Proxy-Less SSL Inspection Appliance for Scalable TCP Flow Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network systems require clients to be configured with proxy IP addresses for secure connections, leading to scalability issues and difficulties with non-HTTP protocols, and conventional proxy-based solutions complicate TCP flow control and retransmission.

Innovation Solution

A proxy-less SSL inspection appliance intercepts client requests, generates a new certificate, decrypts and inspects data, and re-encrypts it without self-scheduling retransmissions, using client or server-side packet retransmission logic to maintain transparent and scalable secure connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a proxy is used for SSL connections, then secure data inspection is enabled, but device complexity and scalability deteriorate due to full TCP flow control logic being implemented on the inspecting device

Engineering Contradiction:
Improvesecure data inspectionVSAvoidTCP flow control logic
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the SSL inspection function from the traditional proxy architecture by implementing SSL termination at the network appliance level. The appliance intercepts SSL traffic, decrypts it, inspects the clear text, and re-encrypts it for forwarding to the actual server. This extraction eliminates the need for the appliance to implement full TCP flow control logic while maintaining secure inspection capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The network appliance serves as an intermediary between the client and the server, but unlike a traditional proxy, it operates at the network layer rather than implementing full TCP session management. The appliance mediates SSL termination and inspection without burdening itself with complex TCP flow control responsibilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a proxy is used for SSL connections, then data inspection capability is provided, but scalability deteriorates due to sockets not scaling well for large number of connections

Engineering Contradiction:
Improvedata inspection capabilityVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent replaces the traditional socket-based proxy architecture with a network appliance that operates at the network layer. This substitution eliminates the scalability limitations of socket-based connections by using packet-switched network communication instead of connection-oriented socket management, allowing the appliance to handle large numbers of concurrent connections efficiently.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If a proxy is used for SSL connections, then secure inspection is achieved, but ease of operation deteriorates due to client browser needing to be configured with proxy IP address

Engineering Contradiction:
Improvesecure inspectionVSAvoidclient configuration
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The network appliance performs self-service by automatically intercepting and inspecting SSL traffic without requiring client configuration. The appliance monitors network traffic, identifies SSL connections, and performs inspection autonomously, eliminating the need for clients to be configured with proxy IP addresses while maintaining secure inspection.

Inventive Principle:
Principle #25Self-service

4Reliability

If a proxy is used for SSL connections, then certificate inspection is enabled, but adaptability deteriorates due to difficulty in configuring for non-HTTP protocols

Engineering Contradiction:
Improvecertificate inspectionVSAvoidprotocol configuration
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The network appliance provides universal SSL inspection capability across multiple protocols by operating at the network layer rather than being protocol-specific. The appliance can inspect SSL traffic for various protocols (HTTP, FTP, SMTP, etc.) using the same inspection mechanism, eliminating the need for separate configuration for each protocol while maintaining comprehensive certificate inspection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12368703B2Proxy-less secure sockets layer (SSL) data inspection
Publication Date: 2025.07.22 SONICWALL US HOLDINGS INC
  • US12368703B2 patent drawing
  • US12368703B2 patent drawing
  • US12368703B2 patent drawing

AI summary

Some embodiments of proxy-less Secure Sockets Layer (SSL) data inspection have been presented. In one embodiment, a secured connection according to a secured network protocol between a client and a responder is setup via a gateway device, which is coupled between the client and the responder. The gateway device transparently intercepts data transmitted according to the secured network protocol between the client and the responder. Furthermore, the gateway device provides flow-control and retransmission of one or more data packets of the data without self-scheduling the packet retransmissions using timeouts and based on the packet retransmission logic of either the client-side or the responder side of the connection. The gateway device is further operable to perform security screening on the data.