IP Library Granted Patent US 9,485,228
Granted Patent B2
US 9,485,228 · App. 14/845,169 · Granted Nov 1, 2016

Selectively performing man in the middle decryption

Inventor: Paul Michael Martini (San Diego, CA)
Assignee: iboss, Inc.
H04L63/0428H04L63/0281H04L63/0464H04L63/20H04L63/168H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,485,228
App. No.
14/845,169
Granted
Nov 1, 2016
Kind
B2
Abstract

Methods, systems, and apparatus, including computer programs encoded on computer storage media, for selectively performing man in the middle decryption. One of the methods includes receiving a first request to access a first resource hosted by a server outside the network, determining whether requests from the client device to access the first resource outside the network should be redirected to a second resource hosted by a proxy within the network, providing a redirect response to the client device, the redirect response including the second universal resource identifier, establishing a first encrypted connected between the client device and the proxy hosting the second resource, and a second encrypted connection between the proxy hosting the second domain and the server hosting the first resource, and decrypting and inspecting the encrypted communication traffic passing between the client device and the server hosting the first resource.

Claims (72)

1. A method performed by data apparatus, the method comprising:

presenting, on a device, a display region within a graphical user interface;

receiving, from a user, input to navigate to a first universal resource identifier that identifies a first resource;

transmitting, by the device, a first request, the first request including the first universal resource identifier;

receiving, by the device, a redirect response that includes a second universal resource identifier, the second universal resource identifier comprising a domain associated with a man-in-the-middle gateway and further comprising at least a portion of the first universal resource identifier;

displaying, by the device to the user, at least the domain associated with the man-in-the-middle gateway in response to receiving, from the user, the input; and

transmitting, by the device, a second request to access the first resource, the second request including the second universal resource identifier.

2. The method of claim 1 , wherein transmitting the second request to access the first resource causes:

establishment of a first encrypted connection between the device and the man-in-the-middle gateway, and a second encrypted connection between the man-in-the-middle gateway and a server hosting the first resource, to facilitate encrypted communication traffic between the device and the server hosting the resource; and

decryption and inspection of the encrypted communication traffic passing between the device and the server hosting the resource.

3. The method of claim 1 , wherein the first request further includes a cookie associated with the resource and the first universal resource identifier; and

wherein the method further comprises receiving, by the device, a second cookie associated with the resource and the second universal resource identifier.

4. The method of claim 1 , the method further comprising:

receiving, by the device, instructions for presentation to the user with a notification regarding redirection from the first universal resource identifier to the second universal resource identifier; and

presenting, to the user, the notification.

5. The method of claim 1 , the method further comprises:

presenting, by the device, a user interface element to receive input from the user to continue with the redirections; and

wherein the second request is transmitted responsive to receiving the input from the user to continue with the redirection.

6. The method of claim 1 , wherein a web browser comprises the graphical user interface.

7. The method of claim 1 , the method further comprising:

receiving, from a user, second input to navigate to a third universal resource identifier that identifies a second resource;

transmitting, by the device, a third request, the third request including the third universal resource identifier; and

wherein transmitting the third request causes establishment of a third encrypted connection between the device and a second server hosting the second resource, to facilitate encrypted communication traffic between the device and the server hosting the resource.

8. A system comprising:

a device comprising a graphical user interface, the device configured to:

present a display region within a graphical user interface;

receive, from a user, input to navigate to a first universal resource identifier that identifies a first resource;

transmit a first request, the first request including the first universal resource identifier;

receive a redirect response that includes a second universal resource identifier, the second universal resource identifier comprising a domain associated with a man-in-the-middle gateway and further comprising at least a portion of the first universal resource identifier;

display at least the domain associated with the man-in-the-middle gateway in response to receiving, from the user, the input; and

transmit a second request to access the first resource, the second request including the second universal resource identifier.

9. The system of claim 8 , wherein transmitting the second request to access the first resource causes:

establishment of a first encrypted connection between the device and the man-in-the-middle gateway, and a second encrypted connection between the man-in-the-middle gateway and a server hosting the first resource, to facilitate encrypted communication traffic between the device and the server hosting the resource; and

decryption and inspection of the encrypted communication traffic passing between the device and the server hosting the resource.

10. The system of claim 8 , wherein the first request further includes a cookie associated with the resource and the first universal resource identifier; and

wherein the device is further configured to receive, by the device, a second cookie associated with the resource and the second universal resource identifier.

11. The system of claim 8 , wherein the device is further configured to:

receive instructions for presentation to the user with a notification regarding redirection from the first universal resource identifier to the second universal resource identifier; and

present, to the user, the notification.

12. The system of claim 8 , wherein the device is further configured to:

present a user interface element to receive input from the user to continue with the redirections; and

wherein the second request is transmitted responsive to receiving the input from the user to continue with the redirection.

13. The system of claim 8 , wherein a web browser comprises the graphical user interface.

14. The system of claim 8 , wherein the device is further configured to:

receive, from a user, second input to navigate to a third universal resource identifier that identifies a second resource;

transmit a third request, the third request including the third universal resource identifier; and

wherein transmitting the third request causes establishment of a third encrypted connection between the device and a second server hosting the second resource, to facilitate encrypted communication traffic between the device and the server hosting the resource.

15. A system comprising:

means for generating a graphical user interface; and

a device configured to:

present a display region within a graphical user interface;

receive, from a user, input to navigate to a first universal resource identifier that identifies a first resource;

transmit a first request, the first request including the first universal resource identifier;

receive a redirect response that includes a second universal resource identifier, the second universal resource identifier comprising a domain associated with a man-in-the-middle gateway and further comprising at least a portion of the first universal resource identifier;

display at least the domain associated with the man-in-the-middle gateway in response to receiving, from the user, the input; and

transmit a second request to access the first resource, the second request including the second universal resource identifier.

16. The system of claim 15 , wherein transmitting the second request to access the first resource causes:

establishment of a first encrypted connection between the device and the man-in-the-middle gateway, and a second encrypted connection between the man-in-the-middle gateway and a server hosting the first resource, to facilitate encrypted communication traffic between the device and the server hosting the resource; and

decryption and inspection of the encrypted communication traffic passing between the device and the server hosting the resource.

17. The system of claim 15 , wherein the first request further includes a cookie associated with the resource and the first universal resource identifier; and

wherein the device is further configured to receive, by the device, a second cookie associated with the resource and the second universal resource identifier.

18. The system of claim 15 , wherein the device is further configured to:

receive instructions for presentation to the user with a notification regarding redirection from the first universal resource identifier to the second universal resource identifier; and

present, to the user, the notification.

19. The system of claim 15 , wherein the device is further configured to:

present a user interface element to receive input from the user to continue with the redirections; and

wherein the second request is transmitted responsive to receiving the input from the user to continue with the redirection.

20. The system of claim 15 , wherein a web browser comprises the graphical user interface.

21. The system of claim 15 , wherein the device is further configured to:

receive, from a user, second input to navigate to a third universal resource identifier that identifies a second resource;

transmit a third request, the third request including the third universal resource identifier; and

wherein transmitting the third request causes establishment of a third encrypted connection between the device and a second server hosting the second resource, to facilitate encrypted communication traffic between the device and the server hosting the resource.

Assignments (7)
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 28, 2023
From: IBOSS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 066158/0219 →
SUPPLEMENTAL INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 28, 2023
From: IBOSS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 066158/0266 →
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Dec 12, 2023
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK TRUST COMPANY
To: IBOSS, INC.
Reel/Frame 066140/0480 →
SECURITY INTEREST Recorded Sep 19, 2022
From: IBOSS, INC.
To: SILICON VALLEY BANK
Reel/Frame 061463/0331 →
SECURITY INTEREST Recorded Dec 16, 2020
From: IBOSS, INC.
To: SILICON VALLEY BANK
Reel/Frame 054789/0680 →
CHANGE OF NAME Recorded May 17, 2016
From: PHANTOM TECHNOLOGIES, INC.
To: IBOSS, INC.
Reel/Frame 038742/0051 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 17, 2016
From: MARTINI, PAUL MICHAEL
To: PHANTOM TECHNOLOGIES, INC.
Reel/Frame 038624/0017 →
Continuity (2)
Continuation 13901515 · May 23, 2013
Related Publication 20150381583A1 · Dec 31, 2015