Traffic Management Device Proxy SSL Handoff
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing secure communications in client-server end-to-end encrypted connections is challenging, especially when a server device needs to be replaced or lacks necessary information, as traditional methods fail to efficiently handle endpoint changes within these secure sessions.
Innovation Solution
A traffic management device (TMD) intercepts and renegotiates the encrypted connection, allowing seamless transition from one server endpoint to another without disrupting the secure session, using SSL renegotiation protocols to maintain encryption and trust relationships.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a server device is replaced in an end-to-end encrypted connection, then the system can handle server failures or information needs, but the encrypted session is disrupted and security trust relationships are broken
Solution Approach 1:
The patent introduces a traffic management device as an intermediary that intercepts SSL/TLS handshake messages between the client and server. This mediator captures the encrypted session information, enables server replacement, and maintains continuous encrypted communication without breaking the trust relationship, thus resolving the contradiction between server replacement needs and session continuity.
2Adaptability or versatility
If traditional SSL/TLS session management is used, then secure communication is established, but server replacement or endpoint changes cannot be performed without disrupting the session
Solution Approach 1:
The traffic management device acts as a mediator that simplifies endpoint replacement by intercepting and managing SSL/TLS handshake messages. It captures session information, facilitates seamless server switching, and maintains encrypted communication continuity, thereby enabling adaptable endpoint replacement without increasing management complexity for end users.
3Adaptability or versatility
If an encrypted session is terminated and re-established with a new server, then the new server can be connected, but time is lost and security trust must be re-built
Solution Approach 1:
The traffic management device performs preliminary actions by intercepting and capturing SSL/TLS handshake messages during the initial connection establishment. It stores the encrypted session information in advance, enabling rapid server switching without requiring time-consuming session re-establishment, thus reducing the time loss when replacing servers while maintaining security trust relationships.
Data Source
AI summary
A traffic management device (TMD), system, and processor-readable storage medium directed towards re-establishing an encrypted connection of an encrypted session, the encrypted connection having initially been established between a client device and a first server device, causing the encrypted connection to terminate at a second server device. As described, a traffic management device (TMD) is interposed between the client device and the first server device. In some embodiments, the TMD may request that the client device renegotiate the encrypted connection. The TMD may redirect the response to the renegotiation request towards a second server device, such that the renegotiated encrypted connection is established between the client device and the second server device. In this way, a single existing end-to-end encrypted connection can be used to serve content from more than one server device


