IP Library Granted Patent US 10,341,357
Granted Patent B2
US 10,341,357 · App. 14/265,540 · Granted Jul 2, 2019

Selectively performing man in the middle decryption

Inventor: Paul Michael Martini (San Diego, CA)
Assignee: iboss, Inc.
H04L63/107H04L63/0471H04L63/1466H04L63/306H04L61/1511
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,341,357
App. No.
14/265,540
Granted
Jul 2, 2019
Kind
B2
Abstract

A device within the network receives a domain name service (DNS) request for an address of a first resource outside the network, the first resource associated with a security policy of the network. An address of a second resource within the network is returned to the device within the network in response the DNS request, the second resource address having previously been associated with the first resource address. A first encrypted connection is established between the device and the second resource, and a second encrypted connection is established between the second resource and the first resource, to facilitate encrypted communication traffic between the device and the first resource. The encrypted communication traffic passing between the device and the first resource is selectively decrypted and inspected depending on the address of the first resource.

Claims (56)

1. A method performed by data processing apparatus, the method comprising:

receiving, from a device within a network, a domain name service (DNS) request for an address of a first resource outside the network;

determining that the first resource is associated with a security policy of the network that specifies decrypting encrypted traffic between the device within the network and the first resource;

responsive to the determination that the first resource is associated with a security policy of the network that specifies decrypting encrypted traffic between the device within the network and the first resource, returning, to the device within the network in response the DNS request, a DNS response comprising an address of a gateway within the network, the gateway address having previously been associated with the first resource address;

establishing a first encrypted connection between the device and the gateway, and a second encrypted connection between the gateway and the first resource, to facilitate encrypted communication traffic between the device and the first resource;

decrypting, by the gateway, all of the encrypted communication traffic passing between the device and the first resource such that all of the encrypted communication traffic passing between the device and the first resource is available to the gateway for inspection; and

inspecting at least some of the encrypted communication traffic passing between the device and the first resource;

receiving, from a second device within the network, a second domain name service (DNS) request for an address of a second resource outside the network;

determining that the second resource is not associated with a security policy of the network that specifies decrypting encrypted traffic between the second device with the network and the second resource;

responsive to the determination that the second resource is not associated with a security policy of the network that specifies decrypting encrypted traffic between the second device and the second resource, sending, to the DNS, the second DNS request;

receiving, from the DNS, a DNS response;

returning, to the second device within the network and in response to receiving the second DNS request, the second DNS request; and

establishing a third encrypted connection between the second device and the second resource, to facilitate encrypted communication traffic between the second device and the second resource.

2. The method of claim 1 , wherein the address of the first resource is determined by the gateway based on the address returned in the DNS response.

3. The method of claim 1 , wherein decrypting and inspecting the encrypted communication traffic includes blocking the encrypted communication traffic.

4. The method of claim 1 , the method further comprising selecting the gateway from a plurality of available devices within the network.

5. The method of claim 4 , wherein the gateway is selected based on a comparison of the first resource with a rule defining destinations associated with encrypted communication traffic.

6. The method of claim 4 , wherein the gateway is selected based on hardware performance.

7. A non-transitory computer storage media encoded with computer program instructions that, when executed by one or more processors, cause a computer device to perform operations comprising:

receiving, from a device within a network, a domain name service (DNS) request for an address of a first resource outside the network;

determining that the first resource is associated with a security policy of the network that specifies decrypting encrypted traffic between the device within the network and the first resource;

responsive to the determination that the first resource is associated with a security policy of the network that specifies decrypting encrypted traffic between the device within the network and the first resource, returning, to the device within the network in response the DNS request, a DNS response comprising an address of a gateway within the network, the gateway address having previously been associated with the first resource address;

establishing a first encrypted connection between the device and the gateway, and a second encrypted connection between the gateway and the first resource, to facilitate encrypted communication traffic between the device and the first resource;

decrypting, by the gateway, all of the encrypted communication traffic passing between the device and the first resource such that all of the encrypted communication traffic passing between the device and the first resource is available to the gateway for inspection; and

inspecting at least some of the encrypted communication traffic passing between the device and the first resource;

receiving, from a second device within the network, a second domain name service (DNS) request for an address of a second resource outside the network;

determining that the second resource is not associated with a security policy of the network that specifies decrypting encrypted traffic between the second device with the network and the second resource;

responsive to the determination that the second resource is not associated with a security policy of the network that specifies decrypting encrypted traffic between the second device and the second resource, sending, to the DNS, the second DNS request;

receiving, from the DNS, a DNS response;

returning, to the second device within the network and in response to receiving the second DNS request, the second DNS request; and

establishing a third encrypted connection between the second device and the second resource, to facilitate encrypted communication traffic between the second device and the second resource.

8. The computer storage media of claim 7 , wherein the address of the first resource is determined by the gateway based on the address returned in the DNS response.

9. The computer storage media of claim 7 , wherein decrypting and inspecting the encrypted communication traffic includes blocking the encrypted communication traffic.

10. The computer storage media of claim 7 , wherein the operations further comprise selecting the gateway from a plurality of available devices within the network.

11. The computer storage media of claim 10 , wherein the gateway is selected based on a comparison of the first resource with a rule defining destinations associated with encrypted communication traffic.

12. The computer storage media of claim 10 , wherein the gateway is selected based on hardware performance.

13. A system comprising:

one or more processors configured to execute computer program instructions; and

non-transitory computer storage media encoded with computer program instructions that, when executed by one or more processors, cause a computer device to perform operations comprising:

receiving, from a device within a network, a domain name service (DNS) request for an address of a first resource outside the network;

determining that the first resource is associated with a security policy of the network that specifies decrypting encrypted traffic between the device within the network and the first resource;

responsive to the determination that the first resource is associated with a security policy of the network that specifies decrypting encrypted traffic between the device within the network and the first resource, returning, to the device within the network in response the DNS request, a DNS response comprising an address of a gateway within the network, the gateway address having previously been associated with the first resource address;

establishing a first encrypted connection between the device and the gateway, and a second encrypted connection between the gateway and the first resource, to facilitate encrypted communication traffic between the device and the first resource;

decrypting, by the gateway, all of the encrypted communication traffic passing between the device and the first resource such that all of the encrypted communication traffic passing between the device and the first resource is available to the gateway for inspection; and

inspecting at least some of the encrypted communication traffic passing between the device and the first resource;

receiving, from a second device within the network, a second domain name service (DNS) request for an address of a second resource outside the network;

determining that the second resource is not associated with a security policy of the network that specifies decrypting encrypted traffic between the second device with the network and the second resource;

responsive to the determination that the second resource is not associated with a security policy of the network that specifies decrypting encrypted traffic between the second device and the second resource, sending, to the DNS, the second DNS request;

receiving, from the DNS, a DNS response;

returning, to the second device within the network and in response to receiving the second DNS request, the second DNS request; and

establishing a third encrypted connection between the second device and the second resource, to facilitate encrypted communication traffic between the second device and the second resource.

14. The system of claim 13 , wherein the address of the first resource is determined by the gateway based on the address returned in the DNS response.

15. The system of claim 13 , wherein decrypting and inspecting the encrypted communication traffic includes blocking the encrypted communication traffic.

16. The system of claim 13 , wherein the operations further comprise selecting the gateway from a plurality of available devices within the network.

17. The system of claim 16 , wherein the gateway is selected based on a comparison of the first resource with a rule defining destinations associated with encrypted communication traffic.

18. The system of claim 16 , wherein the gateway is selected based on hardware performance.

Assignments (6)
SUPPLEMENTAL INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 28, 2023
From: IBOSS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 066158/0266 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 28, 2023
From: IBOSS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 066158/0219 →
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Dec 12, 2023
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK TRUST COMPANY
To: IBOSS, INC.
Reel/Frame 066140/0480 →
SECURITY INTEREST Recorded Sep 19, 2022
From: IBOSS, INC.
To: SILICON VALLEY BANK
Reel/Frame 061463/0331 →
SECURITY INTEREST Recorded Dec 16, 2020
From: IBOSS, INC.
To: SILICON VALLEY BANK
Reel/Frame 054789/0680 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 22, 2014
From: MARTINI, PAUL MICHAEL
To: IBOSS, INC.
Reel/Frame 033791/0756 →
Continuity (2)
Continuation 13865850 · Apr 18, 2013
Related Publication 20140317397A1 · Oct 23, 2014
Cited By (1)
US 12,368,703