IP Library Granted Patent US 9,565,180
Granted Patent B2
US 9,565,180 · App. 13/631,646 · Granted Feb 7, 2017

Exchange of digital certificates in a client-proxy-server network configuration

Inventors: Srinivas Yerra (Sunnyvale, CA); Krists Krilovs (Santa Clara, CA); Dharmendra Mohan (Sunyvale, CA); Ron Frederick (Mountain View, CA); Tammy Green (Provo, UT)
Assignee: Symantec Corporation
H04L63/0823H04L9/3202H04L9/3265H04L9/3271H04L2209/76
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,565,180
App. No.
13/631,646
Granted
Feb 7, 2017
Kind
B2
Abstract

Various techniques are described to authenticate the identity of a proxy in a client-proxy-server configuration. The configuration may have a client-side and a server-side SSL session. In the server-side session, if the proxy has access to the private keys of the client, the proxy may select a client certificate from a collection of client certificates and send the selected certificate to the server to satisfy a client authentication request of the server. If the proxy does not have access to the private keys, the proxy may instead send an emulated client certificate to the server. Further, the client certificate received from the client may be embedded within the emulated client certificate so as to allow the server to directly authenticate the client, in addition to the proxy. An emulated client certificate chain may be formed instead of an emulated client certificate. Similar techniques may be applied to the client-side session.

Claims (35)

1. A method for providing a client certificate from a proxy to a server, the proxy communicatively coupled between a client and the server, the method comprising:

configuring at the proxy a collection of one or more client certificates and one or more client private keys, each client certificate corresponding to a client private key;

defining a policy at the proxy which selects one of the client certificates based on information associated with an identity of the client;

in response to a request from the server to the proxy to authenticate the identity of the client, selecting one of the client certificates based on the defined policy; and

transmitting the selected client certificate from the proxy to the server.

2. The method of claim 1 , wherein one of the client certificates is selected further based on one or more of a group that the client belongs to, a URL of the server, a network address of the server, and field values of a server certificate.

3. The method of claim 1 , wherein one of the client certificates is selected further based on a user group associated with the client.

4. The method of claim 1 , further comprising securely sending one or more client certificates and their associated private keys from the client to the proxy.

5. A method for providing a client certificate from a proxy to a server, the proxy communicatively coupled between a client and the server, the method comprising:

authenticating an identity of the client at the proxy;

configuring at the proxy a collection of one or more client certificates and one or more client private keys, each client certificate corresponding to a client private key;

defining a policy at the proxy which selects one of the client certificates based on information associated with the identity of the client;

receiving at the proxy a request from the client to connect to the server;

transmitting a request from the proxy to the server to establish a connection between the proxy and the server;

providing from the proxy to the client an emulated server certificate to allow man-in-the-middle interception;

in response to a request from the server to authenticate the identity of the client, selecting one of the client certificates based on the defined policy; and

transmitting the selected client certificate from the proxy to the server.

6. A method for providing an emulated server certificate from a proxy to a client, the proxy communicatively coupled between the client and a server, the method comprising:

in response to a request from the client to the proxy to authenticate an identity of the server, sending a request from the proxy to the server for a server certificate, which binds a public key of the server with the identity of the server;

generating a key pair having a private key and public key;

generating an emulated server certificate based on the server certificate, the emulated server certificate containing the public key generated at the proxy instead of the public key of the server;

embedding the server certificate in a field within the emulated server certificate;

signing the emulated server certificate; and

transmitting the emulated server certificate from the proxy to the client.

7. The method of claim 6 , wherein the server certificate is embedded in an nsComment field of the emulated server certificate.

8. The method of claim 7 , further comprising the client verifying an identity of the proxy via the emulated server certificate and verifying the identity of the server via the embedded server certificate.

9. A method for providing an emulated client certificate from a proxy to a server, the proxy communicatively coupled between a client and the server, the method comprising:

in response to a request from the server to the proxy to authenticate an identity of the client, sending a request from the proxy to the client for a client certificate, which binds a public key of the client with the identity of the client;

generating a key pair having a private key and public key;

generating an emulated client certificate based on the client certificate, the emulated client certificate containing the public key generated at the proxy instead of the public key of the client;

embedding the client certificate in a field within the emulated client certificate;

signing the emulated client certificate; and

transmitting the emulated client certificate from the proxy to the server.

10. The method of claim 9 , wherein the client certificate is embedded in an nsComment field of the emulated client certificate.

11. The method of claim 9 , further comprising the server verifying an identity of the proxy via the emulated client certificate and verifying the identity of the client via the embedded client certificate.

Assignments (10)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2016
From: BLUE COAT SYSTEMS, INC.
To: SYMANTEC CORPORATION
Reel/Frame 039851/0044 →
RELEASE OF SECURITY INTEREST Recorded Aug 1, 2016
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 039516/0929 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 15, 2016
From: MOHAN, DHARMENDRA
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 037976/0176 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 30740/0181 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 035797/0280 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 30521/0271 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 035797/0877 →
SECURITY INTEREST Recorded May 22, 2015
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS THE COLLATERAL AGENT
Reel/Frame 035751/0348 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 3, 2013
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 030740/0181 →
PATENT SECURITY AGREEMENT Recorded May 31, 2013
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 030521/0271 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 18, 2012
From: YERRA, SRINIVAS; KRILOVS, KRISTS; MOHAN, SHARMENDRA; FREDERICK, RON; GREEN, TAMMY
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 029494/0878 →
Continuity (1)
Related Publication 20140095865A1 · Apr 3, 2014