Proxy Server SSL Certificate Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for deploying domain-specific security policies in secure environments, such as healthcare and financial sectors, face challenges in scalability and require manual pre-programming or modification of registry settings on thousands of computers, which is inefficient and labor-intensive.

Innovation Solution

Deploying security gateways that create replacement SSL server certificates with application-specific extensions in an X.509v3 digital certificate profile, allowing a proxy server to intercept and manage outbound connections, verify server identities, and transmit digitally-signed policies to clients, thereby regulating application functionality.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If registry settings are modified on each computer to enforce security policies, then policy enforcement capability is improved, but deployment complexity and administrative burden increase significantly

Engineering Contradiction:
Improvepolicy enforcement capabilityVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a proxy server as an intermediary between clients and external servers. The proxy server creates and manages replacement SSL certificates containing policy information, eliminating the need to modify registry settings on each client computer. Clients simply connect to the proxy server, which automatically enforces policies through the certificate-based mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates replacement copies of SSL server certificates that contain embedded policy information. Instead of modifying each client computer's registry, the proxy server generates alternative certificates that clients use for secure connections, thereby copying and distributing policy enforcement capability through the certificate infrastructure.

Inventive Principle:
Principle #26Copying

2Adaptability or versatility

If software clients are pre-programmed to access active directory for policy information, then centralized policy management is improved, but software flexibility and adaptability decrease

Engineering Contradiction:
Improvecentralized policy managementVSAvoidsoftware pre-programming requirement
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent makes SSL certificates serve multiple functions: their traditional role in establishing secure connections and an additional role of carrying policy information through custom extensions. This eliminates the need for specialized pre-programmed clients that query active directory, as any SSL-capable client can automatically receive and enforce policies through the certificate.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If manual registry modification is performed on thousands of computers to deploy security policies, then policy coverage is improved, but time consumption and labor requirements increase

Engineering Contradiction:
Improvepolicy coverageVSAvoiddeployment efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent performs preliminary action by configuring security policies in advance within the replacement SSL certificates at the proxy server. When clients connect, they automatically receive pre-configured policy information embedded in the certificates, eliminating the need for manual, computer-by-computer deployment and achieving immediate organization-wide policy coverage.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9231983B2Methods and systems for providing trusted signaling of domain-specific security policies
Publication Date: 2016.01.05 GOTO GRP INC
  • US9231983B2 patent drawing
  • US9231983B2 patent drawing

AI summary

Methods and systems for providing trusted signaling of domain-specific security policies. One method includes intercepting a connection request to a remote server from a client device on a domain and returning a security certificate with policy information for regulating the communications with the target server.