Interposer Security Assistant Key Escrow

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security solutions struggle to provide network service functions on encrypted application traffic without requiring the interposing device to hold private keying material, which is not feasible in all enterprise deployments, especially when the device is located outside the secure perimeter.

Innovation Solution

The implementation of a Security Assistant Key Escrow (SAKE) system that allows a network device to forward session initiation messages to a security assistant device in a secure location, enabling the device to decrypt encrypted sessions without holding private keys, thus allowing it to participate in the security flow without compromising security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the interposing device holds private keying material to decrypt encrypted sessions, then it can provide network service functions on encrypted traffic, but it cannot be deployed outside the secure perimeter

Engineering Contradiction:
Improvedeployment flexibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent extracts the private keying material from the interposing device and stores it exclusively in the security assistant device located within the secure perimeter. The interposing device outside the perimeter can still provide network service functions by receiving decryption assistance from the security assistant device without holding private keys locally, thus achieving deployment flexibility while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The security assistant device acts as an intermediary between the interposing device and the encrypted traffic. It receives decryption requests from the interposing device, performs the decryption using held private keys, and returns the decrypted data, enabling the interposing device to function without directly possessing sensitive keying material.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the interposing device is located outside the secure perimeter for flexibility, then deployment is easier, but security is compromised in case of device theft

Engineering Contradiction:
Improvedeployment easeVSAvoidsecurity breach risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

By extracting private keying material from the interposing device and storing it only in the security assistant device within the secure perimeter, the system allows the interposing device to be deployed anywhere (improving deployment ease) while eliminating the security breach risk associated with storing keys in externally deployed devices.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The interposing device can obtain temporary copies of decryption keys from the security assistant device when needed, use them to decrypt traffic, and then discard them. This allows the interposing device to perform its function without permanently storing sensitive keying material, thus enabling external deployment without security compromise.

Inventive Principle:
Principle #26Copying

3Productivity

If the network device proxies the security protocol to access plain text content, then it can provide network service functions, but it requires configuration with private keying material

Engineering Contradiction:
Improvenetwork service function capabilityVSAvoidconfiguration complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The security assistant device serves as an intermediary that handles the complex security protocol proxying and private key management. The interposing device can provide network service functions on encrypted traffic by delegating the security protocol proxying tasks to the security assistant device, thus achieving functionality without the configuration complexity of managing private keys.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10178181B2Interposer with security assistant key escrow
Publication Date: 2019.01.08 CISCO TECHNOLOGY INC
  • US10178181B2 patent drawing
  • US10178181B2 patent drawing
  • US10178181B2 patent drawing

AI summary

An interposer is provided that is configured to interpose into an application security protocol exchange by obtaining application session security state. The interposer does this without holding any private keying material of client or server. An out-of-band Security Assistant Key Escrow service (SAS/SAKE) is also provided. The SAKE resides in the secure physical network perimeter and holds the private keying material required to derive session keys for interposing into application security protocol. During a security protocol handshake, the interposer sends SAKE security protocol handshake messages and in return receives from the SAKE session security state that allows it to participate in application security protocol.