Secure connection and mutual authentication between intermediate and client devices and server systems

The secure connection is established through the intermediate device using the intermediate server public and private keys, which solves the authentication failure caused by the intermediate device and realizes trusted communication between the client device and the server system.

CN120389871APending Publication Date: 2025-07-29HEWLETT PACKARD ENTERPRISE DEV LP
View PDF 10 Cites 0 Cited by

Patent Information

Application Number
CN202410687954.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-01-29
Filing Date
2024-05-30
Publication Date
2025-07-29

AI Technical Summary

Technical Problem

In the communication between the client device and the server system, the existence of the intermediate device causes the certificate-based authentication process to fail, and the trusted connection cannot be established, resulting in the client device being unable to access the services provided by the server system.

Method used

Intermediate devices act as clients and servers, use intermediate server public keys and intermediate client private keys to establish a secure connection with client devices and server systems, and maintain the association between the public keys and private keys of intermediate devices by mapping information to achieve mutual authentication.

Benefits of technology

It realizes a secure connection between the client device and the server system, ensures the success of the authentication process, and allows the client device to access the services of the server system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120389871A_ABST
    Figure CN120389871A_ABST
Patent Text Reader

Abstract

Examples of the present disclosure relate to secure connections and mutual authentication between intermediate and client devices and server systems. In some examples, the intermediary device includes a memory to store mapping information that correlates an intermediary server public key with an intermediary server private key of the intermediary device, and mapping information that correlates an intermediary client public key with an intermediary client private key of the intermediary device. The intermediary device establishes a first secure connection between the intermediary device and the client device using the intermediary server public key and the intermediary server private key, wherein establishment of the first secure connection includes mutual authentication between the intermediary device and the client device. The intermediary device establishes a second secure connection between the intermediary device and the server system using the intermediary client public key and the intermediary client private key, wherein establishment of the second secure connection includes mutual authentication between the intermediary device and the server system.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0001] A client device can access a server system to use the services of the server system. An authentication process can be performed between the client device and the server system to allow a trust relationship to be established between the client device and the server system. BRIEF DESCRIPTION OF THE DRAWINGS

[0002] Some implementations of the present disclosure are described with reference to the following drawings.

[0003] Figure 1 is a block diagram of an arrangement including a client device, an intermediate device, and a server system according to some examples.

[0004] Figure 2 is a flowchart of a process involving a client device, an intermediate device, and a server system according to some examples.

[0005] Figure 3 is a block diagram of an intermediate device according to some examples.

[0006] Figure 4 is a block diagram of a storage medium storing machine-readable instructions according to some examples.

[0007] Figure 5 is a flowchart of a process according to some examples.

[0008] In all the drawings, the same reference numerals represent similar but not necessarily identical elements. The drawings are not necessarily to scale, and the dimensions of some parts may be enlarged to more clearly show the examples illustrated. Additionally, the drawings provide examples and / or implementations consistent with the specification; however, the specification is not limited to the examples and / or implementations provided in the drawings. DETAILED DESCRIPTION

[0009] In some examples, a client device can use user certificate information (e.g., a username and password) to allow the server system to authenticate the client device. In some other examples, certificate-based authentication can be performed between the client device and the server system. In certificate-based authentication, the client device and the server system can use certificates associated with the client device and the server system to perform authentication. Examples of certificates include public keys, which include a client public key of the client device sent from the client device to the server system, and a server public key of the server system sent from the server system to the client device. In some examples, certificate-based authentication can be according to the Secure Shell (SSH) protocol, including SSH version 2 (SSH2). In other examples, certificate-based authentication can be according to other security protocols.

[0010] In some scenarios, an intermediate device (e.g., a gateway or proxy) may be provided between a client device and a server system. However, the presence of an intermediate device between the client device and the server system can prevent the establishment of communication between the client device and the server system. As part of the authentication process, the client device may expect to receive a message encrypted using the server certificate (including the server public key) from the server system, rather than a message encrypted using the intermediate device's certificate. Similarly, the server system may expect to receive a message encrypted using the client certificate (including the client public key) from the client device, rather than a message encrypted using the intermediate device's certificate. If the certificate-based authentication process fails, the client device will not be able to establish a trusted connection with the intermediate device. Similarly, the intermediate device may not be able to successfully perform certificate-based authentication with the server system. If an authenticated connection cannot be successfully established in a computing arrangement where an intermediate device is provided between the client device and the server system, the client device will not be able to access the services provided by the server system without separately using user-certificate-based authentication that employs user certificates such as usernames and passwords.

[0011] According to some implementations of the present disclosure, an intermediate device is capable of performing both the server and client roles for establishing connections with a client device and a server system, such that the intermediate device can authorize interactions between the client device and the server system. The intermediate device is a proxy between the client device and the server system, where the intermediate device acts as the server when establishing a first secure connection with the client device that includes mutual authentication between the intermediate device and the client device, and the intermediate device acts as the client when establishing a second secure connection with the server system that includes mutual authentication between the intermediate device and the server system. In some examples of the present disclosure, the intermediate device provides an intermediate server public key that is used to establish the first secure connection (between the client device and the intermediate device), and an intermediate client private key that is used to establish the second secure connection (between the intermediate device and the server system). The intermediate device sends the intermediate server public key to the client device, which the client device uses to encrypt an authentication message as part of the authentication process for establishing the first secure connection. The intermediate device sends the intermediate client public key to the server system, which the server system uses to encrypt an authentication message as part of the authentication process for establishing the second secure connection.

[0012] In an example of the present disclosure, an intermediate device maintains mapping information that (1) associates an intermediate server public key with an intermediate server private key of the intermediate device and (2) associates an intermediate client public key with an intermediate client private key of the intermediate device. During a mutual authentication process between a client device and the intermediate device, the intermediate device receives a first encrypted authentication message encrypted by the client device using the intermediate server public key, and the intermediate device decrypts the first encrypted authentication message using the intermediate server private key associated with the intermediate server public key through the mapping information. In addition, the intermediate device sends a second encrypted authentication message encrypted using the client public key of the client device to the client device for decryption at the client device using the client private key. During a mutual authentication process between the intermediate device and a server system, the intermediate device receives a third encrypted authentication message encrypted by the server system using the intermediate client public key, and the intermediate device decrypts the third encrypted authentication message using the intermediate client private key associated with the intermediate client public key by the mapping information. In addition, the intermediate device sends a fourth encrypted authentication message encrypted using the server public key of the server system to the client device for decryption at the server system using the server private key. "Mutual authentication between the intermediate system and the client device" means that the intermediate device authenticates the client device and the client device authenticates the intermediate device. "Mutual authentication between the intermediate system and the server system" means that the intermediate device authenticates the server system and the server system authenticates the intermediate device.

[0013] The "mapping information" may include one or more data structures, such as one or more files or other data structures, that contain entries that map corresponding public keys of the intermediate device to the corresponding private keys of the intermediate device.

[0014] In some examples, the keys used may be part of a post-quantum cryptography (also known as quantum-resistant cryptography) process. Post-quantum cryptography includes the use of cryptographic techniques (including public-key algorithms) that are secure against both quantum computers and classical computers. A quantum computer refers to a computer that utilizes quantum mechanical effects. A classical computer is a non-quantum computer.

[0015] Figure 1 is a block diagram of an example arrangement that includes a client device 102, a server system 104, and an intermediate device 106 between the client device 102 and the server system 104. Although Figure 1 one client device 102 and one server system 104 are shown, in other examples, the intermediate device 106 may be connected between multiple client devices and multiple server systems. In addition, there may be more than one intermediate device in additional examples.

[0016] "Client device" can refer to any electronic device capable of accessing the services of server system 104. Examples of electronic devices can include any item or some combination of the following: a computer (e.g., a desktop computer, a server computer, a laptop computer, a tablet computer, or another type of computer), a smart phone, an Internet of Things (IoT) device, a household appliance, a gaming device, a vehicle, or any other type of electronic device.

[0017] Server system 104 can be implemented using one or more computers. Examples of server systems can include any item or some combination of the following: a network access device that provides access to a network, a web server that provides web-based services, a cloud server that provides cloud-based services, a storage system, or any other type of system having services accessible by client devices. Services provided by server system 104 can include any item or some combination of the following: a network access service that provides access to a network, web services, applications, use of resources (e.g., processing resources, storage resources, communication resources, or other resources), or other types of functionality. In an example where server system 104 is a network access device, server system 104 can include a switch, a router, a gateway, or any other device that enables access to a network by client devices.

[0018] Intermediate device 106 can be implemented using one or more computers. Intermediate device 106 is connected to client device 102 via communication link 108, and intermediate device 106 is connected to server system 104 via communication link 110. "Communication link" can refer to any type of communication medium that allows electronic devices to communicate with each other. Examples of communication links can include wireless links or wired links, including links that are part of a network.

[0019] In some examples, intermediate device 106 can be provided in a cloud computing environment. Messages to intermediate device 106 (e.g., from client device 102 and server system 104) can be routed through a network such as the Internet to intermediate device 106 in the cloud computing environment. The benefit of implementing intermediate device 106 in a cloud computing environment is that as the number of messages to be processed by intermediate device 106 increases, additional resources (including processing resources, communication resources, and storage resources) can be provided to intermediate device 106 on demand. With intermediate device 106 in a cloud computing environment, an enterprise will not have to deploy expensive intermediate devices at the enterprise's premises. Instead, the enterprise can pay for the use of resources for the intermediate device on demand as the resources are allocated by the cloud computing provider.

[0020] Although reference is made to the intermediate device 106 in a cloud computing environment, note that in other examples, the intermediate device 106 may be implemented in different computing environments, such as in a data center or another computing environment.

[0021] The client device 102 may establish a secure session S1 with the intermediate device 106, and the intermediate device 106 may establish a secure session S2 with the server system 104. The data exchanged in each of the secure sessions S1 and S2 is encrypted. Note that the data (e.g., messages) in the secure session S1 and the data in the secure session S2 may be the same, except that the data in the respective secure sessions S1 and S2 may use different cryptographic algorithms and keys. A "key" refers to the secret used in encrypting data according to a cryptographic algorithm.

[0022] According to some implementations of the present disclosure, the intermediate device 106 stores mapping information 112 in a memory 114 of the intermediate device 106. The memory may be implemented using one or more memory devices. Examples of memory devices include any of or some combination of the following: dynamic random access memory (DRAM) devices, static random access memory (SRAM) devices, flash memory devices, or any other type of memory device. Although Figure 1 an example is shown in which the mapping information 112 is stored in the memory 114 that is part of the intermediate device 106, in other examples, the mapping information 112 (or a portion thereof) may be stored on an external memory outside the intermediate device 106. In either case, the memory 114 may include a secure memory that protects against unauthorized access.

[0023] The mapping information 112 includes a client-side mapping information segment 112A and a server-side mapping information segment 112B. The client-side mapping information segment 112A includes entries that correlate intermediate server public keys with corresponding intermediate server private keys, and the server-side mapping information segment 112B includes entries that correlate intermediate client public keys with corresponding intermediate client private keys. For example, in Figure 1 the example of, the client-side mapping information segment 112A includes an entry 115 that correlates the intermediate server public key PU-KEY IS with the intermediate server private key PR-KEY IS Other entries in the client-side mapping information segment 112A correlate other intermediate server public keys with corresponding intermediate server private keys. Each entry in the client-side mapping information segment 112A includes a respective pair of an intermediate server public key and a corresponding intermediate server private key.

[0024] A given pair of intermediate server public key and intermediate server private key is used to perform encrypted communication from a corresponding client device to the intermediate device 106. For example, the first pair of intermediate server public key and intermediate server private key is used to perform encrypted communication from the first client device to the intermediate device 106, the second pair of intermediate server public key and intermediate server private key is used to perform encrypted communication from the second client device to the intermediate device 106, and so on.

[0025] Similarly, the server-side mapping information segment 112B includes entries 116 that associate the intermediate client private key PR-KEY IC with the intermediate client public key PU-KEY IC Other entries in the server-side mapping information segment 112B associate other intermediate client private keys with the corresponding intermediate client public keys. Each entry in the server-side mapping information segment 112B includes a corresponding pair of intermediate client private key and intermediate server public key.

[0026] A given pair of intermediate server private key and intermediate server public key is used to perform encrypted communication from a corresponding server system to the intermediate device 106. For example, the first pair of intermediate server private key and intermediate server public key is used to perform encrypted communication from the first server system to the intermediate device 106, the second pair of intermediate server private key and intermediate server public key is used to perform encrypted communication from the second server system to the intermediate device 106, and so on.

[0027] The client device 102, the intermediate device 106, and the server system 104 exchange their respective public keys with each other. More specifically, the intermediate device 106 sends the intermediate server public key PU-KEY IS to the client device 102 for the client device 102 to use in encrypting data sent from the client device 102 to the intermediate device 106 over the communication link 108. The intermediate device 106 uses the intermediate client private key PR-KEY IC to decrypt the encrypted data from the client device 102.

[0028] The intermediate server public key PU-KEY received by the client device 102 from the intermediate device 106 IS is stored in the memory 120 of the client device 102. The memory 120 of the client device 102 also stores the client public key PU-KEY C and the client private key PR-KEY C (the public key-private key pair of the client device 102). The client device 102 sends the client public key PU-KEY stored in the memory 114 to the intermediate device 106 C . The intermediate device 106 can use the client public key PU-KEY Cto encrypt data sent from the intermediate device 106 to the client device 102 via the communication link 108. The client device 102 uses the client private key PR-KEY C to decrypt the encrypted data from the intermediate device 106.

[0029] Similarly, the intermediate device 106 sends the intermediate client public key PU-KEY IC to the server system 104 for use by the server system 104 in encrypting data sent from the server system 104 to the intermediate device 106 via the communication link 110. The intermediate device 106 uses the intermediate client private key PR-KEY IC to decrypt the encrypted data from the server system 104.

[0030] The server system 104 stores the intermediate client public key PU-KEY IC in the memory 122 of the server system 104. The memory 122 of the server system 104 also stores the server public key PU-KEY S and the server private key PR-KEY S (the public-private key pair of the server system 104). The server system 104 sends the server public key PU-KEY S to the intermediate device 106, and the intermediate device 106 stores the server public key PU-KEY S in the memory 114. The intermediate device 106 uses the server public key PU-KEY S to encrypt data sent to the server system 104 via the communication link. The server system 104 uses the server private key PR-KEY S to decrypt the encrypted data from the intermediate device 106.

[0031] In some examples, the memory 120 of the client device 102 may also store a list 142 of known servers, which may include a list of information elements associated with servers known to the client device 102. A list of "known" servers or clients may refer to servers or clients for which information (e.g., by a human administrator, program, or machine) has been provided to a given device before any interaction between the given device and the client or server. For example, the list 142 of known servers may be provided to the client device 102 before any interaction between the client device 102 and the servers represented by the list 142 of known servers.

[0032] In some examples, the list 142 of known servers may include a list of server public keys for the known servers. For example, the intermediate device 106 is an example of a server that may be represented in the list 142 of known servers. In such an example, the list 142 of known servers will include the intermediate server public key PU-KEYIS (and any other server public keys of the servers known to the client device 102).

[0033] The list of known servers 142 can be used by the client device 102 to verify the server public keys received from a server such as the intermediate device 106. In other examples, the list of known servers 142 is not provided to the client device 102 prior to the interaction with the server.

[0034] The memory 122 of the server system 104 can similarly include a list of known clients 144, which can include information elements associated with clients known to the server system 104. For example, the list of known clients 144 can include a list of client public keys for clients known to the server system 104. The intermediate device 106 is an example of a client that can be represented in the list of known clients 144. In such an example, the list of known clients 144 will include the intermediate client public key PU-KEY IC (and any other client public keys of the clients known to the client device 102). The list of known clients 144 can be used by the server system 104 to verify the client public keys received from a client such as the intermediate device 106. In other examples, the list of known clients 144 is not provided to the server system 104 prior to the interaction with the client.

[0035] The memory 114 of the intermediate device 106 can also store a list of known clients 146, which can include information elements associated with clients known to the intermediate device 106. For example, the list of known clients 144 can include a list of client public keys for clients known to the intermediate device 106. The client device 102 is an example of a client that can be represented in the list of known clients 146. In such an example, the list of known clients 146 will include the client public key PU-KEY C (and any other client public keys of the clients known to the intermediate device 106). The list of known clients 146 can be used by the intermediate device 106 to verify the client public keys received from a client such as the client device 102. In other examples, the list of known clients 146 is not provided to the intermediate device 106 prior to the interaction with the client.

[0036] The memory 114 of the intermediate device 106 may also store a list 148 of known servers, which may include a list of information elements associated with servers known to the intermediate device 106. In some examples, the list 148 of known servers may include a list of server public keys for the known servers. For example, the server system 104 is an example of a server that may be represented in the list 148 of known servers. In such an example, the list 148 of known servers will include the server public key PU-KEY S (and any other server public keys of the servers known to the intermediate device 106).

[0037] The list 148 of known servers may be used by the intermediate device 106 to verify server public keys received from a server such as the server system 104. In other examples, the list 148 of known servers is not provided to the intermediate device 106 before interacting with the server.

[0038] As further depicted in Figure 1 , the client device 102 includes an authentication engine 132, the server system 104 includes an authentication engine 134, and the intermediate device 106 includes an authentication engine 136. As used herein, "engine" may refer to one or more hardware processing circuits, which may include any item or some combination of a microprocessor, a core of a multi-core microprocessor, a microcontroller, a programmable integrated circuit, a programmable gate array, or another hardware processing circuit. Alternatively, "engine" may refer to a combination of one or more hardware processing circuits and machine-readable instructions (software and / or firmware) executable on the one or more hardware processing circuits.

[0039] The authentication engines 132, 134, and 136 may perform a mutual authentication process. More specifically, the authentication engines 132 and 136 may perform a mutual authentication process between the client device 102 and the intermediate device 106 to authenticate each other, and the authentication engines 136 and 134 may perform a mutual authentication process between the intermediate device 106 and the server system 104 to authenticate each other.

[0040] In response to the mutual authentication of the client device 102 and the intermediate device 106, the establishment of a secure session S1 between the client device 102 and the intermediate device 106 occurs. Similarly, in response to the mutual authentication of the intermediate device 106 and the server system 104, the establishment of a secure session S2 between the intermediate device 106 and the server system 104 occurs.

[0041] Figure 2 is a message flow diagram of a process involving the client device 102, the intermediate device 106, and the server system 104. Although Figure 2Shows a specific order of tasks, but in other examples, the tasks may be performed in a different order, some of the tasks may be omitted, and additional tasks may be added.

[0042] As shown in Figure 2 , the client device 102 and the intermediate device 106 may (at 202) exchange their respective public keys. More specifically, the client device 102 (at 202A) sends the client public key PU-KEY to the intermediate device 106 C , and the intermediate device 106 (at 202B) sends the intermediate server public key PU-KEY to the client device 102 IS .

[0043] Similarly, the intermediate device 106 and the server system 104 may (at 204) exchange their respective public keys. More specifically, the intermediate device 106 (at 204A) sends the intermediate client public key PU-KEY to the server system 104 IC , and the server system 104 (at 204B) sends the server public key PU-KEY to the intermediate device 106 S .

[0044] The authentication engine 132 in the client device 102 may (at 206) verify the intermediate server public key PU-KEY IS , for example, by comparing the intermediate server public key PU-KEY received from the intermediate device 106 IS with the server public keys in the known server list 142. If the received intermediate server public key PU-KEY IS matches the server public keys in the known server list 142, the client device 102 confirms that the received intermediate server public key PU-KEY IS is verified.

[0045] Similarly, the authentication engine 136 in the intermediate device 106 (at 208) verifies the client public key PU-KEY C , for example, by comparing the client public key PU-KEY received from the client device 102 C with the client public keys in the known client list 146. If the received client public key PU-KEY C matches the client public keys in the known client list 146, the intermediate device 106 confirms that the received client public key PU-KEY C is verified. In other examples, other techniques for verifying public keys may be performed, such as by using public key fingerprints (e.g., cryptographic hashes) according to the SSH protocol or trust technology roots according to the HTTPS protocol.

[0046] The authentication engine 136 in the intermediate device 106 (at 210) further verifies the server public key PU-KEY S , for example, by comparing the server public key PU-KEY received from the server system 104 S with the server public keys in the known server list 148. If the received server public key PU-KEY S matches the server public key in the known server list 138, the intermediate device 106 confirms that the received server public key PU-KEY S is verified.

[0047] The authentication engine 134 in the server system 104 (at 212) verifies the intermediate client public key PU-KEY IC , for example, by comparing the client public key PU-KEY received from the intermediate device 106 IC with the client public keys in the known client list 144. If the received intermediate client public key PU-KEY IC matches the client public key in the known client list 144, the server system 104 confirms that the received intermediate client public key PU-KEY IC is verified.

[0048] Assuming (at 206, 208, 210, 212) that the corresponding public keys are successfully verified, the client device 102, the intermediate device 106, and the server system 104 can continue to establish a secure session between the client device 102 and the intermediate device 106, and between the intermediate device 106 and the server system 104 (including S1 and S2 in Figure 1 ).

[0049] To establish the secure session S1 between the client device 102 and the intermediate device 106 (at 214), the client device 102 (at 214A) sends (encrypted using the intermediate server public key PU-KEY IS ) the first encrypted data to the intermediate device 106, and the intermediate device 106 decrypts the first encrypted data from the client device 102 using the intermediate server private key PR-KEY IS to generate the first decrypted data. As part of the mutual authentication between the intermediate device 106 and the client device 102, the authentication engine 132 in the client device 102 can authenticate the intermediate device 106 based on the first decrypted data (e.g., by detecting that the first encrypted data has been successfully decrypted, or by comparing the first decrypted data with the stored data, or by another technique).

[0050] To establish a secure session S1 (at 214), the intermediate device 106 sends (using the client public key PU-KEY C encrypted) a second encrypted data to the client device 102 (at 214B), and the client device 102 uses the client private key PR-KEY C to decrypt the second encrypted data from the intermediate device 106 to generate a second decrypted data. As part of the mutual authentication between the intermediate device 106 and the client device 102, the authentication engine 134 in the intermediate device 106 can authenticate the client device 102 based on the second decrypted data. Note that the mutual authentication between the intermediate device 106 and the client device 102 is part of the establishment of the secure session S1, in which the cryptographic algorithms and keys are negotiated between the intermediate device 106 and the client device 102, e.g., according to the SSH protocol.

[0051] Similarly, to establish a secure session S2 (at 216) between the intermediate device 106 and the server system 104, the intermediate device 106 (at 216A) sends (using the server public key PU-KEY S encrypted) a third encrypted data to the server system 104, and the server system 104 uses the server private key PR-KEY S to decrypt the third encrypted data from the intermediate device 106 to generate a third decrypted data. As part of the mutual authentication between the intermediate device 106 and the server system 104, the authentication engine 134 in the server system 104 can authenticate the intermediate device 106 based on the third decrypted data. To establish a secure session S2 (at 216), the server system 104 (at 216B) sends (using the intermediate client public key PU-KEY IC encrypted) a fourth encrypted data to the intermediate device 106, and the intermediate device 106 uses the intermediate client private key PR-KEY IC to decrypt the fourth encrypted data received from the server system 104 to generate a fourth decrypted data. As part of the mutual authentication between the intermediate device 106 and the server system 104, the authentication engine 134 in the intermediate device 106 can authenticate the server system 104 based on the fourth decrypted data. Note that the mutual authentication between the intermediate device 106 and the server system 104 is part of the establishment of the secure session S2, in which the cryptographic algorithms and keys are negotiated between the intermediate device 106 and the server system 104, e.g., according to the SSH protocol.

[0052] Note that the data exchanged between the client device 102, the intermediate device 106, and the server system 104 to establish the secure sessions S1 and S2 includes authentication messages and any other data associated with the session establishment.

[0053] Once the secure sessions S1 and S2 are established, the client device and the intermediate device 106 can (at 218) perform secure communication through the secure session S1, and the intermediate device 106 and the server system 104 can (at 220) perform secure communication through the secure session S2.

[0054] In some examples, key rotation may be performed at the intermediate device 106. "Key rotation" refers to generating a new key to replace a previous key. Key rotation may be triggered in response to an event, such as a timer expiration, detection of a security issue in the intermediate device 106 or a system coupled to the intermediate device 106, or any other event.

[0055] Once triggered, key rotation may cause the intermediate device 106 to generate a new intermediate server public key to replace the existing intermediate server public key, and generate a new intermediate client public key to replace the existing intermediate client public key. In response to the generation of the new intermediate server public key, the intermediate device 106 generates a corresponding new intermediate server private key, and updates the corresponding entry in the client - side mapping information segment 112A with the new intermediate server public key and the corresponding new intermediate server private key. Similarly, in response to the generation of the new intermediate client public key, the intermediate device 106 generates a corresponding new intermediate client private key, and updates the corresponding entry in the server - side mapping information segment 112B with the new intermediate client public key and the corresponding new intermediate client private key.

[0056] In some examples, the intermediate device 106 may be used to perform various workflows involving the client device 102 and the server system 104. For example, the client device 102 may issue a command to the server system 104, which may execute the command at the server system 104. The command is sent by the client device 102 to the intermediate device 106 that can verify the command. If the command is verified by the intermediate device 106, the intermediate device 106 may forward the command to the server system 104. If the command is not verified by the intermediate device 106, the intermediate device 106 may discard the command.

[0057] In another example, the client device 102 may access a subsystem coupled to the server system 104. The intermediate device 106 may be used to determine whether access to the subsystem is allowed.

[0058] In a further example, the client device 102 may transmit data (e.g., a file) to the server system 104. The intermediate device 106 may include a malware protection program to determine whether the transmitted data contains malware. The intermediate device 106 may also establish a sandbox for the transmitted data to isolate the transmitted data from other processes.

[0059] According to some examples of the present disclosure,Figure 3 is a block diagram of an intermediate device 300. The intermediate device 300 can be Figure 1 and Figure 2 an example of the intermediate device 106 of

[0060] The intermediate device 300 includes a memory 302 for storing mapping information 304 that correlates the intermediate server public key 306 with the intermediate server private key 308 of the intermediate device 300, and that correlates the intermediate client public key 310 with the intermediate client private key 312 of the intermediate device 300.

[0061] The intermediate device 300 includes a hardware processor 314 (or multiple hardware processors) to perform various tasks. The hardware processor can include a microprocessor, a core of a multi-core microprocessor, a microcontroller, a programmable integrated circuit, a programmable gate array, or another hardware processing circuit. The hardware processor performing a task can refer to a single hardware processor performing the task or multiple hardware processors performing the task.

[0062] Tasks of the hardware processor 314 include a secure connection establishment task 316 based on an intermediate server key to establish a first secure connection between the intermediate device 300 and a client device using the intermediate server public key 306 and the intermediate server private key 308 correlated by the mapping information 304. In the first secure connection, the intermediate device 300 acts as a server to the client device. In some examples, the establishment of the first secure connection includes mutual authentication between the intermediate device 300 and the client device, the mutual authentication being based on the use of the intermediate server public key 306 to encrypt a first message from the client device to the intermediate device 300, and on the use of the intermediate server private key 308 to decrypt the encrypted first message at the intermediate device 300. The mutual authentication between the intermediate device 300 and the client device is also based on the use of the client public key of the client device to encrypt a second message sent from the intermediate device 300 to the client device.

[0063] The tasks of the hardware processor 314 include a secure connection establishment task 318 based on an intermediate client key for establishing a second secure connection between the intermediate device 300 and the server system using the intermediate client public key 310 and the intermediate client private key 312 correlated with each other by the mapping information 304. In the second secure connection, the intermediate device 300 acts as a client to the server system. In some examples, establishing the second secure connection includes mutual authentication between the intermediate device 300 and the server system, which is based on the use of the intermediate client public key 310 to encrypt a third message from the server system to the intermediate device 300 and on the use of the intermediate client private key 312 to decrypt the encrypted third message at the intermediate device 300. The mutual authentication between the intermediate device 300 and the server system is also based on the use of the server public key of the server system to encrypt a fourth message sent from the intermediate device 300 to the server system.

[0064] In some examples, the intermediate device 300 sends the intermediate server public key 306 to the client device for use by the client, and the intermediate device 300 sends the intermediate client public key 310 to the server system for use by the server system.

[0065] In some examples, as part of a key rotation performed at the intermediate device 300, the hardware processor 314 generates a new intermediate server public key (which replaces the intermediate server public key 306), and based on the generation of the new intermediate server public key, the hardware processor 314 generates a new intermediate server private key for the intermediate device 300 (which replaces the intermediate server private key 308). The hardware processor 314 updates the mapping information 304 to correlate the new intermediate server public key with the new intermediate server private key.

[0066] In some examples, the intermediate device 300 receives the client public key of the client device from the client device. The hardware processor 314 uses the client public key of the client device to encrypt a message to produce an encrypted message. The hardware processor 314 causes the encrypted message to be sent to the client device.

[0067] In some examples, the intermediate device 300 receives the server public key of the server system from the server system. The hardware processor 314 uses the server public key of the server system to encrypt a message to produce an encrypted message. The hardware processor 314 causes the encrypted message to be sent to the server system.

[0068] In some examples, the establishment of the first secure connection is based on the use of the intermediate server public key 306 to encrypt the first message from the client device to the intermediate device 300, and on the use of the intermediate server private key 308 to decrypt the encrypted first message at the intermediate device 300. The establishment of the second secure connection is based on the use of the intermediate client public key 310 to encrypt the second message from the server system to the intermediate device 300, and on the use of the intermediate client private key 312 to decrypt the encrypted second message at the intermediate device 300.

[0069] In some examples, the first message is part of an authentication process between the client device and the intermediate device 300, and the second message is part of an authentication process between the server system and the intermediate device 300.

[0070] In some examples, the authentication process between the client device and the intermediate device and the authentication process between the server system and the intermediate device are according to the SSH protocol or any other protocol that supports device authentication.

[0071] In some examples, the mapping information 304 correlates multiple intermediate server public keys with the corresponding intermediate server private keys of the intermediate device. The hardware processor 314 causes the multiple intermediate server public keys to be sent to the corresponding client devices.

[0072] In some examples, the mapping information 304 correlates multiple intermediate client public keys with the corresponding intermediate client private keys of the intermediate device. The hardware processor 314 causes the multiple intermediate client public keys to be sent to the corresponding server systems.

[0073] In some examples, the intermediate device 300 sends the intermediate server public key to the client device for verification at the client device, and the intermediate device 300 receives the client public key of the client device from the client device. The hardware processor 314 verifies the client public key at the intermediate device 300.

[0074] In some examples, the intermediate device 300 sends the intermediate client public key to the server system for verification at the server system, and the intermediate device 300 receives the server public key of the server system from the server system. The hardware processor 314 verifies the server public key at the intermediate device 300.

[0075] Figure 4 is a block diagram of a non-transitory machine-readable or computer-readable storage medium 400 storing machine-readable instructions that, when executed, cause the intermediate device to perform various tasks.

[0076] The machine-readable instructions include an intermediate server public key sending instruction 402 for sending an intermediate server public key from an intermediate device to a client device. When the intermediate server public key sending instruction 402 is executed, it causes the intermediate server public key to be sent through the network interface of the intermediate device to transfer the intermediate server public key to the client device via the network.

[0077] The machine-readable instructions include an intermediate client public key sending instruction 404 for sending an intermediate client public key from the intermediate device to a server system. When the intermediate client public key sending instruction 404 is executed, it causes the intermediate client public key to be sent through the network interface of the intermediate device to transfer the intermediate client public key to the server system via the network.

[0078] The machine-readable instructions include a first encrypted data decryption instruction 406 for decrypting first encrypted data received from the client device using an intermediate server private key retrieved from an entry of mapping information that correlates the intermediate server public key and the intermediate server private key. An example of the mapping information is Figure 1 the mapping information 112. The machine-readable instructions include a client device authentication instruction 408 for authenticating the client device using the first decrypted data generated by decrypting the first encrypted data. The authentication of the client device by the intermediate device is part of a mutual authentication between the intermediate device and the client device, which is used to establish a first secure connection between the intermediate device and the client device. This mutual authentication between the intermediate device and the client device is part of establishing a first cryptographic session between the intermediate device and the client device, in which the intermediate device and the client device can negotiate a first cryptographic algorithm and password.

[0079] The machine-readable instructions include a second encrypted data decryption instruction 410 for decrypting second encrypted data received from the server system using an intermediate client private key retrieved from an entry of mapping information that correlates the intermediate client public key and the intermediate client private key. The machine-readable instructions include a server system authentication instruction 412 for authenticating the server system using the second decrypted data generated by decrypting the second encrypted data. The authentication of the server system by the intermediate device is part of a mutual authentication between the intermediate device and the server system, which is used to establish a second secure connection between the intermediate device and the server system. This mutual authentication between the intermediate device and the server system is part of establishing a second cryptographic session between the intermediate device and the server system, in which the intermediate device and the server system can negotiate a second cryptographic algorithm and password.

[0080] Figure 5is a flowchart of process 500 according to some examples. Process 500 includes (at 502) coupling an intermediate device between a client device and a server system. The intermediate device acts as a server to the client device and the intermediate device acts as a client to the server system.

[0081] Process 500 includes (at 504) storing in a memory mapping information that correlates a plurality of intermediate server public keys with corresponding intermediate server private keys of the intermediate device, and correlates a plurality of intermediate client public keys with corresponding intermediate client private keys of the intermediate device. An example of the mapping information is Figure 1 mapping information 112.

[0082] Process 500 includes, as part of a first secure session establishment that includes mutual authentication between the intermediate device and the client device, (at 506) authenticating the client device by the intermediate device based on first encrypted data encrypted by the client device using an intermediate server public key among the intermediate server public keys. The intermediate device uses the intermediate server private key correlated with the intermediate server public key through the mapping information to decrypt the first encrypted data.

[0083] Process 500 includes, as part of a second secure session establishment that includes mutual authentication between the intermediate device and the server system, (at 508) authenticating the server system by the intermediate device based on second encrypted data encrypted by the server system using an intermediate client public key among the intermediate client public keys. The intermediate device uses the intermediate client private key correlated with the intermediate client public key through the mapping information to decrypt the second encrypted data.

[0084] A storage medium (e.g., 400 in Figure 4 ) can include any of the following or some combination thereof: semiconductor memory devices such as DRAM or SRAM, erasable programmable read only memory (EPROM), electrically erasable programmable read only memory (EEPROM), and flash memory; magnetic disks such as fixed disks, floppy disks, and removable disks; another magnetic medium including magnetic tape; optical media such as compact discs (CDs) or digital versatile discs (DVDs); or another type of storage device. Note that the instructions discussed above can be provided on one computer-readable or machine-readable storage medium or, alternatively, can be provided on multiple computer-readable or machine-readable storage media distributed in a large system that may have multiple nodes. Such (multiple) computer-readable or machine-readable storage media are considered to be part of a work (or article of manufacture). A work or article of manufacture can refer to any single manufactured component or multiple components. The storage medium or multiple storage media can be located in a machine that runs the machine-readable instructions or at a remote site from which the machine-readable instructions can be downloaded over a network for execution.

[0085] In this disclosure, the use of the terms "a", "an", or "the" is also intended to include the plural forms, unless the context clearly dictates otherwise. Additionally, when the terms "include", "including", "comprise", "comprising", "have", or "having" are used in this disclosure, they specify the presence of the recited element but do not preclude the presence or addition of other elements.

[0086] In the foregoing description, numerous specific details are set forth to provide an understanding of the subject matter disclosed herein. It is, however, possible to practice implementations without some of these specific details. Other implementations may include modifications and variations from the details discussed above. The appended claims are intended to cover these modifications and variations.

Claims

1. An intermediate device for being provided between a client device and a server system, the intermediate device comprising: a memory for storing mapping information that correlates an intermediate server public key with an intermediate server private key of the intermediate device and correlates an intermediate client public key with an intermediate client private key of the intermediate device; and a hardware processor for: establishing a first secure connection between the intermediate device and the client device using the intermediate server public key and the intermediate server private key correlated by the mapping information, wherein in the first secure connection, the intermediate device acts as a server for the client device, and the establishment of the first secure connection includes mutual authentication between the intermediate device and the client device; and establishing a second secure connection between the intermediate device and the server system using the intermediate client public key and the intermediate client private key correlated by the mapping information, wherein in the second secure connection, the intermediate device acts as a client for the server system, and the establishment of the second secure connection includes mutual authentication between the intermediate device and the server system.

2. The intermediate device according to claim 1, wherein the intermediate device is configured to: send the intermediate server public key to the client device for use by the client device; and send the intermediate client public key to the server system for use by the server system.

3. The intermediate device according to claim 2, wherein the hardware processor is configured to: generate a new intermediate server public key as part of a key rotation performed at the intermediate device; generate a new intermediate server private key of the intermediate device based on the generation of the new intermediate server public key; and update the mapping information to correlate the new intermediate server public key with the new intermediate server private key.

4. The intermediate device according to claim 1, wherein the intermediate device is configured to receive a client public key of the client device from the client device, and wherein the hardware processor is configured to: as part of the mutual authentication between the intermediate device and the client device, use the client public key of the client device to encrypt a message to produce an encrypted message; and cause the encrypted message to be sent to the client device.

5. The intermediate device according to claim 1, wherein the intermediate device is configured to receive a server public key of the server system from the server system, and wherein the hardware processor is configured to: as part of the mutual authentication between the intermediate device and the server system, use the server public key of the server system to encrypt a message to produce an encrypted message; and cause the encrypted message to be sent to the server system.

6. The intermediate device according to claim 1, wherein the establishment of the first secure connection including the mutual authentication between the intermediate device and the client device is based on the use of the intermediate server public key to encrypt a first message from the client device to the intermediate device, and based on the use of the intermediate server private key to decrypt the encrypted first message at the intermediate device, and wherein the establishment of the second secure connection including the mutual authentication between the intermediate device and the server system is based on the use of the intermediate client public key to encrypt a second message from the server system to the intermediate device, and based on the use of the intermediate client private key to decrypt the encrypted second message at the intermediate device.

7. The intermediate device according to claim 6, wherein the mutual authentication between the client device and the intermediate device and the mutual authentication between the server system and the intermediate device are according to the Secure Shell (SSH) protocol.

8. The intermediate device according to claim 1, wherein the mapping information correlates a plurality of intermediate server public keys with corresponding intermediate server private keys of the intermediate device, and wherein the hardware processor is configured to:[[]] Cause the plurality of intermediate server public keys to be sent to corresponding client devices.

9. The intermediate device according to claim 1, wherein the mapping information correlates a plurality of intermediate client public keys with corresponding intermediate client private keys of the intermediate device, and wherein the hardware processor is configured to:[[]] Cause the plurality of intermediate client public keys to be sent to corresponding server systems.

10. The intermediate device according to claim 1, wherein the hardware processor is configured to:[[]] Send the intermediate server public key from the intermediate device to the client device for verification at the client device; Receive the client public key of the client device at the intermediate device from the client device; and Verify the client public key at the intermediate device.

11. The intermediate device according to claim 1, wherein the hardware processor is configured to:[[]] Send the intermediate client public key from the intermediate device to the server system for verification at the server system; Receive the server public key of the server system at the intermediate device from the server system; and Verify the server public key at the intermediate device.

12. A non-transitory machine-readable storage medium including instructions that, when executed, cause an intermediate device to:[[]] Send an intermediate server public key from the intermediate device to a client device; Send an intermediate client public key from the intermediate device to a server system; Decrypt first encrypted data received from the client device using an intermediate server private key retrieved from an entry of mapping information that correlates the intermediate server public key with the intermediate server private key; Authenticate the client device using the first decrypted data generated by decrypting the first encrypted data, wherein the authentication of the client device by the intermediate device is part of a mutual authentication between the intermediate device and the client device, and the mutual authentication between the intermediate device and the client device is used to establish a first secure connection between the intermediate device and the client device; Decrypt the second encrypted data received from the server system using the intermediate client private key retrieved from an entry of the mapping information that correlates the intermediate client public key with the intermediate client private key; And Authenticate the server system using the second decrypted data generated by decrypting the second encrypted data, wherein the authentication of the server system by the intermediate device is part of a mutual authentication between the intermediate device and the server system, and the mutual authentication between the intermediate device and the server system is used to establish a second secure connection between the intermediate device and the server system.

13. The non-transitory machine-readable storage medium according to claim 12, wherein the mutual authentication between the intermediate device and the client device is part of establishing a first cryptographic session between the intermediate device and the client device, and wherein the mutual authentication between the intermediate device and the server system is part of establishing a second cryptographic session between the intermediate device and the server system.

14. The non-transitory machine-readable storage medium according to claim 12, wherein the intermediate device acts as a server for the client device and as a client for the server system.

15. The non-transitory machine-readable storage medium according to claim 12, wherein the instructions, when executed, cause the intermediate device to: Send third encrypted data encrypted using the client public key of the client device from the intermediate device to the client device, the third encrypted data being used by the client device in authenticating the intermediate device, wherein authenticating the intermediate device is part of the mutual authentication between the intermediate device and the client device; and Send fourth encrypted data encrypted using the server public key of the server system from the intermediate device to the server system, the fourth encrypted data being used by the server system in authenticating the intermediate device, wherein authenticating the intermediate device is part of the mutual authentication between the intermediate device and the server system.

16. The non-transitory machine-readable storage medium according to claim 15, wherein the instructions, when executed, cause the intermediate device to: Receive the client public key from the client device at the intermediate device; and Receive the server public key from the server system at the intermediate device.

17. The non-transitory machine-readable storage medium according to claim 12, wherein the instructions, when executed, cause the intermediate device to: Perform key rotation at the intermediate device, the key rotation including: Generating a new intermediate server public key to replace the intermediate server public key; Generating a new intermediate server private key for the intermediate device based on the generation of the new intermediate server public key; Generating a new intermediate client public key to replace the intermediate client public key; Generating a new intermediate client private key for the intermediate device based on the generation of the new intermediate client public key; and Updating the mapping information to associate the new intermediate server public key with the new intermediate server private key and to associate the new intermediate client public key with the new intermediate client private key.

18. The non-transitory machine-readable storage medium according to claim 12, wherein the mapping information associates a plurality of intermediate server public keys with corresponding intermediate server private keys of the intermediate device, and the mapping information associates a plurality of intermediate client public keys with corresponding intermediate client private keys of the intermediate device.

19. A method, comprising: Coupling an intermediate device between a client device and a server system, wherein the intermediate device serves as a server for the client device and the intermediate device serves as a client for the server system; Storing mapping information in a memory, the mapping information associating a plurality of intermediate server public keys with corresponding intermediate server private keys of the intermediate device and associating a plurality of intermediate client public keys with corresponding intermediate client private keys of the intermediate device; Authenticating the client device by the intermediate device based on first encrypted data encrypted by the client device using a first intermediate server public key among the intermediate server public keys as part of establishing a first secure session including mutual authentication between the intermediate device and the client device; And Authenticating the server system by the intermediate device based on second encrypted data encrypted by the server system using a first intermediate client public key among the intermediate client public keys as part of establishing a second secure session including mutual authentication between the intermediate device and the server system.

20. The method according to claim 19, wherein: The mutual authentication between the intermediate device and the client device further includes sending the first intermediate server public key from the intermediate device to the client device and receiving, at the intermediate device, encrypted data encrypted by the client device using the first intermediate server public key; and The mutual authentication between the intermediate device and the server system includes sending the first intermediate client public key from the intermediate device to the server system and receiving, at the intermediate device, encrypted data encrypted by the server system using the first intermediate client public key.

Citation Information

Patent Citations

  • Data recovery method and device based on SSL protocol

    CN106685983A

  • Method and apparatus for implementing certificate reconstruction, storage medium and program product

    CN108011888A

  • Hosts accessing to computer network

    CN108123930A

  • TLS protocol session key restoration method based on random number implicit negotiation

    CN109600226A

  • Multiple businesses-based secure authentication method and device, electronic device and storage medium

    CN109660534A