US20090220080A1

Application-Level Service Access to Encrypted Data Streams

Claim Score by NHIP

Read claim 29, the broadest

Abstract

Techniques for securely providing cryptographic keys to trusted intermediate nodes or monitoring devices are described so that SSL, TLS, or IPSec communications can be monitored, compressed over a WAN, or otherwise used. In an embodiment, a trusted intermediate node establishes a secure connection to a key server; receiving session identification data for an encrypted session between a client and a content server during negotiation of the encrypted session, and storing a copy of the session identification data; requesting from the key server, over the secure connection, a decryption key associated with the encrypted session; receiving an encrypted message communicated between the client and the content server; forwarding the encrypted message without modification to a destination address in the encrypted message; and decrypting the encrypted message using the decryption key to result in decrypted data and using or storing the decrypted data in a storage unit.

US20090220080A1, drawing sheet 1
Sheet 1 of 9

Term

5.7 yearsto projected expiry

Projected expiry 19 May 2032, counted from filing; an application has no term until it is granted.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

29 claims: 6 independent, 23 dependent

  1. 1
    An apparatus, comprising:a first network interface that is configured to be coupled to a client computer through a first network;one or more second network interfaces that are configured to be coupled to a content server and to a key server through one or more second networks;wherein the first network interface and second network interface are configured to receive and forward all data communicated between the client and the server;a processor;logic encoded in one or more computer-readable media for operation and configurable when executed operable to cause the processor to perform: establishing a secure connection to the key server;receiving session identification data for an encrypted session between the client and the content server during negotiation of the encrypted session between the client and the content server using an encryption protocol, and storing a copy of the session identification data;receiving a message from the content server indicating that the negotiation is finished;requesting from the key server, over the secure connection, a decryption key associated with the encrypted session;receiving an encrypted message communicated between the client and the content server in the encrypted session;decrypting the encrypted message using the decryption key to result in decrypted data and using or storing the decrypted data in a storage unit.
  2. 11
    A data processing system, comprising:a content server comprising a key server, wherein one or both of the content server and the key server are configured with logic which when executed implements an encrypted data communication protocol;a first trusted intermediate node configured at an edge location of a wide area network and comprising: a first network interface that is configured to be coupled to a client computer;one or more second network interfaces that are configured to be coupled to the wide area network and to the key server;a second trusted intermediate node configured at an core location of the wide area network and comprising: a third network interface that is configured to be coupled to the content server;a fourth network interface that is configured to be coupled to the first trusted intermediate node through the wide area network;wherein the network interfaces are configured to receive and forward all data communicated between the client and the server;logic in each of the first trusted intermediate node and the second trusted intermediate node encoded in one or more computer-readable media for operation and configurable when executed operable to cause a processor in the node to perform: establishing a secure connection to the key server;receiving session identification data for an encrypted session between the client and the content server during negotiation of the encrypted session between the client and the content server using an encryption protocol, and storing a copy of the session identification data;communicating a plurality of handshake messages relating to the negotiation between the first trusted intermediate node and the second trusted intermediate node using data compression, decompressing the plurality of handshake messages at the first trusted intermediate node and the second trusted intermediate node, and forwarding the decompressed handshake messages without modification to the client or the content server according to a destination address in the handshake messages;receiving a message from the content server indicating that the negotiation is finished;requesting from the key server, over the secure connection, a decryption key associated with the encrypted session;receiving an encrypted message communicated between the client and the content server in the encrypted session;forwarding the encrypted message without modification to the client or the content server according to a destination address in the encrypted message;decrypting the encrypted message using the decryption key to result in decrypted data and using or storing the decrypted data in a storage unit.
  3. 16
    A network monitoring apparatus, comprising:a first network interface that is configured to be coupled to a first endpoint computer through a first network;a second network interface that is configured to be coupled to a second endpoint computer through a second network;wherein the first network interface and second network interface are configured to receive and forward all data communicated between the first endpoint computer and the second endpoint computer;a processor;logic encoded in one or more computer-readable media for operation and configurable when executed operable to cause the processor to perform: sending a request message to one or more of the first endpoint computer and the second endpoint computer to provide an encryption key that the first endpoint computer and the second endpoint computer are using to encrypt data communicated in a cryptographic session between the first endpoint computer and the second endpoint computer;wherein the request message comprises a session descriptor that describes the cryptographic session;receiving, from one or more of the first endpoint computer and the second endpoint computer, a reply message comprising a keyshare or a key that can be used to decrypt the data communicated in the cryptographic session;wherein the reply session descriptor is encrypted;receiving an encrypted message communicated between the first endpoint computer and the second endpoint computer in the encrypted session;decrypting the encrypted message using the decryption key to result in decrypted data and using or storing the decrypted data in a storage unit.
  4. 21
    A computer-readable storage medium storing one or more sequences of instructions, which instructions, when executed by one or more processors, cause the one or more processors to carry out the steps of:establishing a secure connection to a key server;receiving session identification data for an encrypted session between a client and a content server during negotiation of the encrypted session between the client and the content server using an encryption protocol, and storing a copy of the session identification data;receiving a message from the content server indicating that the negotiation is finished;requesting from the key server, over the secure connection, a decryption key associated with the encrypted session;receiving an encrypted message communicated between the client and the content server in the encrypted session;forwarding the encrypted message without modification to the client or the content server according to a destination address in the encrypted message;decrypting the encrypted message using the decryption key to result in decrypted data and using or storing the decrypted data in a storage unit.
  5. 24
    A computer-readable storage medium storing one or more sequences of instructions, which instructions, when executed by one or more processors, cause the one or more processors to carry out the steps of:sending a request message to one or more of a first endpoint computer and a second endpoint computer to provide an encryption key that the first endpoint computer and the second endpoint computer are using to encrypt data communicated in a cryptographic session between the first endpoint computer and the second endpoint computer;wherein the request message comprises a session descriptor that describes the cryptographic session;receiving, from one or more of the first endpoint computer and the second endpoint computer, a reply message comprising a keyshare or a key that can be used to decrypt the data communicated in the cryptographic session;wherein the reply session descriptor is encrypted;receiving an encrypted message communicated between the first endpoint computer and the second endpoint computer in the encrypted session;forwarding the encrypted message without modification to the first endpoint computer or the second endpoint computer according to a destination address in the encrypted message;decrypting the encrypted message using the decryption key to result in decrypted data and using or storing the decrypted data in a storage unit.
  6. 29
    Broadest claimClaim Score 52, average(NHIP)An apparatus, comprising:a first network interface that is configured to be coupled to a network;a processor;logic encoded in one or more computer-readable media for operation and configurable when executed operable to cause the processor to perform: establishing a secure connection to a node in the network;receiving from the node in the network, over the secure connection, session identification data for an encrypted session between a client and a content server using an encryption protocol;selecting based on stored policy one or more cipher keys, initialization vectors, or message authentication code keys to provide to the node;generating and sending a reply to the node, wherein the reply comprises the selected one or more cipher keys, initialization vectors, or message authentication code keys for the encrypted session.