TLS Terminating Node Key Distribution for HTTPS Inspection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network devices, such as SDWAN devices, lack the ability to inspect and manage HTTPS traffic due to their inability to decipher encrypted connections, limiting their Quality of Service (QoS) and policy enforcement capabilities, as they do not possess the necessary cryptographic information to decrypt TLS traffic.

Innovation Solution

A system and method that allows network devices to determine if a TLS connection is terminated by another device, obtain key generation information, and use it to decipher and inspect HTTPS traffic without installing a server certificate or terminating the secure connection, enabling them to perform traffic regulation and steering based on URL information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network devices do not act as a proxy for secure connections, then security and connection simplicity are maintained, but the ability to inspect and manage encrypted traffic is lost

Engineering Contradiction:
ImprovesecurityVSAvoidtraffic inspection capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a key distribution mechanism where the TLS terminating node acts as an intermediary that provides decryption keys to network devices. This allows the network device to inspect encrypted traffic without being a proxy, maintaining security while enabling traffic management. The key distribution system serves as the mediator between the TLS terminating node and the network device, allowing controlled access to decryption capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If network devices obtain cryptographic information to decrypt TLS traffic, then traffic inspection and policy enforcement capabilities are enhanced, but computational overhead and security risks increase

Engineering Contradiction:
Improvetraffic inspection capabilityVSAvoidcomputational overhead
Core Design Contradiction:
Ease of operationVSUse of energy by moving object

Solution Approach 1:

The patent extracts the computationally intensive TLS decryption and termination functions from the network device and relocates them to a dedicated TLS terminating node. The network device only receives already-decrypted traffic or minimal cryptographic material for selective inspection, rather than performing full TLS termination itself. This extraction of heavy computational tasks significantly reduces the energy and processing overhead on network devices while maintaining inspection capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If network devices intercept and decrypt traffic for inspection, then policy enforcement and QoS management are improved, but connection security and minimal intervention principles are compromised

Engineering Contradiction:
Improvepolicy enforcement capabilityVSAvoidconnection security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The TLS terminating node serves as a trusted intermediary that handles all decryption and security-sensitive operations. The network device acts as a secondary intermediary that receives selectively decrypted traffic for policy enforcement. This layered intermediary structure allows policy enforcement capabilities to be added without requiring the network device to directly intercept or compromise the original TLS connection, maintaining security through separation of duties.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11716314B2System and apparatus for enhanced QOS, steering and policy enforcement for HTTPS traffic via intelligent inline path discovery of TLS terminating node
Publication Date: 2023.08.01 CITRIX SYSTEMS INC
  • US11716314B2 patent drawing
  • US11716314B2 patent drawing
  • US11716314B2 patent drawing

AI summary

Described embodiments provide systems and apparatuses for enhanced quality of service, steering and policy enforcement for https traffic via intelligent in-line path discovery of a TLS terminating node. The system may include a first network device having a secure connection traversing through the first network device, and in communication with a second network device. The first network device and the second network device may be intermediary to a client device and a server. The first network device may determine that the second network device terminates the secure connection. The first network device may receive key generation information of the secure connection from the second network device following determining the second network device terminates the secure connection. The first network device may decipher packet(s) of the secure connection destined for the device or the server using the received key generation information, to regulate network traffic of the secure connection at the first network device.