Split-Terminating Secure Network Connections for Client Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure communication protocols, such as SSL and TLS, hinder transaction acceleration due to their inability to participate in client authentication schemes, often ignoring or using substitute certificates, which fail to authenticate unique client attributes and distinguish between multiple clients.

Innovation Solution

A method and apparatus for establishing a secure client-server communication connection using split-termination at intermediate network devices that can cooperate to optimize communications, where intermediaries observe and store handshaking messages, compute the session key, and participate in the connection to authenticate clients and servers transparently.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traditional transaction acceleration methods are used, then network communication performance is improved, but client authentication capability is lost or compromised

Engineering Contradiction:
Improvenetwork communication performanceVSAvoidclient authentication capability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the authentication process into two distinct phases: certificate validation (performed by the transaction accelerator) and client attribute authentication (performed by the server). This allows the accelerator to optimize traffic while the server maintains authenticating capability through server-to-client certificate validation and attribute verification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The server acts as an intermediary that receives authenticated client certificates from the transaction accelerator and performs additional authentication of client attributes. This intermediary role enables the accelerator to handle traffic optimization while the server ensures authentic identification of unique clients.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If substitute certificates are used for client authentication, then transaction acceleration is enabled, but unique client attribute authentication fails

Engineering Contradiction:
Improvetransaction accelerationVSAvoidunique client attribute authentication
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent replaces the mechanical substitution of certificates with a cryptographic validation mechanism. The server validates client certificates and extracts authentication information through structured validation processes, enabling precise identification of unique client attributes without substituting certificates.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the authentication parameters from static certificate substitution to dynamic certificate validation with attribute extraction. The server validates multiple certificate parameters and extracts client attributes, enabling precise authentication while maintaining transaction acceleration.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If multiple substitute certificates are applied for different client classes, then some authentication is possible, but server cannot distinguish between multiple clients

Engineering Contradiction:
Improveclient class authenticationVSAvoidclient distinction capability
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The patent implements feedback mechanisms where the server validates client certificates and extracts authentication information, then uses this information to distinguish between multiple clients. The server receives authenticated client identifiers and uses them to maintain accurate client distinction throughout the communication session.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The server performs multiple functions: validating certificates, extracting client attributes, and distinguishing between multiple clients. This multi-functional approach enables both client class authentication and precise client identification without relying on multiple substitute certificates.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8438628B2Method and apparatus for split-terminating a secure network connection, with client authentication
Publication Date: 2013.05.07 RIVERBED TECH LLC
  • US8438628B2 patent drawing
  • US8438628B2 patent drawing
  • US8438628B2 patent drawing

AI summary

A method and apparatus are provided for split-terminating a secure client-server communication connection, with client authentication. During handshaking between the client and the server, cooperating network intermediaries relay the handshaking messages, without altering the messages. At least one of the intermediaries possesses a private key of the server, and extracts a set of data fields from the handshaking messages, including a Client-Key-Exchange message that can be decrypted with the private key. The intermediary uses the extracted data to compute the client-server session key separate from the client's and the server's similar computation, and may transmit the key to the other intermediary via a secure communication channel. The client and the server thus establish the end-to-end client-server connection, and may authenticate each other, after which the network intermediaries may intercept and optimize the client-server communications transparently to the client and the server.