EP1533982A2

System and method for pre-fetching secure content in a proxy architecture via transparent secure connections

Abstract

Requests for secure content are rewritten before delivering the secure content to a client [201]. In one implementation, the rewritten requests include the information content from the original request with the addition of a predetermined domain. The domain may correspond to a trusted agent [205, 207] that acts as a proxy for all secure requests from the client [201]. Because of the rewritten request, the trusted agent is contacted by the client for the secure content. The trusted agent [205, 207] may then transparently (from the point of view of the client) retrieve and forward the secure content to the client.

EP1533982A2, drawing sheet 1
Sheet 1 of 12

Term

Term ended

Projected expiry passed 4 November 2024, 1.9 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

23 claims: 5 independent, 18 dependent

  1. 1
    A method for retrieving content for a client comprising:receiving a reference to secure content accessed via a first resource [210];editing the reference to the secure content to redirect requests for the secure content to a trusted agent [205, 207], the edited reference to the secure content including information that identifies the first resource and the secure content of the received reference;forwarding the edited reference to the client [201];and requesting the secure content from the first resource, by the trusted agent [205, 207] on behalf of the client [201], when the client requests the edited reference.
  2. 6
    A network proxy apparatus for providing a proxy service to retrieve content over a data network from a content server, the apparatus comprising:an interface for receiving requests from a user [201] for a secure connection with the content server [210] and, in response to the received request, establishing a first connection [SSL1] between the interface and the user and establishing a second connection [SSL3] between the interface and the content server, the second connection being a secure connection;and a cache [215] for storing content pre-fetched from the content server over the second connection.
  3. 11
    A system comprising:a first proxy [205] configured to receive a request from a user for a secure connection with a content server [210];a second proxy [207] configured to accept a first secure connection with the first proxy and to establish a second secure connection with the content server [210];and a wide area network [211] configured to connect the first proxy and the second proxy.
  4. 18
    A method comprising:receiving a domain name system (DNS) lookup request from a user;determining whether the DNS lookup request refers to a first predetermined domain;returning an Internet Protocol address of a proxy to the requesting user when the DNS lookup request refers to the first predetermined domain;and forwarding the DNS lookup request to a DNS server when the DNS lookup request does not refer to the first predetermined domain.
  5. 21
    A method comprising:intercepting a HyperText Markup Language (HTML) document from a content server in response to a request from a user;editing the HTML document to insert a predetermined domain within secure HyperText Transfer Protocol (HTTPS) links before an original domain name included in the HTTPS links;and forwarding the edited HTML document to the user.