Endpoint Trust Attestation for Encrypted Traffic Inspection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network security infrastructures struggle to effectively verify and inspect encrypted application layer traffic without slowing down traffic flows or accessing confidential information, as direct inspection is impractical and often provides inferior security functions.
Innovation Solution
Implementing collaborative security methods that establish trust between devices and network infrastructure using trust anchors, allowing for efficient traffic processing and policy enforcement by negotiating appropriate inspection methods based on device and application trustworthiness, such as through attestation and metadata verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If direct inspection of encrypted traffic is performed, then security verification capability is improved, but traffic flow speed deteriorates and confidential information is exposed
Solution Approach 1:
The patent extracts only the necessary trust verification elements (attestation tokens, metadata) from the encrypted traffic flow for inspection, rather than decrypting or inspecting the entire traffic. This allows security verification while maintaining traffic flow speed and protecting confidential information.
Solution Approach 2:
Instead of the network infrastructure actively inspecting encrypted traffic by decrypting it, the patent inverts the approach by having endpoint devices proactively provide trust evidence (attestations) to the network infrastructure. This eliminates the need for active decryption and inspection while maintaining security verification.
2Reliability
If application layer traffic is encrypted with application specific trust stores and custom SSL stacks, then application security is improved, but network security infrastructure verification capability deteriorates
Solution Approach 1:
The patent creates a universal attestation framework that works across different application-specific encryption schemes and custom SSL stacks. The standardized attestation tokens and metadata can be verified by network security infrastructure regardless of the specific application layer encryption used, enabling broad verification capability while maintaining application security.
3Reliability
If traffic flow is intercepted and decrypted for inspection, then security inspection capability is improved, but traffic flow continuity deteriorates
Solution Approach 1:
The patent extracts only the essential trust verification data (attestation tokens, metadata) from the traffic flow for inspection, leaving the main encrypted traffic flow intact and uninterrupted. This maintains both security inspection capability and traffic flow continuity.
Solution Approach 2:
The patent performs trust verification in advance by checking attestation tokens and metadata before allowing traffic to flow through the network infrastructure. This preliminary verification eliminates the need for later interception and decryption, maintaining traffic flow continuity while ensuring security.
Data Source
AI summary
A non-transitory computer readable medium comprising instructions stored thereon, the instructions effective to cause at least one processor to: establish trustworthiness of an application installed on a endpoint, the established trustworthiness is sufficient for an enterprise security infrastructure to treat the application installed on the endpoint and the endpoint as a trusted application and a trusted endpoint; negotiate with the trusted endpoint to determine a traffic inspection method for traffic flows originating at the trusted application that is destined for a service, the traffic inspection method is determined based on at least the trusted application, and the service; and instruct the trusted application of the determined traffic inspection method.


