Cloud Security Node Certificate Proxying for Secure Content Inspection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud-based security services face challenges in inspecting secure content, particularly when client certificate-based authentication is employed, as they cannot translate and sign client certificates, leading to incomplete content inspection and vulnerability to man-in-the-middle attacks, and managing client certificates is complex and resource-intensive.

Innovation Solution

Implementing a system that verifies the security of connections between client devices and cloud services, and between cloud services and servers, allowing the cloud service to inspect secure content while ensuring no man-in-the-middle attacks by using certificate proxying and verification mechanisms to ensure valid client certificates are used, and simplifying certificate management through centralized issuance and revocation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If cloud based security service nodes intercept HTTPS communication by providing server certificates to enable content inspection, then content inspection capability is improved, but vulnerability to man-in-the-middle attacks increases

Engineering Contradiction:
Improvecontent inspection capabilityVSAvoidman-in-the-middle attack vulnerability
Core Design Contradiction:
Difficulty of detecting and measuringVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a certificate proxying mechanism where the cloud security service node acts as an intermediary between the client and the destination server. The service node receives the destination server's certificate, validates it against trusted CAs, and presents a proxied certificate to the client that maintains the original server's identity. This intermediary approach enables content inspection while preserving authentication integrity and preventing man-in-the-middle attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary validation of the destination server's certificate before proxying it to the client. The cloud security service node verifies the certificate chain against trusted certificate authorities in advance, ensuring the original server's authenticity is confirmed before any content inspection or forwarding occurs. This preliminary action establishes trust before the inspection process begins.

Inventive Principle:
Principle #10Preliminary action

2Ease of manufacture

If cloud based security service nodes abort inspection when client certificate authentication is required, then ability to translate and sign client certificates is avoided, but content inspection completeness deteriorates

Engineering Contradiction:
Improvecertificate translation complexityVSAvoidcontent inspection completeness
Core Design Contradiction:
Ease of manufactureVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces a certificate proxying mechanism where the cloud security service node acts as an intermediary between the client and the destination server. The service node receives the destination server's certificate, validates it against trusted CAs, and presents a proxied certificate to the client that maintains the original server's identity. This intermediary approach enables content inspection while preserving authentication integrity and preventing man-in-the-middle attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary validation of the destination server's certificate before proxying it to the client. The cloud security service node verifies the certificate chain against trusted certificate authorities in advance, ensuring the original server's authenticity is confirmed before any content inspection or forwarding occurs. This preliminary action establishes trust before the inspection process begins.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If multiple client certificates are deployed for different services, then service-specific authentication is improved, but certificate management complexity increases

Engineering Contradiction:
Improveservice-specific authenticationVSAvoidcertificate management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal certificate management system where a single client certificate can be used to access multiple services. The cloud security service node maintains a mapping between services and their required certificate authorities, allowing one certificate to satisfy authentication requirements across multiple services that share the same trusted CA. This multi-functional approach reduces certificate management complexity while maintaining service-specific authentication through the service-to-CA mapping.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8869259B1Cloud based inspection of secure content avoiding man-in-the-middle attacks
Publication Date: 2014.10.21 ZSCALER INC
  • US8869259B1 patent drawing
  • US8869259B1 patent drawing
  • US8869259B1 patent drawing

AI summary

A cloud based system that facilitates inspection of secure content and inexpensively detects the presence of a Man-in-the-Middle attack in a client-server communication is disclosed. Through inspection of the server certificate, no Man-in-the-Middle attack between server and the system is ensured; through inspection and designation of the client certificate, absence of a Man-in-the-Middle attack between the cloud based system and the client is ensured. In this way, the cloud based system can perform its usual policy enforcement functions with respect to secure content while avoiding Man-in-the-Middle attacks.