Gateway TLS Inspection via Server Certificate Probing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current TLS/SSL inspection methods are imprecise, leading to potential security policy violations, as they rely on Server Name Indication (SNI) information that can be manipulated by malicious clients, resulting in incorrect routing of encrypted traffic.
Innovation Solution
A probing connection is established between the gateway and the server to verify the site identity through certificate authentication, ensuring precise inspection, bypass, or blocking decisions based on the verified server certificate, rather than relying solely on client-provided SNI information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of time
If SNI information from client is used for inspection decision, then inspection decision can be made quickly, but security precision deteriorates due to potential manipulation by malicious clients
Solution Approach 1:
The gateway performs a probing connection to the server in advance to obtain the actual site identity before making the final inspection decision. This preliminary action of verifying the server's certificate ensures that the inspection decision is based on accurate information rather than potentially manipulated client-provided SNI data, thus resolving the contradiction between quick decision-making and accurate identification.
2Measurement precision
If probing connection is established to verify server identity, then site identity identification accuracy is improved, but device complexity increases
Solution Approach 1:
The probing connection acts as an intermediary verification mechanism between the gateway and the server. Instead of directly trusting client-provided information or implementing complex client verification protocols, the gateway establishes a separate probing connection to the server to obtain authoritative site identity information. This intermediary approach simplifies the overall system architecture while maintaining high identification accuracy.
Data Source
AI summary
Methods and systems for processing cryptographically secured connections by a gateway, between a client and a server, are performed. Upon receiving TCP and TLS/SSL handshakes associated with a client side connection, from a client (client computer) to the gateway, a probing connection is established. The probing connection completes the handshakes, and based on the completion of the handshakes, the gateway renders a decision, to bypass, block or inspect, the connections between the client and the server, allowing or not allowing data to pass through the connections between the client and the server.


