WAN Optimization Device Session Key Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Optimizing secure network traffic is challenging for WAN optimization devices due to encryption and authentication protocols, which impede prefetching, caching, and compression processes, especially when the devices lack privileges to decrypt service tickets.

Innovation Solution

Implementing a system where WAN optimization devices intercept and transform network communications between clients and servers using session keys obtained without decrypting service tickets, leveraging trust relationships between domain controllers to secure key exchange and optimize network traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If WAN optimization devices perform prefetching, caching, and compression on secure network traffic, then network performance is improved, but security is compromised because the devices need decryption privileges

Engineering Contradiction:
Improvenetwork performanceVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a session key extraction mechanism that acts as an intermediary between the encrypted traffic and the optimization functions. The WAN optimization device extracts session keys from Kerberos authentication protocols without requiring full decryption privileges, enabling optimization operations while maintaining security boundaries. This intermediary approach allows the device to access only the minimal information needed for optimization without compromising the encrypted communication channel.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the optimization functions into two parts: those requiring decryption (performed only when privileges exist) and those that can operate with extracted session keys (performed when privileges are absent). This segmentation allows the system to dynamically adjust its optimization capabilities based on available security credentials, maintaining both performance and security requirements.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If WAN optimization devices obtain session keys by decrypting service tickets, then optimization capability is improved, but device complexity increases due to required decryption privileges

Engineering Contradiction:
Improveoptimization capabilityVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The session key extraction process serves as an intermediary that simplifies the device's requirements. Instead of needing full decryption privileges and complex key management infrastructure, the device uses extraction mechanisms that obtain session keys from the authentication protocol itself, reducing the complexity of privilege management while maintaining optimization capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service optimization by extracting session keys directly from the authentication traffic without requiring external key distribution infrastructure or complex privilege escalation mechanisms. The WAN optimization device autonomously obtains the necessary keys through protocol analysis, eliminating the need for complex administrative configurations and reducing device complexity.

Inventive Principle:
Principle #25Self-service

3Reliability

If WAN optimization devices operate without decryption privileges, then security is maintained, but optimization effectiveness deteriorates due to inability to access encrypted data

Engineering Contradiction:
ImprovesecurityVSAvoidoptimization effectiveness
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The session key extraction mechanism acts as an intermediary that bridges the gap between security requirements and optimization needs. By extracting session keys from the authentication protocol without compromising the encrypted channel, the system enables optimization functions to operate effectively while maintaining the security boundary that prevents unauthorized decryption of service tickets.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a functional copy of the session key information needed for optimization without copying the actual encrypted data. The extracted session keys enable the creation of optimized data representations (caches, compressed versions) that are functionally equivalent to the original encrypted data but can be processed without full decryption privileges, maintaining security while improving effectiveness.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9191201B1Optimizing secure communications
Publication Date: 2015.11.17 RIVERBED TECH LLC
  • US9191201B1 patent drawing
  • US9191201B1 patent drawing
  • US9191201B1 patent drawing

AI summary

Systems and techniques are described for optimizing secure communications. A client can use an authentication protocol, e.g., Kerberos, to authenticate with the server. Specifically, the client can obtain a service ticket from a ticket granting server, and then use the service ticket to authenticate with the server. The server can respond by providing an encrypted session key. The session key can then be used by the client and server to securely communicate with each other. A wide area network (WAN) optimization device described in this disclosure is capable of obtaining the session key without decrypting the service ticket. Specifically, the WAN optimization device can use information other than the service ticket to obtain the session key.