Security Gateway SSL Session Key Extraction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing deep-inspection-based network security appliances cannot detect attacks within encrypted secure communication sessions, and conventional SSL interception-based solutions require private server certificates, which are often not accepted by businesses or users.
Innovation Solution
A system that establishes secure sessions using a security gateway and storage unit, allowing clients and servers to exchange key secrets and calculate a session key without needing private server certificates, enabling secure communication and threat detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If SSL encryption is used for secure communication sessions, then data security is improved, but network security appliances cannot detect attacks within encrypted data
Solution Approach 1:
The patent introduces a security gateway as an intermediary component that acts as a man-in-the-middle to establish separate SSL sessions with both the client and the server. This gateway can decrypt and inspect encrypted traffic by establishing its own SSL connections, allowing attack detection while maintaining end-to-end encryption between client and server without requiring them to trust each other directly
2Difficulty of detecting and measuring
If conventional SSL interception-based solutions are used, then attack detection capability is improved, but private server certificates are required which are often not accepted by businesses or users
Solution Approach 1:
The security gateway serves as a mediator that handles certificate management internally, allowing it to establish SSL sessions with both client and server using its own certificates. This eliminates the need for businesses to obtain and manage private server certificates, as the gateway performs the interception and inspection functions using its own cryptographic credentials
3Difficulty of detecting and measuring
If deep-inspection-based network security appliances are used, then they cannot examine encrypted data, but the patent enables examination of encrypted data packets through session key calculation
Solution Approach 1:
The security gateway acts as an intermediary that calculates the session key used by the client and server to encrypt their communication. By obtaining this session key through its intermediary position in the SSL handshake process, the gateway can decrypt and inspect encrypted data packets while the client and server continue to communicate securely without knowing about the gateway's presence
Solution Approach 2:
The patent extracts the session key from the SSL handshake process between client and server. The security gateway obtains the session key that is normally kept private between the communicating parties, allowing it to extract and examine the encrypted content of their communications without disrupting the security of their direct connection
Data Source
AI summary
Provided are methods and systems for establishing secure sessions. A method for establishing secure sessions may commence with receiving a request to establish a secure session between a client and a server. Client security parameters may be provided in client extension fields of the request. The method may include forwarding the request to the server and receiving a secure session response from the server. Server security parameters may be provided in server extension fields of the secure session response. The method may include receiving a server key secret, forwarding the secure session response and the server key secret to the client, receiving a client key secret, and forwarding the client key secret to the server. The method may continue with calculating a session key and establishing a first secure session between the security gateway and the server and a second secure session between the security gateway and the client.


