WAN Optimization Device Session Key Extraction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Optimizing secure network traffic is challenging for WAN optimization devices due to encryption and authentication protocols, which impede prefetching, caching, and compression processes, especially when the devices lack privileges to decrypt service tickets.
Innovation Solution
Implementing a system where WAN optimization devices intercept and transform network communications between clients and servers using session keys obtained without decrypting service tickets, leveraging trust relationships between domain controllers to secure key exchange and optimize network traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If WAN optimization devices perform prefetching, caching, and compression on secure network traffic, then network performance is improved, but security is compromised because the devices need decryption privileges
Solution Approach 1:
The patent introduces a session key extraction mechanism that acts as an intermediary between the encrypted traffic and the optimization functions. The WAN optimization device extracts session keys from Kerberos authentication protocols without requiring full decryption privileges, enabling optimization operations while maintaining security boundaries. This intermediary approach allows the device to access only the minimal information needed for optimization without compromising the encrypted communication channel.
Solution Approach 2:
The patent segments the optimization functions into two parts: those requiring decryption (performed only when privileges exist) and those that can operate with extracted session keys (performed when privileges are absent). This segmentation allows the system to dynamically adjust its optimization capabilities based on available security credentials, maintaining both performance and security requirements.
2Adaptability or versatility
If WAN optimization devices obtain session keys by decrypting service tickets, then optimization capability is improved, but device complexity increases due to required decryption privileges
Solution Approach 1:
The session key extraction process serves as an intermediary that simplifies the device's requirements. Instead of needing full decryption privileges and complex key management infrastructure, the device uses extraction mechanisms that obtain session keys from the authentication protocol itself, reducing the complexity of privilege management while maintaining optimization capability.
Solution Approach 2:
The system enables self-service optimization by extracting session keys directly from the authentication traffic without requiring external key distribution infrastructure or complex privilege escalation mechanisms. The WAN optimization device autonomously obtains the necessary keys through protocol analysis, eliminating the need for complex administrative configurations and reducing device complexity.
3Reliability
If WAN optimization devices operate without decryption privileges, then security is maintained, but optimization effectiveness deteriorates due to inability to access encrypted data
Solution Approach 1:
The session key extraction mechanism acts as an intermediary that bridges the gap between security requirements and optimization needs. By extracting session keys from the authentication protocol without compromising the encrypted channel, the system enables optimization functions to operate effectively while maintaining the security boundary that prevents unauthorized decryption of service tickets.
Solution Approach 2:
The patent creates a functional copy of the session key information needed for optimization without copying the actual encrypted data. The extracted session keys enable the creation of optimized data representations (caches, compressed versions) that are functionally equivalent to the original encrypted data but can be processed without full decryption privileges, maintaining security while improving effectiveness.
Data Source
AI summary
Systems and techniques are described for optimizing secure communications. A client can use an authentication protocol, e.g., Kerberos, to authenticate with the server. Specifically, the client can obtain a service ticket from a ticket granting server, and then use the service ticket to authenticate with the server. The server can respond by providing an encrypted session key. The session key can then be used by the client and server to securely communicate with each other. A wide area network (WAN) optimization device described in this disclosure is capable of obtaining the session key without decrypting the service ticket. Specifically, the WAN optimization device can use information other than the service ticket to obtain the session key.


