SSL Offloader Decrypts Traffic for Load Balancing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
SSL traffic handling in data centers is inefficient due to high CPU utilization during encryption operations, security risks from exposing clear text traffic, and the inability of network-based intrusion detection systems to analyze encrypted traffic, leading to complex configurations and increased vulnerability to attacks.
Innovation Solution
Implementing a load balancer with an SSL offloader that decrypts HTTPS traffic, performs load balancing, and re-encrypts it without altering destination ports or parameters, allowing for secure handling and intrusion detection on decrypted traffic, thereby reducing CPU load and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If SSL encryption operations are performed on servers to secure traffic, then data confidentiality and integrity are improved, but CPU utilization increases significantly reducing transaction processing capacity
Solution Approach 1:
The patent extracts SSL encryption/decryption operations from the server system and places them in dedicated SSL appliances. This separation allows servers to focus on application processing while SSL appliances handle cryptographic operations, resolving the contradiction between maintaining data confidentiality and preserving transaction processing capacity.
Solution Approach 2:
The patent introduces SSL appliances as intermediary devices between clients and servers. These appliances perform SSL termination and re-encryption, acting as mediators that secure traffic without burdening server resources. The load balancer also serves as an intermediary that distributes encrypted traffic to multiple servers.
2Productivity
If clear text traffic is distributed to servers for load balancing, then load distribution efficiency is improved, but security is worsened due to exposure of decrypted traffic
Solution Approach 1:
The patent performs re-encryption of traffic immediately after load balancing decisions are made, before traffic is forwarded to servers. This preliminary action ensures that clear text exposure is minimized to only the necessary time window for load balancing, while security is restored before traffic leaves the load balancer.
3Difficulty of detecting and measuring
If SSL traffic is decrypted for intrusion detection, then security monitoring capability is improved, but traffic security is worsened during the decryption window
Solution Approach 1:
The patent performs re-encryption immediately after intrusion detection analysis is completed on the decrypted traffic. This ensures that the window of exposure during which traffic is in clear text form is minimized, allowing intrusion detection while rapidly restoring security.
Data Source
AI summary
A data center provides secure handling of HTTPS traffic using backend SSL decryption and encryption in combination with a load balancer such as a content switch. The load balancer detects HTTPS traffic and redirects it to an SSL offloading device for decryption and return to the load balancer. The load balancer then uses the clear text traffic for load balancing purposes before it redirects the traffic back to the SSL offloading device for re-encryption. Thereafter, the re-encrypted traffic is sent to the destination servers in the data center. In one embodiment, the combination with the back-end SSL with an intrusion detection system improves security by performing intrusion detection on the decrypted HTTPS traffic.


