Split-Terminating Secure Network Connections for Client Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing secure communication protocols, such as SSL and TLS, hinder transaction acceleration due to their inability to participate in client authentication schemes, often ignoring or using substitute certificates, which fail to authenticate unique client attributes and distinguish between multiple clients.
Innovation Solution
A method and apparatus for establishing a secure client-server communication connection using split-termination at intermediate network devices that can cooperate to optimize communications, where intermediaries observe and store handshaking messages, compute the session key, and participate in the connection to authenticate clients and servers transparently.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If traditional transaction acceleration methods are used, then network communication performance is improved, but client authentication capability is lost or compromised
Solution Approach 1:
The patent segments the authentication process into two distinct phases: certificate validation (performed by the transaction accelerator) and client attribute authentication (performed by the server). This allows the accelerator to optimize traffic while the server maintains authenticating capability through server-to-client certificate validation and attribute verification.
Solution Approach 2:
The server acts as an intermediary that receives authenticated client certificates from the transaction accelerator and performs additional authentication of client attributes. This intermediary role enables the accelerator to handle traffic optimization while the server ensures authentic identification of unique clients.
2Productivity
If substitute certificates are used for client authentication, then transaction acceleration is enabled, but unique client attribute authentication fails
Solution Approach 1:
The patent replaces the mechanical substitution of certificates with a cryptographic validation mechanism. The server validates client certificates and extracts authentication information through structured validation processes, enabling precise identification of unique client attributes without substituting certificates.
Solution Approach 2:
The patent changes the authentication parameters from static certificate substitution to dynamic certificate validation with attribute extraction. The server validates multiple certificate parameters and extracts client attributes, enabling precise authentication while maintaining transaction acceleration.
3Adaptability or versatility
If multiple substitute certificates are applied for different client classes, then some authentication is possible, but server cannot distinguish between multiple clients
Solution Approach 1:
The patent implements feedback mechanisms where the server validates client certificates and extracts authentication information, then uses this information to distinguish between multiple clients. The server receives authenticated client identifiers and uses them to maintain accurate client distinction throughout the communication session.
Solution Approach 2:
The server performs multiple functions: validating certificates, extracting client attributes, and distinguishing between multiple clients. This multi-functional approach enables both client class authentication and precise client identification without relying on multiple substitute certificates.
Data Source
AI summary
A method and apparatus are provided for split-terminating a secure client-server communication connection, with client authentication. During handshaking between the client and the server, cooperating network intermediaries relay the handshaking messages, without altering the messages. At least one of the intermediaries possesses a private key of the server, and extracts a set of data fields from the handshaking messages, including a Client-Key-Exchange message that can be decrypted with the private key. The intermediary uses the extracted data to compute the client-server session key separate from the client's and the server's similar computation, and may transmit the key to the other intermediary via a secure communication channel. The client and the server thus establish the end-to-end client-server connection, and may authenticate each other, after which the network intermediaries may intercept and optimize the client-server communications transparently to the client and the server.


