SSL Offloader Decrypts Traffic for Load Balancing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

SSL traffic handling in data centers is inefficient due to high CPU utilization during encryption operations, security risks from exposing clear text traffic, and the inability of network-based intrusion detection systems to analyze encrypted traffic, leading to complex configurations and increased vulnerability to attacks.

Innovation Solution

Implementing a load balancer with an SSL offloader that decrypts HTTPS traffic, performs load balancing, and re-encrypts it without altering destination ports or parameters, allowing for secure handling and intrusion detection on decrypted traffic, thereby reducing CPU load and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SSL encryption operations are performed on servers to secure traffic, then data confidentiality and integrity are improved, but CPU utilization increases significantly reducing transaction processing capacity

Engineering Contradiction:
Improvedata confidentialityVSAvoidtransaction processing capacity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts SSL encryption/decryption operations from the server system and places them in dedicated SSL appliances. This separation allows servers to focus on application processing while SSL appliances handle cryptographic operations, resolving the contradiction between maintaining data confidentiality and preserving transaction processing capacity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces SSL appliances as intermediary devices between clients and servers. These appliances perform SSL termination and re-encryption, acting as mediators that secure traffic without burdening server resources. The load balancer also serves as an intermediary that distributes encrypted traffic to multiple servers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If clear text traffic is distributed to servers for load balancing, then load distribution efficiency is improved, but security is worsened due to exposure of decrypted traffic

Engineering Contradiction:
Improveload distribution efficiencyVSAvoidtraffic security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent performs re-encryption of traffic immediately after load balancing decisions are made, before traffic is forwarded to servers. This preliminary action ensures that clear text exposure is minimized to only the necessary time window for load balancing, while security is restored before traffic leaves the load balancer.

Inventive Principle:
Principle #10Preliminary action

3Difficulty of detecting and measuring

If SSL traffic is decrypted for intrusion detection, then security monitoring capability is improved, but traffic security is worsened during the decryption window

Engineering Contradiction:
Improveintrusion detection capabilityVSAvoidtraffic security
Core Design Contradiction:
Difficulty of detecting and measuringVSReliability

Solution Approach 1:

The patent performs re-encryption immediately after intrusion detection analysis is completed on the decrypted traffic. This ensures that the window of exposure during which traffic is in clear text form is minimized, allowing intrusion detection while rapidly restoring security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7657940B2System for SSL re-encryption after load balance
Publication Date: 2010.02.02 CISCO TECHNOLOGY INC
  • US7657940B2 patent drawing
  • US7657940B2 patent drawing
  • US7657940B2 patent drawing

AI summary

A data center provides secure handling of HTTPS traffic using backend SSL decryption and encryption in combination with a load balancer such as a content switch. The load balancer detects HTTPS traffic and redirects it to an SSL offloading device for decryption and return to the load balancer. The load balancer then uses the clear text traffic for load balancing purposes before it redirects the traffic back to the SSL offloading device for re-encryption. Thereafter, the re-encrypted traffic is sent to the destination servers in the data center. In one embodiment, the combination with the back-end SSL with an intrusion detection system improves security by performing intrusion detection on the decrypted HTTPS traffic.