Encryption-Aware Visibility Device for Encrypted Traffic Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Active SSL inspection methods introduce performance bottlenecks in monitoring encrypted network traffic due to the need for decrypting and re-encrypting SSL traffic, which is computationally expensive and resource-intensive.

Innovation Solution

An encryption-aware visibility (EAV) device receives session decryption information from a secure session management server via a secure backchannel interface, allowing it to decrypt encrypted network traffic flows without acting as a man-in-the-middle, thereby reducing processing overhead.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If active SSL inspection is used to monitor encrypted traffic, then network visibility is improved, but processing performance deteriorates due to decrypting and re-encrypting overhead

Engineering Contradiction:
Improvenetwork visibilityVSAvoidprocessing performance
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The patent extracts the SSL decryption function from the network monitoring device and places it on a separate SSL server. The monitoring device only receives decrypted traffic from the SSL server, eliminating the need for it to perform computationally expensive decrypting and re-encrypting operations while maintaining full network visibility.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an SSL server as an intermediary component between the encrypted traffic source and the network monitoring device. This SSL server acts as a mediator that handles all SSL decryption and re-encryption operations, allowing the monitoring device to focus solely on analyzing decrypted traffic without performance degradation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If SSL traffic is decrypted and re-encrypted by a MITM device, then clear-text copying for monitoring is achieved, but resource consumption increases

Engineering Contradiction:
Improveclear-text accessVSAvoidcomputational resources
Core Design Contradiction:
Loss of informationVSUse of energy by moving object

Solution Approach 1:

The patent extracts the computationally intensive SSL decryption and re-encryption operations from the network monitoring device and relocates them to a dedicated SSL server. This separation allows the monitoring device to access clear-text traffic without bearing the computational burden of SSL processing.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The SSL server autonomously handles all SSL decryption and re-encryption operations without requiring the network monitoring device to intervene in the SSL processing chain. The SSL server serves itself by managing the cryptographic operations and providing decrypted traffic to monitoring tools.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10992652B2Methods, systems, and computer readable media for monitoring encrypted network traffic flows
Publication Date: 2021.04.27 KEYSIGHT TECH SINGAPORE (SALES) PTE LTD
  • US10992652B2 patent drawing
  • US10992652B2 patent drawing
  • US10992652B2 patent drawing

AI summary

Methods, systems, and computer readable media for monitoring encrypted packet communications are disclosed. According to one method executed at an encryption aware visibility (EAV) device, the method includes receiving copies of encrypted network traffic flow records belonging to at least one communication session involving a monitored application and obtaining, from a secure session management (SSM) server, session decryption information (SDI) via a secure backchannel interface connection, wherein the session decryption information includes cryptographic keys generated by the SSM server to establish the at least one communication session. The method further includes using the cryptographic keys to decrypt the copies of encrypted network traffic flow records to produce decrypted network traffic flow records.