Gateway TLS Inspection via Server Certificate Probing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current TLS/SSL inspection methods are imprecise, leading to potential security policy violations, as they rely on Server Name Indication (SNI) information that can be manipulated by malicious clients, resulting in incorrect routing of encrypted traffic.

Innovation Solution

A probing connection is established between the gateway and the server to verify the site identity through certificate authentication, ensuring precise inspection, bypass, or blocking decisions based on the verified server certificate, rather than relying solely on client-provided SNI information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If SNI information from client is used for inspection decision, then inspection decision can be made quickly, but security precision deteriorates due to potential manipulation by malicious clients

Engineering Contradiction:
Improveinspection decision timeVSAvoidsite identity identification accuracy
Core Design Contradiction:
Loss of timeVSMeasurement precision

Solution Approach 1:

The gateway performs a probing connection to the server in advance to obtain the actual site identity before making the final inspection decision. This preliminary action of verifying the server's certificate ensures that the inspection decision is based on accurate information rather than potentially manipulated client-provided SNI data, thus resolving the contradiction between quick decision-making and accurate identification.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If probing connection is established to verify server identity, then site identity identification accuracy is improved, but device complexity increases

Engineering Contradiction:
Improvesite identity identification accuracyVSAvoidgateway processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The probing connection acts as an intermediary verification mechanism between the gateway and the server. Instead of directly trusting client-provided information or implementing complex client verification protocols, the gateway establishes a separate probing connection to the server to obtain authoritative site identity information. This intermediary approach simplifies the overall system architecture while maintaining high identification accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11411924B2Method for performing TLS/SSL inspection based on verified subject name
Publication Date: 2022.08.09 CHECK POINT SOFTWARE TECH LTD
  • US11411924B2 patent drawing
  • US11411924B2 patent drawing
  • US11411924B2 patent drawing

AI summary

Methods and systems for processing cryptographically secured connections by a gateway, between a client and a server, are performed. Upon receiving TCP and TLS/SSL handshakes associated with a client side connection, from a client (client computer) to the gateway, a probing connection is established. The probing connection completes the handshakes, and based on the completion of the handshakes, the gateway renders a decision, to bypass, block or inspect, the connections between the client and the server, allowing or not allowing data to pass through the connections between the client and the server.