IP Library Granted Patent US 9,749,292
Granted Patent B2
US 9,749,292 · App. 15/336,639 · Granted Aug 29, 2017

Selectively performing man in the middle decryption

Inventor: Paul Michael Martini (San Diego, CA)
Assignee: iboss, Inc.
H04L63/0209H04L63/0254H04L63/0281H04L63/0428H04L63/0464H04L63/20H04L67/42H04L63/168H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,749,292
App. No.
15/336,639
Granted
Aug 29, 2017
Kind
B2
Abstract

Methods, systems, and apparatus, including computer programs encoded on computer storage media, for selectively performing man in the middle decryption. One of the methods includes receiving a first request to access a first resource hosted by a server outside the network, determining whether requests from the client device to access the first resource outside the network should be redirected to a second resource hosted by a proxy within the network, providing a redirect response to the client device, the redirect response including the second universal resource identifier, establishing a first encrypted connected between the client device and the proxy hosting the second resource, and a second encrypted connection between the proxy hosting the second domain and the server hosting the first resource, and decrypting and inspecting the encrypted communication traffic passing between the client device and the server hosting the first resource.

Claims (62)

1. A method performed by data processing apparatus, the method comprising:

receiving, at a network gateway from a client device within a network, a first request to access a first resource hosted by a server outside the network, the first request including a first universal resource identifier that identifies the first resource;

determining, based on one or more policies in a policy group associated with the client device, whether requests from the client device to access the first resource outside the network should be inspected;

selecting, from a plurality of candidate man-in-the-middle gateways, a man-in-the-middle gateway for use; and

providing, based on determining that requests from the client device to access the first resource outside the network are to be inspected, a redirect response to the client device, the redirect response including a second universal resource identifier, the second universal resource identifier comprising a domain associated with the man-in-the-middle gateway and further comprising at least a portion of the first universal resource identifier, such that the client device displays at least the domain associated with the man-in-the-middle gateway to a user of the client device in response to receiving, from the user, input to navigate to the first universal resource identifier.

2. The method of claim 1 , the method further comprising:

receiving, from the client device, a second request to access the first resource, the second request including the second universal resource identifier;

establishing, based on receiving the second request, a first encrypted connection between the client device and the man-in-the-middle gateway, and a second encrypted connection between the man-in-the-middle gateway and the server hosting the first resource, to facilitate encrypted communication traffic between the client device and the server hosting the first resource; and

decrypting and inspecting the encrypted communication traffic passing between the client device and the server hosting the first resource.

3. The method of claim 2 , wherein the inspecting comprises applying one or more first security policies to the decrypted communication traffic, the first security policies being included in the policy group.

4. The method of claim 3 , further comprising blocking communication traffic between the client device and the server hosting the first resource upon determining that one or more second security policies have been violated, the second security policies being included in the policy group.

5. The method of claim 3 , further comprising modifying communication traffic between the client device and the server hosting the first resource based on content of the communication traffic.

6. The method of claim 3 , wherein:

the providing comprises appending one or more client device parameters to the redirect response, the client device parameters identifying one of the client device and the policy group;

the receiving the second request to access the first resource comprises receiving the client device parameters from the client device; and

the inspecting comprises identifying the policy group using the client device parameters and selecting the first security policies from the policy group.

7. The method of claim 3 , wherein:

the providing comprises sending a cookie to the client device;

the receiving the second request to access the first resource comprises receiving one or more parameters included in the cookie from the client device; and

the inspecting comprises identifying the policy group using the parameters from the cookie and selecting the first security policies from the policy group.

8. The method of claim 3 , wherein the inspecting comprises identifying the policy group associated with the client device based on the internet protocol address of the client device and selecting the first security policies from the policy group.

9. The method of claim 2 , wherein the encrypted communication traffic between the client device and the server hosting the first resource passes through the man-in-the-middle gateway.

10. The method of claim 1 , wherein the receiving the first request, the determining and the providing are performed by a web gateway device.

11. The method of claim 10 , wherein the man-in-the-middle gateway comprises a proxy server device separate from the web gateway device.

12. The method of claim 1 , wherein:

each candidate man-in-the-middle gateway inspects based on an associated one of a plurality of inspection levels; and

selecting, from a plurality of candidate man-in-the-middle gateways, a man-in-the-middle gateway for use comprises selecting a man-in-the-middle gateway based on an associated one of a plurality of inspection levels.

13. The method of claim 1 , wherein selecting, from a plurality of candidate man-in-the-middle gateways, a man-in-the-middle gateway for use comprises selecting a man-in-the-middle gateway based on a classification of the first resource.

14. A non-transitory computer storage medium encoded with instructions that, when executed by one or more computers, cause the one or more computers to perform operations comprising:

receiving, at a network gateway from a client device within a network, a first request to access a first resource hosted by a server outside the network, the first request including a first universal resource identifier that identifies the first resource;

determining, based on one or more policies in a policy group associated with the client device, whether requests from the client device to access the first resource outside the network should be inspected;

selecting, from a plurality of candidate man-in-the-middle gateways, a man-in-the-middle gateway for use; and

providing, based on determining that requests from the client device to access the first resource outside the network are to be inspected, a redirect response to the client device, the redirect response including a second universal resource identifier, the second universal resource identifier comprising a domain associated with the man-in-the-middle gateway and further comprising at least a portion of the first universal resource identifier, such that the client device displays at least the domain associated with the man-in-the-middle gateway to a user of the client device in response to receiving, from the user, input to navigate to the first universal resource identifier.

15. A system comprising:

one or more computers and one or more storage devices storing instructions that are operable, when executed by the one or more computers, to cause the one or more computers to perform operations comprising:

receiving, at a network gateway from a client device within a network, a first request to access a first resource hosted by a server outside the network, the first request including a first universal resource identifier that identifies the first resource;

determining, based on one or more policies in a policy group associated with the client device, whether requests from the client device to access the first resource outside the network should be inspected;

selecting, from a plurality of candidate man-in-the-middle gateways, a man-in-the-middle gateway for use; and

providing, based on determining that requests from the client device to access the first resource outside the network are to be inspected, a redirect response to the client device, the redirect response including a second universal resource identifier, the second universal resource identifier comprising a domain associated with the man-in-the-middle gateway and further comprising at least a portion of the first universal resource identifier, such that the client device displays at least the domain associated with the man-in-the-middle gateway to a user of the client device in response to receiving, from the user, input to navigate to the first universal resource identifier.

16. The system of claim 15 , the operations further comprising:

receiving, from the client device, a second request to access the first resource, the second request including the second universal resource identifier;

establishing, based on receiving the second request, a first encrypted connection between the client device and the man-in-the-middle gateway, and a second encrypted connection between the man-in-the-middle gateway and the server hosting the first resource, to facilitate encrypted communication traffic between the client device and the server hosting the first resource; and

decrypting and inspecting the encrypted communication traffic passing between the client device and the server hosting the first resource.

17. The system of claim 16 , wherein the inspecting comprises applying one or more first security policies to the decrypted communication traffic, the first security policies being included in the policy group.

18. The system of claim 17 , further comprising blocking communication traffic between the client device and the server hosting the first resource upon determining that one or more second security policies have been violated, the second security policies being included in the policy group.

19. The system of claim 17 , the operations further comprising modifying communication traffic between the client device and the server hosting the first resource based on content of the communication traffic.

20. The system of claim 17 , wherein:

the providing comprises appending one or more client device parameters to the redirect response, the client device parameters identifying one of the client device and the policy group;

the receiving the second request to access the first resource comprises receiving the client device parameters from the client device; and

the inspecting comprises identifying the policy group using the client device parameters and selecting the first security policies from the policy group.

21. The system of claim 17 , wherein:

the providing comprises sending a cookie to the client device;

the receiving the second request to access the first resource comprises receiving one or more parameters included in the cookie from the client device; and

the inspecting comprises identifying the policy group using the parameters from the cookie and selecting the first security policies from the policy group.

22. The system of claim 17 , wherein the inspecting comprises identifying the policy group associated with the client device based on the internet protocol address of the client device and selecting the first security policies from the policy group.

23. The system of claim 16 , wherein the encrypted communication traffic between the client device and the server hosting the first resource passes through the man-in-the-middle gateway.

24. The system of claim 15 , wherein the receiving the first request, the determining and the providing are performed by a web gateway device.

25. The system of claim 24 , wherein the man-in-the-middle gateway comprises a proxy server device separate from the web gateway device.

26. The system of claim 15 , wherein:

each candidate man-in-the-middle gateway inspects based on an associated one of a plurality of inspection levels; and

selecting, from a plurality of candidate man-in-the-middle gateways, a man-in-the-middle gateway for use comprises selecting a man-in-the-middle gateway based on an associated one of a plurality of inspection levels.

27. The system of claim 15 , wherein selecting, from a plurality of candidate man-in-the-middle gateways, a man-in-the-middle gateway for use comprises selecting a man-in-the-middle gateway based on a classification of the first resource.

Assignments (7)
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 28, 2023
From: IBOSS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 066158/0219 →
SUPPLEMENTAL INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 28, 2023
From: IBOSS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 066158/0266 →
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Dec 12, 2023
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK TRUST COMPANY
To: IBOSS, INC.
Reel/Frame 066140/0480 →
SECURITY INTEREST Recorded Sep 19, 2022
From: IBOSS, INC.
To: SILICON VALLEY BANK
Reel/Frame 061463/0331 →
SECURITY INTEREST Recorded Dec 16, 2020
From: IBOSS, INC.
To: SILICON VALLEY BANK
Reel/Frame 054789/0680 →
CHANGE OF NAME Recorded Mar 24, 2017
From: PHANTOM TECHNOLOGIES, INC.
To: IBOSS, INC.
Reel/Frame 042091/0841 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 24, 2017
From: MARTINI, PAUL MICHAEL
To: PHANTOM TECHNOLOGIES, INC.
Reel/Frame 041734/0891 →
Continuity (3)
Continuation 14845169 · Sep 3, 2015
Continuation 13901515 · May 23, 2013
Related Publication 20170048196A1 · Feb 16, 2017