IP Library › Granted Patent US 9,843,561
Granted Patent B2
US 9,843,561 · App. 14/884,690 · Granted Dec 12, 2017

MiTM proxy having client authentication support

Inventors: Vijaykumar V. Borkar (Pune, IN); Saurabh Sule (Pune, IN)
Assignee: Avaya Inc.
H04L63/0281H04L9/0897H04L9/321H04L9/3263H04L63/0823H04L63/168
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,843,561
App. No.
14/884,690
Granted
Dec 12, 2017
Kind
B2
Abstract

Methods, systems and computer readable media for a MiTM proxy that supports client authentication are described.

Claims (56)

1. A method comprising:

receiving, at a man-in-the-middle (MiTM) proxy, a first client certificate request from a server during a communication session that utilizes a communication protocol;

recognizing the first client certificate request by the MiTM proxy;

transmitting, after receiving the first client certificate request from the server, from the MiTM proxy, a second client certificate request to a client;

receiving, at the MiTM proxy, a first set of response messages generated by the client in response to the second client certificate request;

obtaining, by the MiTM proxy a public certificate and a signed message, wherein the public certificate is mapped to the client and wherein the signed message is signed with a private key associated with the client;

generating, at the MiTM proxy, a second set of response messages configured to be sent to the server on behalf of the client in response to the first client certificate request message, the second set of response messages containing the public certificate and the signed message, the public certificate being managed by a third party system; and

sending, from the MiTM proxy to the server, the second set of response messages configured to authenticate the client to the server through the MiTM proxy.

2. The method of claim 1 , wherein the communication protocol includes a secure socket layer/transport layer security (SSL/TLS) protocol.

3. The method of claim 1 , wherein the third party system includes a hardware security module (HSM), and wherein the method further comprises obtaining the public certificate and the private key from the HSM.

4. The method of claim 1 , wherein the third party system includes a lightweight directory access protocol (LDAP) system, and wherein the method further comprises obtaining the public certificate and the private key from the LDAP system.

5. The method of claim 1 , wherein the third party system includes a Windows Active Directory system, and wherein the method further comprises obtaining the public certificate and the private key from the Windows Active Directory system.

6. The method of claim 1 , wherein the third party system includes a database, and wherein the method further comprises obtaining the public certificate and the private key from the database.

7. The method of claim 1 , further comprising:

requesting the public certificate mapped to the client from a hardware security module (HSM);

adding the public certificate received from the HSM to the second set of response messages;

requesting a hardware security module (HSM) to sign a certificate verify message for the MiTM proxy; and

sending the second set of response messages, including the certificate verify message signed by the HSM using the private key, to the server.

8. A system comprising:

a network communication interface;

one or more processors coupled to the network communication interface, the processors configured to perform operations comprising:

receiving, at a man-in-the-middle (MiTM) proxy, a first client certificate request from a server during a communication session in a communication protocol via the network communication interface;

intercepting, at the MiTM proxy, the first client certificate request;

forwarding, from the MiTM proxy, after receiving the first client certificate request from the server, a second client certificate request to a client;

intercepting, at the MiTM proxy, a first set of response messages generated by the client in response to the second client certificate request;

obtaining, by the MiTM proxy from a third party system, a public certificate mapped to the client and a private key associated with the client;

generating, at the MiTM proxy, a second set of response messages configured to be sent to the server on behalf of the client in response to the first client certificate request message, the second set of response messages containing the public certificate mapped to the client that was obtained by the MiTM proxy, and a certificate verify message generated by the MiTM proxy and signed using the private key associated with the client; and

sending, from the MiTM proxy to the server, the second set of response messages configured to authenticate the client to the server through the MiTM proxy.

9. The system of claim 8 , wherein the communication protocol includes a secure socket layer/transport layer security (SSL/TLS) protocol.

10. The system of claim 8 , wherein the third party system includes a hardware security module (HSM), and wherein the operations further include obtaining the public certificate and the private key from the HSM.

11. The system of claim 8 , wherein the third party system includes a lightweight directory access protocol (LDAP) system, and wherein the operations further include obtaining the public certificate and the private key from the LDAP system.

12. The system of claim 8 , wherein the third party system includes a Windows Active Directory system, and wherein the operations further include obtaining the public certificate and the private key from the Windows Active Directory system.

13. The system of claim 8 , wherein the third party system includes a database, and wherein the operations further include obtaining the public certificate and the private key from the database.

14. The system of claim 8 , wherein the operations further include:

requesting the public certificate mapped to the client from a hardware security module (HSM);

adding the public certificate received from the HSM to the second set of response messages;

requesting a hardware security module (HSM) to provide a private key associated with the client to sign the certificate verify message by the MiTM proxy; and

sending the second set of response messages, including the signed certificate verify message, to the server.

15. A nontransitory computer readable medium having stored thereon software instructions that, when executed by one or more processors, cause the one or more processors to perform operations including:

receiving, at a man-in-the-middle (MiTM) proxy, a first client certificate request from a server during a communication session in a communication protocol;

intercepting, at the MiTM proxy, the first client certificate request;

forwarding, from the MiTM proxy, after receiving the first client certificate request from the server, a second client certificate request to a client;

intercepting, at the MiTM proxy, a first set of response messages generated by the client in response to the second client certificate request;

requesting, by the MiTM proxy to a third party system, a public certificate and a signed message, wherein the public certificate is mapped to the client and wherein the signed message is signed with a private key associated with the client;

obtaining, by the MiTM proxy from the third party system, the public certificate and the signed message;

generating, at the MiTM proxy, a second set of response messages configured to be sent to the server on behalf of the client in response to the first client certificate request message, the second set of response messages containing the public certificate mapped to the client that was obtained by the MiTM proxy and the signed message; and

sending, from the MiTM proxy to the server, the second set of response messages configured to authenticate the client to the server through the MiTM proxy.

16. The nontransitory computer readable medium of claim 15 , wherein the communication protocol includes a secure socket layer/transport layer security (SSL/TLS) protocol.

17. The nontransitory computer readable medium of claim 15 , wherein the third party system includes a hardware security module (HSM), and wherein the operations further include obtaining the public certificate and the signed message from the HSM.

18. The nontransitory computer readable medium of claim 15 , wherein the third party system includes a lightweight directory access protocol (LDAP) system, and wherein the operations further include obtaining the public certificate and the signed message from the LDAP system.

19. The nontransitory computer readable medium of claim 15 , wherein the third party system includes a Windows Active Directory system, and wherein the operations further include obtaining the public certificate and the signed message from the Windows Active Directory system.

20. The nontransitory computer readable medium of claim 15 , wherein the operations further include:

requesting the public certificate mapped to the client from a hardware security module (HSM);

adding the public certificate received from the HSM to the second set of response messages;

requesting a hardware security module (HSM) to sign a certificate verify message for the MiTM proxy; and

sending the second set of response messages, including the certificate verify message signed by the HSM, to the server.

Assignments (15)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 14, 2026
From: AVAYA LLC
To: PULSELINK SYSTEMS LLC
Reel/Frame 074909/0627 →
INTELLECTUAL PROPERTY PARTIAL RELEASE AND REASSIGNMENT Recorded Feb 4, 2026
From: WILMINGTON SAVINGS FUND SOCIETY, FSB
To: AVAYA LLC (F/K/A AVAYA INC.); AVAYA MANAGEMENT L.P.
Reel/Frame 074981/0940 →
INTELLECTUAL PROPERTY PARTIAL RELEASE AND REASSIGNMENT Recorded Feb 4, 2026
From: CITIBANK, N.A.
To: AVAYA LLC (F/K/A AVAYA INC.); AVAYA MANAGEMENT L.P.
Reel/Frame 074944/0573 →
(SECURITY INTEREST) GRANTOR'S NAME CHANGE Recorded Sep 21, 2023
From: AVAYA INC.
To: AVAYA LLC
Reel/Frame 065019/0231 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 045034/0001) Recorded May 18, 2023
From: GOLDMAN SACHS BANK USA., AS COLLATERAL AGENT
To: AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC. (FORMER NAME OF AVAYA CLOUD INC.); HYPERQUALITY, INC.; HYPERQUALITY II, LLC; CAAS TECHNOLOGIES, LLC; AVAYA MANAGEMENT L.P.
Reel/Frame 063779/0622 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 53955/0436) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063705/0023 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 61087/0386) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063690/0359 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 4, 2023
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 063542/0662 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 3, 2023
From: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; KNOAHSOFT INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB [COLLATERAL AGENT]
Reel/Frame 063742/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS AT REEL 45124/FRAME 0026 Recorded Apr 26, 2023
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: AVAYA HOLDINGS CORP.; AVAYA INC.; AVAYA MANAGEMENT L.P.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063457/0001 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 5, 2022
From: AVAYA INC.; INTELLISIST, INC.; AVAYA MANAGEMENT L.P.; AVAYA CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 061087/0386 →
SECURITY INTEREST Recorded Sep 25, 2020
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 053955/0436 →
SECURITY INTEREST Recorded Jan 23, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 045124/0026 →
SECURITY INTEREST Recorded Jan 10, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 045034/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 19, 2015
From: BORKAR, VIKAYKUMAR V; SULE, SAURABH
To: AVAYA INC.
Reel/Frame 036819/0809 →
Continuity (1)
Related Publication 20170111323A1 · Apr 20, 2017