Proxy Device Granular Offloading Secure Session Inspection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current TLS/SSL proxy devices face performance issues due to processor-intensive decryption and re-encryption processes, leading to inefficient resource usage and reduced throughput, as they often need to decrypt and re-encrypt all encrypted traffic even when no security inspection is required.
Innovation Solution
Implementing a proxy device that dynamically offloads secure sessions by bypassing decryption and re-encryption for data messages until a specific condition is met, such as a threshold of data being inspected or a particular event occurring, allowing for granular control over when security services apply their inspections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the proxy device decrypts and re-encrypts all encrypted traffic to apply security services, then security inspection effectiveness is improved, but processor resource usage increases and throughput decreases
Solution Approach 1:
The patent applies partial action by selectively decrypting only specific portions of encrypted traffic that require security inspection, rather than decrypting all traffic. The proxy device determines whether decryption is necessary based on traffic analysis, applying security services only when needed, thus maintaining security effectiveness while reducing processor overhead and improving throughput.
2Reliability
If the proxy device decrypts and re-encrypts all encrypted traffic, then security services can inspect all traffic, but processor resource usage increases
Solution Approach 1:
The proxy device performs partial decryption only on traffic segments that require security inspection, determined through traffic analysis. This approach ensures comprehensive security coverage for necessary traffic while minimizing processor resource consumption by avoiding unnecessary decryption of traffic that does not require inspection.
3Reliability
If the proxy device continuously decrypts and re-encrypts traffic throughout the secure session, then security inspection is maintained, but performance deteriorates
Solution Approach 1:
The patent implements dynamic offloading by adjusting the decryption and security inspection process during the secure session based on real-time traffic analysis. The proxy device can dynamically switch between decrypting and forwarding traffic without decryption, allowing security inspection continuity when needed while improving session throughput when inspection is not required.
Solution Approach 2:
The proxy device applies security inspection partially throughout the session, determining on-demand whether decryption is necessary for each traffic segment. This dynamic partial inspection approach maintains security coverage where needed while eliminating unnecessary decryption operations that would deteriorate performance.
Data Source
Figure 1A
Figure 1B
Figure 1C
AI summary
A device may receive encrypted traffic associated with a secure session. The device may determine, based on the encrypted traffic, information associated with an offload service to be applied to the encrypted traffic associated with the secure session. The information associated with the offload service may indicate whether the encrypted traffic is permitted to bypass inspection by one or more security services. The device may selectively permit the encrypted traffic, associated with the secure session, to bypass inspection by the one or more security services based on the information associated with the offload service.