided by the embodiment of the present invention will be introduced below.

[0069] The SSL VPN authentication method provided by the embodiment of the present inven...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The embodiments of the invention provide an SSL VPN authentication method, client, and gateway, and a server. The method comprises the following steps that: an SSL VPN client sends a first login request message to an SSL VPN gateway after the SSL VPN client establishes a connection with the SSL VPN gateway; the SSL VPN gateway sends a first authentication request message to an AAA server after receiving the first login request message; the AAA server performs a certificate authentication interaction process with the SSL VPN client when identifying that the first authentication request messagecarries a certificate authentication identifier; and it can be determined that the SSL VPN authentication is successful if the SSL VPN client verifies that the server certificate of the AAA server isvalid and the AAA server verifies that the client certificate of the SSL VPN client is valid. The SSL VPN client and the AAA server are guaranteed to be equipment which can be identified as effectivethrough the bidirectional certificate verification between the SSL VPN client and the AAA server, and the SSL VPN client and the AAA server are prevented from being spoofed, thereby improving the security of SSL VPN authentication.

Description

technical field [0001] The invention relates to the field of network technology, in particular to an SSL VPN authentication method, a client, a server and a gateway. Background technique [0002] SSL VPN is a new VPN (Virtual Private Network, virtual private network) technology based on the SSL (Secure Socket Layer) / TLS (TransportLayer Security, Transport Layer Security) protocol. SSL VPN authentication provides a safe and reliable way for access users to access internal resources. [0003] Currently, during the SSL VPN authentication process, the SSL VPN client sends the user name and password to the SSL VPN gateway, and the SSL VPN gateway forwards the user name and password to the AAA (Authentication Authorization Accounting, authentication, authorization, accounting) server for verification. If the AAA server authentication passes, it is determined that the SSL VPN authentication is successful. [0004] However, when SSL VPN clients and SSL VPN gateways send usernames ...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Applications(China)
IPC IPC(8): H04L29/06
CPCH04L63/0272H04L63/0815H04L63/0823H04L63/0892H04L69/162
Inventor 王钰洁
Owner NEW H3C TECH CO LTD