Endpoint Trust Attestation for Encrypted Traffic Inspection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network security infrastructures struggle to effectively verify and inspect encrypted application layer traffic without slowing down traffic flows or accessing confidential information, as direct inspection is impractical and often provides inferior security functions.

Innovation Solution

Implementing collaborative security methods that establish trust between devices and network infrastructure using trust anchors, allowing for efficient traffic processing and policy enforcement by negotiating appropriate inspection methods based on device and application trustworthiness, such as through attestation and metadata verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If direct inspection of encrypted traffic is performed, then security verification capability is improved, but traffic flow speed deteriorates and confidential information is exposed

Engineering Contradiction:
Improvesecurity verification capabilityVSAvoidtraffic flow speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent extracts only the necessary trust verification elements (attestation tokens, metadata) from the encrypted traffic flow for inspection, rather than decrypting or inspecting the entire traffic. This allows security verification while maintaining traffic flow speed and protecting confidential information.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of the network infrastructure actively inspecting encrypted traffic by decrypting it, the patent inverts the approach by having endpoint devices proactively provide trust evidence (attestations) to the network infrastructure. This eliminates the need for active decryption and inspection while maintaining security verification.

Inventive Principle:
Principle #13The other way round (Inversion)

2Reliability

If application layer traffic is encrypted with application specific trust stores and custom SSL stacks, then application security is improved, but network security infrastructure verification capability deteriorates

Engineering Contradiction:
Improveapplication securityVSAvoidnetwork security infrastructure verification capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal attestation framework that works across different application-specific encryption schemes and custom SSL stacks. The standardized attestation tokens and metadata can be verified by network security infrastructure regardless of the specific application layer encryption used, enabling broad verification capability while maintaining application security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If traffic flow is intercepted and decrypted for inspection, then security inspection capability is improved, but traffic flow continuity deteriorates

Engineering Contradiction:
Improvesecurity inspection capabilityVSAvoidtraffic flow continuity
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The patent extracts only the essential trust verification data (attestation tokens, metadata) from the traffic flow for inspection, leaving the main encrypted traffic flow intact and uninterrupted. This maintains both security inspection capability and traffic flow continuity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs trust verification in advance by checking attestation tokens and metadata before allowing traffic to flow through the network infrastructure. This preliminary verification eliminates the need for later interception and decryption, maintaining traffic flow continuity while ensuring security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11570213B2Collaborative security for application layer encryption
Publication Date: 2023.01.31 CISCO TECHNOLOGY INC
  • US11570213B2 patent drawing
  • US11570213B2 patent drawing
  • US11570213B2 patent drawing

AI summary

A non-transitory computer readable medium comprising instructions stored thereon, the instructions effective to cause at least one processor to: establish trustworthiness of an application installed on a endpoint, the established trustworthiness is sufficient for an enterprise security infrastructure to treat the application installed on the endpoint and the endpoint as a trusted application and a trusted endpoint; negotiate with the trusted endpoint to determine a traffic inspection method for traffic flows originating at the trusted application that is destined for a service, the traffic inspection method is determined based on at least the trusted application, and the service; and instruct the trusted application of the determined traffic inspection method.