SSL Handshake Mirroring for Backup Server Key Derivation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Transaction mirroring fails in secure sockets layer (SSL) protocol, as backup communications servers cannot continue secure communications without the shared secret key, leading to transaction loss when the active communications server fails.
Innovation Solution
Implementing a system where multiple communications servers, including an active and backup server, share a derived key from a common security value, allowing the backup server to mirror and continue secure communications with network devices using the same encryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If transaction mirroring is implemented with backup communications servers, then reliability is improved, but secure communications cannot be continued by backup servers due to lack of shared secret key
Solution Approach 1:
The patent applies preliminary action by pre-distributing the shared secret key to all communications servers including backup servers before any transaction occurs. This allows backup servers to immediately continue encrypted communications without needing to obtain the key after the active server fails, thus resolving the contradiction between reliability improvement and information loss.
2Object-affected harmful factors
If the shared secret is securely transmitted using public key infrastructure, then security is improved, but encryption overhead increases
Solution Approach 1:
The patent segments the cryptographic process into two phases: an initial key establishment phase using computationally intensive public key infrastructure to securely transmit the shared secret, and a subsequent communication phase using the pre-established shared secret for efficient symmetric encryption. This segmentation allows security to be maintained while reducing ongoing encryption overhead.
Solution Approach 2:
The shared secret is preliminarily established through public key infrastructure before actual communications begin. This preliminary action transfers the computational burden of key exchange to the initialization phase, allowing subsequent communications to use lighter-weight symmetric encryption with the pre-shared key, thus reducing encryption overhead while maintaining security.
Data Source
AI summary
A traffic manager system comprises communications servers, including one or more active and backup servers. At least one of the communications servers mirrors the communications of the other server involving one or more other network devices, including the encrypted communications. At least one backup server obtains a security value associated with the encrypted communications of at least one active server to independently derive the same key. The backup servers use the keys to engage in the encrypted communications when the active servers become unavailable, for example, without requiring the backup server to reinitiate the encrypted communications.


