Interposer Security Assistant Key Escrow
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security solutions struggle to provide network service functions on encrypted application traffic without requiring the interposing device to hold private keying material, which is not feasible in all enterprise deployments, especially when the device is located outside the secure perimeter.
Innovation Solution
The implementation of a Security Assistant Key Escrow (SAKE) system that allows a network device to forward session initiation messages to a security assistant device in a secure location, enabling the device to decrypt encrypted sessions without holding private keys, thus allowing it to participate in the security flow without compromising security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the interposing device holds private keying material to decrypt encrypted sessions, then it can provide network service functions on encrypted traffic, but it cannot be deployed outside the secure perimeter
Solution Approach 1:
The patent extracts the private keying material from the interposing device and stores it exclusively in the security assistant device located within the secure perimeter. The interposing device outside the perimeter can still provide network service functions by receiving decryption assistance from the security assistant device without holding private keys locally, thus achieving deployment flexibility while maintaining security.
Solution Approach 2:
The security assistant device acts as an intermediary between the interposing device and the encrypted traffic. It receives decryption requests from the interposing device, performs the decryption using held private keys, and returns the decrypted data, enabling the interposing device to function without directly possessing sensitive keying material.
2Ease of operation
If the interposing device is located outside the secure perimeter for flexibility, then deployment is easier, but security is compromised in case of device theft
Solution Approach 1:
By extracting private keying material from the interposing device and storing it only in the security assistant device within the secure perimeter, the system allows the interposing device to be deployed anywhere (improving deployment ease) while eliminating the security breach risk associated with storing keys in externally deployed devices.
Solution Approach 2:
The interposing device can obtain temporary copies of decryption keys from the security assistant device when needed, use them to decrypt traffic, and then discard them. This allows the interposing device to perform its function without permanently storing sensitive keying material, thus enabling external deployment without security compromise.
3Productivity
If the network device proxies the security protocol to access plain text content, then it can provide network service functions, but it requires configuration with private keying material
Solution Approach 1:
The security assistant device serves as an intermediary that handles the complex security protocol proxying and private key management. The interposing device can provide network service functions on encrypted traffic by delegating the security protocol proxying tasks to the security assistant device, thus achieving functionality without the configuration complexity of managing private keys.
Data Source
AI summary
An interposer is provided that is configured to interpose into an application security protocol exchange by obtaining application session security state. The interposer does this without holding any private keying material of client or server. An out-of-band Security Assistant Key Escrow service (SAS/SAKE) is also provided. The SAKE resides in the secure physical network perimeter and holds the private keying material required to derive session keys for interposing into application security protocol. During a security protocol handshake, the interposer sends SAKE security protocol handshake messages and in return receives from the SAKE session security state that allows it to participate in application security protocol.


