Certificate Discovery via Passive PKI Handshake Mirroring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security monitoring solutions in networks are intrusive and trigger alarms in network monitoring systems, failing to adequately check Public Key Infrastructure (PKI) data for compliance with standards, and lack the ability to capture client certificate information during secure connection handshakes.
Innovation Solution
Implementing a non-intrusive security monitoring mechanism in network switches that captures and analyzes PKI data via an analysis port, mirroring security data from handshake communications to an external system for compliance evaluation, enabling comprehensive analysis of certificate usage and compliance with standards.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If existing security monitoring solutions are deployed to capture PKI data, then security compliance analysis capability is improved, but false alarms are triggered in network monitoring systems
Solution Approach 1:
The patent introduces a network tap as an intermediary device that passively captures PKI data from network traffic without actively injecting probes or alerts into the monitored network. This intermediary approach allows security compliance analysis while avoiding the harmful effect of triggering false alarms in network monitoring systems.
Solution Approach 2:
The system creates a copy of network traffic containing PKI data through the network tap, analyzing the copied data rather than the original traffic flow. This copying mechanism enables comprehensive PKI data capture and compliance analysis without interfering with normal network operations or triggering security alerts.
2Reliability
If intrusive security monitoring is implemented to capture handshake data, then certificate compliance checking is improved, but network operations are disrupted
Solution Approach 1:
The monitored network systems perform their own certificate compliance verification through the captured PKI data, without requiring external intervention or disruption to their operations. The passive capture approach allows systems to self-verify compliance while maintaining normal operational flow.
Solution Approach 2:
By copying network traffic to an analysis port for PKI data extraction, the system enables compliance verification without interrupting the original network operations. The copy mechanism preserves operational continuity while providing comprehensive certificate validation capability.
3Measurement precision
If comprehensive PKI data analysis is performed to ensure security compliance, then compliance evaluation thoroughness is improved, but data processing complexity increases
Solution Approach 1:
The patent segments the compliance evaluation process into distinct functional modules: PKI data capture from network traffic, extraction of relevant certificate information, validation against compliance requirements, and reporting. This segmentation reduces overall system complexity while maintaining comprehensive evaluation accuracy.
Solution Approach 2:
The analysis port serves as an intermediary that receives copied traffic and feeds PKI data to the compliance analysis system, separating the monitoring function from the analysis function. This intermediary architecture simplifies the data processing pipeline while enabling thorough compliance evaluation.
Data Source
AI summary
Mechanisms are provided, in a communication device associated with a first computing device, for capturing security data exchanged between the first computing device and a second computing device. The mechanisms receive a data message from either the first computing device or the second computing device. The data message is part of an operation for establishing a secure communication connection between the first computing device and the second computing device. The mechanisms filter the received data message for security data passed in the received data message and mirror the security data to an analysis port of the communication device. Moreover, the mechanisms output, via the analysis port, the security data to a data collection and analysis system that analyzes the security data with regard to security requirement compliance.


