IP Library Granted Patent US 9,413,728
Granted Patent B2
US 9,413,728 · App. 14/446,710 · Granted Aug 9, 2016

Identifying content from an encrypted communication

Inventor: Yuji Watanabe (Tokyo, JP)
Assignee: GLOBALFOUNDRIES INC.
H04L63/0428G06F17/30241H04L63/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,413,728
App. No.
14/446,710
Granted
Aug 9, 2016
Kind
B2
Abstract

Provided is an identifying device for identifying request content from an encrypted request to a server, the identifying device including: a target acquiring unit for acquiring the data size of an encrypted response returned from the server for the encrypted request to the server to be identified; a candidate acquiring unit for acquiring the data size of each of a plurality of encrypted response candidates returned by the server in response to a plurality of encrypted request candidates to be identified sent to the server corresponding to a plurality of known request content candidates; and an identifying unit for identifying the request content to be identified from the plurality of request candidates on the basis of results obtained by comparing the data size of an encrypted response for an encrypted request to be identified to the data sizes of a plurality of encrypted response candidates.

Claims (45)

1. A method for identifying request content of an encrypted request message communicated over a network from a client device to a server device, the method comprising the steps of:

receiving, at one or more computer processors, an encrypted response message communicated over said network by the server device in response to the encrypted request message received at said server device;

determining at one or more computer processors one or more of: a data size, a response time, a location information, or a character string of the received encrypted response message;

receiving, at the one or more computer processors, a plurality of encrypted response message candidates communicated over said network by the server corresponding to a plurality of known encrypted request message candidates received at said server device;

determining at one or more computer processors one or more of: a data size, a response time, a location information, or a character string of each of the received plurality of encrypted response message candidates; and

identifying, by the one or more computer processors, content of the encrypted request message by comparing the one or more of: the data size, the response time, the location information, or the character string of the encrypted response message to the respective one or more of: the data size, the response time, the location information, or the character string of each of the plurality of encrypted response message candidates.

2. The method of claim 1 , further comprising:

receiving, at the one or more computer processors a further plurality of encrypted response messages communicated over said network by the server corresponding to a further plurality of encrypted request messages received at said server device; and

determining at the one or more computer processors one or more of: a data size, a response time, a location information, or a character string of each of the received further plurality of encrypted response messages; wherein

said identifying content of the encrypted request message comprises:

identifying, at the one or more computer processors, content of each of the further plurality of encrypted request messages by comparing one or more of: the data size, the response time, the location information, or the character string of each of the further plurality of encrypted response messages to the respective one or more of: the data size, the response time, the location information, or the character string of each of the plurality of encrypted response message candidates.

3. The method of claim 2 : wherein the determining at one or more computer processors of one or more of a data size, a response time, a location information, or a character string of each of the received further plurality of encrypted response messages comprises:

determining a first information about a first encrypted response message communicated over said network by the server device corresponding to a first encrypted request message received at said server device and a second information about a second encrypted response message communicated over said network by the server device corresponding to a second encrypted request message received at said server device, the first information and second information comprising one or more of: a data size, a response time, a location information, or a character string;

wherein the identifying the content of each of the further plurality of encrypted request messages comprises:

identifying, at the one or more computer processors, a first content of the first encrypted response message corresponding to the first encrypted request message by comparing the first information about the first encrypted response message to the one or more of: a data size, a response time, a location information, or a character string of each of the plurality of encrypted response message candidates and identifying at the one or more computer processors a second content of the second encrypted response message corresponding to the second encrypted request message by comparing the second information about the second encrypted response message to the one or more of: a data size, a response time, a location information, or a character string of each of the plurality of encrypted response message candidates; and further comprising the step of identifying, by one or more computer processors, content that is included in both of the first content and the second content.

4. A non-transitory computer program product for identifying request content of an encrypted request message communicated over a network from a client device to a server device, the computer program product comprising:

one or more storage devices; and program instructions stored on the one or more storage devices, the program instructions comprising:

program instructions to receive, from a server, an encrypted response message communicated over said network by the server device in response to the encrypted request message received at said server device;

program instructions to determine one or more of: a data size, a response time, a location information, or a character string of the received encrypted response message;

program instructions to receive, from the server, a plurality of encrypted response message candidates communicated over said network by the server device corresponding to a plurality of known encrypted request message candidates;

program instructions to determine one or more of a data size, a response time, a location information, or a character string of each of the received plurality of encrypted response message candidates; and

program instructions to identify content of the encrypted request message by comparing the one or more of: the data size, the response time, the location information, or the character string of the encrypted response to the respective one or more of: the data size, the response time, the location information, or the character string of each of the plurality of encrypted response message candidates.

5. The non-transitory computer program product of claim 4 , further comprising:

program instructions to receive, from the server, a further plurality of encrypted response messages communicated over said network by said server corresponding to a further plurality of encrypted request messages received at the service;

program instructions to determine one or more of: a data size, a response time, a location information, or a character string of each of the received further plurality of encrypted response messages; wherein the program instructions to identify content of the encrypted request message comprises:

program instructions to identify content of each of the further plurality of encrypted request messages by comparing one or more of: the data size, the response time, the location information, or the character string of each of the further plurality of encrypted response messages to the respective one or more of: the data size, the response time, the location information, or the character string of each of the plurality of encrypted response message candidates.

6. The non-transitory computer program product of claim 5 : wherein the program instructions to determine at one or more computer processors of one or more of: a data size, a response time, a location information, or a character string of each of the received further plurality of encrypted response messages comprises:

program instructions to determine a first information about a first encrypted response message communicated over said network by the server device corresponding to a first encrypted request message received at said server device and a second information about a second encrypted response message communicated over said network by the server device corresponding to a second encrypted request message received at said server device, the first information and second information comprising one or more of: a data size, a response time, a location information, or a character string;

wherein the program instructions to identify the content of each of the further plurality of encrypted request messages comprises:

program instructions to identify a first content of the first encrypted response corresponding to the first encrypted request by comparing the first information about the first encrypted response message to the one or more of: a data size, a response time, a location information, or a character string of each of the plurality of encrypted response message candidates and identify a second content of the second encrypted response message corresponding to the second encrypted request message by comparing the second information about the second encrypted response message to the one or more of: a data size, a response time, a location information, or a character string of each of the plurality of encrypted response message candidates; and further comprising program instructions, stored on the one or more storage devices, to identify content that is included in both of the first content and the second content.

7. A computer system for identifying request content of an encrypted request message communicated over a network from a client device to a server device, the computer system comprising:

one or more computer processors; one or more storage devices; and program instructions, stored on the one or more storage devices for execution by the one or more computer processors, the program instructions comprising:

program instructions to receive, from a server, an encrypted response message communicated over said network by the server device in response to the encrypted request message received at said server device;

program instructions to determine one or more of: a data size, a response time, a location information, or a character string of the received encrypted response message;

program instructions to receive, from the server, a plurality of encrypted response message candidates communicated over said network by the server device corresponding to a plurality of known encrypted request message candidates;

program instructions to determine one or more of: a data size, a response time, a location information, or a character string of each of the received plurality of encrypted response message candidates; and

program instructions to identify content of the encrypted request message by comparing the one or more of: the data size, the response time, the location information, or the character string of the encrypted response to the respective one or more of: the data size, the response time, the location information, or the character string of each of the plurality of encrypted response message candidates.

8. The computer system of claim 7 , further comprising:

program instructions to receive, from the server, a further plurality of encrypted response messages communicated over said network by said server corresponding to a further plurality of encrypted request messages received at the service;

program instructions to determine one or more of: a data size, a response time, a location information, or a character string of each of the received further plurality of encrypted response messages; wherein

the program instructions to identify content of the encrypted request message comprises:

program instructions to identify content of each of the further plurality of encrypted request messages by comparing one or more of: the data size, the response time, the location information, or the character string of each of the further plurality of encrypted response messages to the respective one or more of: the data size, the response time, the location information, or the character string of each of the plurality of encrypted response message candidates.

9. The computer system of claim 8 , wherein the program instructions to determine at one or more computer processors of one or more of a data size, a response time, a location information, or a character string of each of the received further plurality of encrypted response messages comprises: program instructions to determine a first information about a first encrypted response message communicated over said network by the server device corresponding to a first encrypted request message received at said server device and a second information about a second encrypted response message communicated over said network by the server device corresponding to a second encrypted request message received at said server device, the first information and second information comprising one or more of: a data size, a response time, a location information, or a character string;

wherein the program instructions to identify the content of each of the further plurality of encrypted request messages comprises:

program instructions to identify a first content of the first encrypted response message corresponding to the first encrypted request message by comparing the first information about the first encrypted response message to the one or more of: the data size, the response time, the location information, or the character string of each of the plurality of encrypted response message candidates and identify a second content of the second encrypted response message corresponding to the second encrypted request message by comparing the second information about the second encrypted response message to the one or more of the data size, the response time, the location information, or the character string of each of the plurality of encrypted response message candidates; and further comprising program instructions, stored on the one or more storage devices for execution by at least one of the one or more computer processors, to identify content that is included in both of the first content and the second content.

Assignments (7)
RELEASE OF SECURITY INTEREST Recorded May 12, 2021
From: WILMINGTON TRUST, NATIONAL ASSOCIATION
To: GLOBALFOUNDRIES U.S. INC.
Reel/Frame 056987/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 20, 2020
From: WILMINGTON TRUST, NATIONAL ASSOCIATION
To: GLOBALFOUNDRIES INC.
Reel/Frame 054636/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 2, 2020
From: GLOBALFOUNDRIES INC.
To: GLOBALFOUNDRIES U.S. INC.
Reel/Frame 054633/0001 →
SECURITY AGREEMENT Recorded Nov 29, 2018
From: GLOBALFOUNDRIES INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 049490/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 5, 2015
From: GLOBALFOUNDRIES U.S. 2 LLC; GLOBALFOUNDRIES U.S. INC.
To: GLOBALFOUNDRIES INC.
Reel/Frame 036779/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 3, 2015
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: GLOBALFOUNDRIES U.S. 2 LLC
Reel/Frame 036550/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 30, 2014
From: WATANABE, YUJI
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 033422/0463 →
Priority Claims (1)
JP 2013160560 · Aug 1, 2013 · national
Continuity (1)
Related Publication 20150039882A1 · Feb 5, 2015