Akamai Technologies, Inc.
SYSTEMS AND METHODS FOR UTILIZING CLIENT SIDE AUTHENTICATION TO SELECT SERVICES AVAILABLE AT A GIVEN PORT NUMBER
Last updated:
Abstract:
Typically, clients request a service from a computer hosting multiple services by specifying a destination port number associated with the desired service. In embodiments, the functionality of such a host computer is enhanced by having it condition client access to services available at a particular port number based on client authentication and/or authorization. A host computer can change the service(s) available at a given port number on a client by client basis, enabling access to service(s) for trusted clients unavailable to untrusted clients. Preferably, client trust is based on client authentication via a certificate and a valid, signed transport layer security (TLS) handshake (or similar mechanism in other protocol contexts). In some embodiments, an authorization step can be added following authentication. The systems and methods disclosed herein find wide uses in bundling services on ports, as well as protecting access to services from untrusted and/or malicious clients, among others.
Utility
26 Feb 2020
20 Aug 2020