US20090178061A1

Methods and systems for filtering encrypted traffic

Claim Score by NHIP

Read claim 15, the broadest

Abstract

Application programming interface (API) hooks are injected into an application program executing at a client during run-time. Responsive to these hooks, data intended for encryption prior to transmission from the client is diverted, for example for content filtering, compression, etc., prior to being encrypted. In the case of encrypted data received at the client, the data is decrypted but before being passed to the application it is diverted, under control of the API hooks, for content filtering, decompression, etc.

US20090178061A1, drawing sheet 1
Sheet 1 of 3

Term

8.1 yearsto projected expiry

Projected expiry 19 October 2034, counted from filing; an application has no term until it is granted.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

31 claims: 7 independent, 24 dependent

  1. 1
    A method, comprising injecting, at run-time, one or more hooks on application programming interface (API) calls within an application executing on a client;catching, using the hooks, calls from the application concerning encryption of data to be transferred to a remote computer system;and diverting the data from said encryption/decryption for manipulation prior to said encryption.
  2. 10
    A computer system having stored thereon computer-readable instructions which, when executed by a processor of said computer system, cause said processor to inject, at run-time, one or more hooks on application programming interface (API) calls within an application executing on said computer system, catch, using the hooks, calls from the application concerning encryption of data to be transferred to a remote computer system, and divert the data from said encryption for manipulation prior to said encryption.
  3. 15
    Broadest claimClaim Score 91, very broad(NHIP)A method, comprising directing, under the control of application programming interface (API) hooks injected into an application program executing at a client, data for content filtering at the client, and subsequently, encrypting the data.
  4. 17
    A method, comprising directing, under the control of application programming interface (API) hooks injected into an application program executing at a client, data received and decrypted at the client for content filtering at the client, and subsequently, passing the data to the application program.
  5. 18
    A method, comprising injecting, at run-time, one or more hooks on application programming interface (API) calls within an application executing on a client;catching, using the hooks, calls from the application concerning decrypted data received at the client to be transferred to the application;and diverting the data for manipulation prior to transferring the data to the application.
  6. 26
    A method, comprising establishing, in a network in which a proxy is logically disposed between a client and a server, a connection between the client and the server;and providing a server certificate to the client over the connection;wherein communications over said connection comprise direct exchanges between the client and the server as determined by one or more hooks on application programming interface (API) calls within an application executing on the client.
  7. 28
    A method, comprising following completion of a certificate exchange between a server and a client, establishing a first connection between the client and the server;thereafter, establishing a second connection between the client and a proxy, and establishing a third connection between the proxy and the server;whereby the proxy is logically disposed between the client and the server for one or more exchanges between the client and the server, but the first connection between the client and the server is used for other exchanges therebetween, in each instance said exchanges determined by one or more hooks on application programming interface (API) calls within an application executing on a client.