IP Library Granted Patent US 10,263,788
Granted Patent B2
US 10,263,788 · App. 14/991,637 · Granted Apr 16, 2019

Systems and methods for providing a man-in-the-middle proxy

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,263,788
App. No.
14/991,637
Granted
Apr 16, 2019
Kind
B2
Abstract

A method for operating a secure man-in-the-middle proxy includes intercepting an attempt to establish a connection between an application and a network server associated with a whitelisted hostname, establishing a secure connection to the network server, checking the secure connection against the stored combination of certificate, encryption protocol, and encryption cipher for the whitelisted hostname, and forwarding traffic between the application and the network server at the whitelisted hostname if the secure connection matches the stored combination of certificate, encryption protocol, and encryption cipher for the whitelisted hostname.

Claims (39)

1. A method for operating a secure man-in-the-middle proxy on an information handling system, comprising:

pre-negotiating certificates, encryption protocol, and encryption cipher with a network server associated with a hostname and adding the hostname, pre-negotiated certificates, encryption protocol, and encryption cipher to a whitelist when the pre-negotiated certificates, encryption protocol, and encryption cipher meet an approved list of certificates, encryption protocol, and encryption cipher;

intercepting an attempt to establish a connection between an application and a network server associated with the hostname;

establishing a secure connection to the network server;

checking the secure connection against the stored combination of certificate, encryption protocol, and encryption cipher for the hostname; and

forwarding traffic between the application and the network server at the hostname if the secure connection matches the stored combination of certificate, encryption protocol, and encryption cipher for the hostname.

2. The method of claim 1 , further comprising rejecting attempted connections to hostnames not in the whitelist.

3. The method of claim 1 , wherein the application is running on the information handling system with the secure man-in-the-middle proxy.

4. The method of claim 3 , wherein the application is running in a virtual container on the information handling system.

5. The method of claim 1 , wherein the method is performed on a firewall and the application is running on an application server behind the firewall.

6. The method of claim 1 , wherein the stored combination of certificate, encryption protocol, and encryption cipher for the whitelisted hostname is verified with the network server prior to the attempt to establish a connection between the application and the network server.

7. The method of claim 6 , wherein the verification is performed when the hostname is added to the whitelist.

8. An information handling system comprising:

a storage configured to store a whitelist of allowed network hostnames and combinations of certificates, network encryption protocols, and encryption ciphers for the allowed network hostnames; and

a hardware processor configured to:

pre-negotiate certificates, encryption protocol, and encryption cipher with a network server associated with the allowed hostnames and storing the combinations of certificates, network encryption protocol, and encryption cipher to a whitelist when the combination of certificates, encryption protocol, and encryption cipher meets an approved list of certificates, encryption protocol, and encryption cipher;

intercept an attempt to establish a connection between an application and the whitelisted hostname;

establish a secure connection to a network server at the whitelisted hostname;

check the secure connection against the stored combination of certificate, encryption protocol, and encryption cipher for the whitelisted hostname; and

forward traffic between the application and the network server at the whitelisted hostname if the secure connection matches the stored combination of certificate, encryption protocol, and encryption cipher for the whitelisted hostname.

9. The information handling system of claim 8 , wherein the processor is further configured to:

interrogate the network server corresponding to one of the allowed network hostnames to determine a current certificate, a supported network encryption protocol version, and a support encryption cipher; and

store a known combination of certificate, network encryption protocol, and encryption cipher for the hostname.

10. The information handling system of claim 9 , wherein the interrogating and storing is performed when the hostname is added to the whitelist.

11. The information handling system of claim 8 , wherein the processor is further configured to rejecting attempted connections to hostnames not in the whitelist.

12. The information handling system of claim 8 , wherein the application is running on the information handling system.

13. The information handling system of claim 12 , wherein the application is running in a virtual container on the information handling system.

14. The information handling system of claim 8 , wherein the information handling system is a firewall and the application is running on an application server behind the firewall.

15. A method for operating a secure man-in-the-middle proxy on an information handling system, comprising:

interrogating a network server at a whitelisted hostname to determine a current certificate, a supported network encryption protocol version, and a support encryption cipher;

storing a known combination of certificate, network encryption protocol, and encryption cipher for the whitelisted hostname when the combination of certificate, network encryption protocol, and encryption cipher meets an approved list of certificates, encryption protocol, and encryption cipher;

intercepting an attempt to establish a connection between an application and the whitelisted hostname;

establishing a secure connection to the network server at the whitelisted hostname;

checking the secure connection against the stored combination of certificate, encryption protocol, and encryption cipher for the whitelisted hostname; and

forwarding traffic between the application and the network server at the whitelisted hostname if the secure connection matches the stored combination of certificate, encryption protocol, and encryption cipher for the whitelisted hostname.

16. The method of claim 15 , further comprising rejecting attempted connections to hostnames not in the whitelist.

17. The method of claim 15 , wherein the application is running on the information handling system.

18. The method of claim 17 , wherein the application is running in a virtual container on the information handling system.

19. The method of claim 15 , wherein the method is performed on a firewall and the application is running on an application server behind the firewall.

Assignments (12)
SECURITY INTEREST Recorded May 2, 2025
From: SECUREWORKS CORP.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 071156/0529 →
RELEASE OF REEL 037848 FRAME 0001 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040028/0152 →
RELEASE OF REEL 038664 FRAME 0908 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, CORP.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040027/0390 →
RELEASE OF REEL 038665 FRAME 0041 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, CORP.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040028/0375 →
RELEASE OF REEL 037848 FRAME 0210 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040031/0725 →
RELEASE OF REEL 038665 FRAME 0001 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, CORP.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040021/0348 →
RELEASE OF REEL 037847 FRAME 0843 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040017/0366 →
ENTITY CONVERSION WITH NAME CHANGE Recorded May 4, 2016
From: SECUREWORKS HOLDING CORPORATION
To: SECUREWORKS CORP.
Reel/Frame 038608/0757 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 8, 2016
From: KINDER, ROSS R.; RAMSEY, JON R.; VIDAS, TIMOTHY M.; DANFORD, ROBERT
To: SECUREWORKS HOLDING CORPORATION
Reel/Frame 038389/0814 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded Feb 18, 2016
From: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 037848/0210 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Feb 18, 2016
From: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 037848/0001 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded Feb 18, 2016
From: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 037847/0843 →