TLS Terminating Node Key Distribution for HTTPS Inspection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network devices, such as SDWAN devices, lack the ability to inspect and manage HTTPS traffic due to their inability to decipher encrypted connections, limiting their Quality of Service (QoS) and policy enforcement capabilities, as they do not possess the necessary cryptographic information to decrypt TLS traffic.
Innovation Solution
A system and method that allows network devices to determine if a TLS connection is terminated by another device, obtain key generation information, and use it to decipher and inspect HTTPS traffic without installing a server certificate or terminating the secure connection, enabling them to perform traffic regulation and steering based on URL information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network devices do not act as a proxy for secure connections, then security and connection simplicity are maintained, but the ability to inspect and manage encrypted traffic is lost
Solution Approach 1:
The patent introduces a key distribution mechanism where the TLS terminating node acts as an intermediary that provides decryption keys to network devices. This allows the network device to inspect encrypted traffic without being a proxy, maintaining security while enabling traffic management. The key distribution system serves as the mediator between the TLS terminating node and the network device, allowing controlled access to decryption capabilities.
2Ease of operation
If network devices obtain cryptographic information to decrypt TLS traffic, then traffic inspection and policy enforcement capabilities are enhanced, but computational overhead and security risks increase
Solution Approach 1:
The patent extracts the computationally intensive TLS decryption and termination functions from the network device and relocates them to a dedicated TLS terminating node. The network device only receives already-decrypted traffic or minimal cryptographic material for selective inspection, rather than performing full TLS termination itself. This extraction of heavy computational tasks significantly reduces the energy and processing overhead on network devices while maintaining inspection capabilities.
3Ease of operation
If network devices intercept and decrypt traffic for inspection, then policy enforcement and QoS management are improved, but connection security and minimal intervention principles are compromised
Solution Approach 1:
The TLS terminating node serves as a trusted intermediary that handles all decryption and security-sensitive operations. The network device acts as a secondary intermediary that receives selectively decrypted traffic for policy enforcement. This layered intermediary structure allows policy enforcement capabilities to be added without requiring the network device to directly intercept or compromise the original TLS connection, maintaining security through separation of duties.
Data Source
AI summary
Described embodiments provide systems and apparatuses for enhanced quality of service, steering and policy enforcement for https traffic via intelligent in-line path discovery of a TLS terminating node. The system may include a first network device having a secure connection traversing through the first network device, and in communication with a second network device. The first network device and the second network device may be intermediary to a client device and a server. The first network device may determine that the second network device terminates the secure connection. The first network device may receive key generation information of the secure connection from the second network device following determining the second network device terminates the secure connection. The first network device may decipher packet(s) of the secure connection destined for the device or the server using the received key generation information, to regulate network traffic of the secure connection at the first network device.


