Proxy Device Granular Offloading Secure Session Inspection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current TLS/SSL proxy devices face performance issues due to processor-intensive decryption and re-encryption processes, leading to inefficient resource usage and reduced throughput, as they often need to decrypt and re-encrypt all encrypted traffic even when no security inspection is required.

Innovation Solution

Implementing a proxy device that dynamically offloads secure sessions by bypassing decryption and re-encryption for data messages until a specific condition is met, such as a threshold of data being inspected or a particular event occurring, allowing for granular control over when security services apply their inspections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the proxy device decrypts and re-encrypts all encrypted traffic to apply security services, then security inspection effectiveness is improved, but processor resource usage increases and throughput decreases

Engineering Contradiction:
Improvesecurity inspection effectivenessVSAvoidthroughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies partial action by selectively decrypting only specific portions of encrypted traffic that require security inspection, rather than decrypting all traffic. The proxy device determines whether decryption is necessary based on traffic analysis, applying security services only when needed, thus maintaining security effectiveness while reducing processor overhead and improving throughput.

Inventive Principle:
Principle #16Partial or excessive action

2Reliability

If the proxy device decrypts and re-encrypts all encrypted traffic, then security services can inspect all traffic, but processor resource usage increases

Engineering Contradiction:
Improvesecurity service inspection coverageVSAvoidprocessor resource usage
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The proxy device performs partial decryption only on traffic segments that require security inspection, determined through traffic analysis. This approach ensures comprehensive security coverage for necessary traffic while minimizing processor resource consumption by avoiding unnecessary decryption of traffic that does not require inspection.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If the proxy device continuously decrypts and re-encrypts traffic throughout the secure session, then security inspection is maintained, but performance deteriorates

Engineering Contradiction:
Improvesecurity inspection continuityVSAvoidsession throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic offloading by adjusting the decryption and security inspection process during the secure session based on real-time traffic analysis. The proxy device can dynamically switch between decrypting and forwarding traffic without decryption, allowing security inspection continuity when needed while improving session throughput when inspection is not required.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The proxy device applies security inspection partially throughout the session, determining on-demand whether decryption is necessary for each traffic segment. This dynamic partial inspection approach maintains security coverage where needed while eliminating unnecessary decryption operations that would deteriorate performance.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP3687138B1Granular offloading of a proxied secure session
Publication Date: 2024.07.31 JUNIPER NETWORKS INC
  • EP3687138B1 patent drawingFigure 1A
  • EP3687138B1 patent drawingFigure 1B
  • EP3687138B1 patent drawingFigure 1C

AI summary

A device may receive encrypted traffic associated with a secure session. The device may determine, based on the encrypted traffic, information associated with an offload service to be applied to the encrypted traffic associated with the secure session. The information associated with the offload service may indicate whether the encrypted traffic is permitted to bypass inspection by one or more security services. The device may selectively permit the encrypted traffic, associated with the secure session, to bypass inspection by the one or more security services based on the information associated with the offload service.