Enforcing Policies on Encrypted Network Traffic
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security measures struggle to enforce policies on encrypted/encoded network communications, making it difficult for enterprises to manage and control legitimate traffic while preventing malicious activities.
Innovation Solution
A data appliance system that includes a cryptographic engine for SSL decryption and uses application identification engines to categorize traffic, allowing for granular policy enforcement even on encrypted communications by correlating DNS requests with network activity, enabling the differentiation of permitted and prohibited applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption techniques are used to protect communications, then security and confidentiality are improved, but the ability to enforce policies on communications deteriorates
Solution Approach 1:
The patent introduces an intermediary system (firewall/security appliance) positioned between the client device and the encrypted communication. This intermediary performs SSL/TLS decryption to inspect the encrypted traffic, allowing policy enforcement while maintaining the security benefits of encryption. The intermediary acts as a mediator that can read the encrypted content without requiring the communication endpoints to change their encryption behavior.
Solution Approach 2:
The patent segments the network security function by separating the encryption/decryption operations from the policy enforcement decisions. The decryption is performed at a specific segment (the firewall appliance), and then the decrypted content is inspected for policy violations. This segmentation allows encryption to remain in place while still enabling policy control through the decryption point.
2Ease of operation
If SSL decryption is performed to enable policy enforcement, then policy enforcement capability is improved, but device complexity increases
Solution Approach 1:
The patent places the complex SSL decryption functionality in a dedicated intermediary device (firewall or security appliance) rather than requiring complexity at every network endpoint. This centralized intermediary handles the cryptographic operations, keeping the overall system architecture manageable while enabling policy enforcement on encrypted traffic.
Solution Approach 2:
The patent makes the intermediary device multi-functional by combining SSL/TLS decryption capabilities with policy enforcement and traffic inspection functions in a single system. This universal device performs multiple tasks (decryption, inspection, decision-making, and traffic control) that would otherwise require separate systems, thereby managing complexity through consolidation rather than multiplication.
Data Source
AI summary
Network traffic collectively associated with a set of communications made between a client device and a respective first and second resource during a usage of a program executed on the client device is monitored. At least of the monitored traffic associated with the second resource is encrypted. The encrypted traffic is categorized. A respective first and second policy to apply to the respective first and second communications is determined. The second policy is based at least in part on the categorization of the encrypted traffic.


