Enforcing Policies on Encrypted Network Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security measures struggle to enforce policies on encrypted/encoded network communications, making it difficult for enterprises to manage and control legitimate traffic while preventing malicious activities.

Innovation Solution

A data appliance system that includes a cryptographic engine for SSL decryption and uses application identification engines to categorize traffic, allowing for granular policy enforcement even on encrypted communications by correlating DNS requests with network activity, enabling the differentiation of permitted and prohibited applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption techniques are used to protect communications, then security and confidentiality are improved, but the ability to enforce policies on communications deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidpolicy enforcement capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary system (firewall/security appliance) positioned between the client device and the encrypted communication. This intermediary performs SSL/TLS decryption to inspect the encrypted traffic, allowing policy enforcement while maintaining the security benefits of encryption. The intermediary acts as a mediator that can read the encrypted content without requiring the communication endpoints to change their encryption behavior.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network security function by separating the encryption/decryption operations from the policy enforcement decisions. The decryption is performed at a specific segment (the firewall appliance), and then the decrypted content is inspected for policy violations. This segmentation allows encryption to remain in place while still enabling policy control through the decryption point.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If SSL decryption is performed to enable policy enforcement, then policy enforcement capability is improved, but device complexity increases

Engineering Contradiction:
Improvepolicy enforcement capabilityVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent places the complex SSL decryption functionality in a dedicated intermediary device (firewall or security appliance) rather than requiring complexity at every network endpoint. This centralized intermediary handles the cryptographic operations, keeping the overall system architecture manageable while enabling policy enforcement on encrypted traffic.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent makes the intermediary device multi-functional by combining SSL/TLS decryption capabilities with policy enforcement and traffic inspection functions in a single system. This universal device performs multiple tasks (decryption, inspection, decision-making, and traffic control) that would otherwise require separate systems, thereby managing complexity through consolidation rather than multiplication.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12095728B2Identifying security risks and enforcing policies on encrypted/encoded network communications
Publication Date: 2024.09.17 PALO ALTO NETWORKS INC
  • US12095728B2 patent drawing
  • US12095728B2 patent drawing
  • US12095728B2 patent drawing

AI summary

Network traffic collectively associated with a set of communications made between a client device and a respective first and second resource during a usage of a program executed on the client device is monitored. At least of the monitored traffic associated with the second resource is encrypted. The encrypted traffic is categorized. A respective first and second policy to apply to the respective first and second communications is determined. The second policy is based at least in part on the categorization of the encrypted traffic.