IP Library Granted Patent US 10,469,465
Granted Patent B2
US 10,469,465 · App. 15/439,349 · Granted Nov 5, 2019

Cryptographic proxy service

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,469,465
App. No.
15/439,349
Granted
Nov 5, 2019
Kind
B2
Abstract

A cryptographic proxy service may be provided. Upon determining that data associated with a network destination comprises at least some sensitive data, a cryptographic service may provide a security certificate associated with the network destination. The plurality of data may be encrypted according to the security certificate associated with the network destination and provided to the cryptographic service for re-encryption and transmission to the network destination.

Claims (53)

1. A cryptographic proxy system comprising:

a memory store; and

a processor coupled to the memory store, wherein the processor is configured to execute operations comprising:

receiving identification of a network destination where a computing device is attempting to transmit sensitive data, wherein the sensitive data is identified by the computing device, prior to transmitting the sensitive data, based on content evaluation rules that cause the computing device to search the sensitive data for keywords and compare the network destination to a list of network destinations;

conditionally blocking transmission of the sensitive data based on a determination that a secure channel cannot be established between the computing device and the network destination identified in the list of network destinations;

obtaining a spoofed security certificate that impersonates the network destination, the spoofed security certificate including a first public key corresponding to a first private key;

verifying that the computing device is in compliance with a compliance rule specifying management restrictions that must be satisfied to establish compliance, the management restrictions comprising an encryption requirement and a firmware-version requirement;

in response to verifying that the computing device is in compliance with the compliance rule, sending the first public key to the computing device to use for encrypting the sensitive data;

receiving the encrypted sensitive data;

decrypting the sensitive data using the first private key;

re-encrypting the sensitive data according to a second security certificate associated with the network destination;

forwarding the re-encrypted data to the network destination;

operating as a certificate authority for the spoofed security certificate.

2. The system of claim 1 , wherein the operations further comprise:

retrieving the second security certificate from a certificate authority associated with the network destination.

3. The system of claim 1 , wherein the operations further comprise:

installing a root certificate for the certificate authority for the spoofed security certificate on the computing device.

4. The system of claim 3 , wherein the operations further comprise:

installing a second root certificate for the certificate authority for the second security certificate on the network destination.

5. The system of claim 1 , wherein the network destination comprises a second computing device.

6. A method for providing a cryptographic proxy service, comprising:

receiving identification of a network destination where a computing device is attempting to transmit sensitive data, wherein the sensitive data is identified by the computing device, prior to transmitting the sensitive data, based on content evaluation rules that cause the computing device to search the sensitive data for keywords and compare the network destination to a list of network destinations;

conditionally blocking transmission of the sensitive data based on a determination that a secure channel cannot be established between the computing device and the network destination identified in the list of network destinations;

generating a spoofed security certificate that impersonates the network destination, the spoofed security certificate including a first public key and a first private key;

verifying that the computing device is in compliance with a compliance rule specifying management restrictions that must be satisfied to establish compliance, the management restrictions comprising an encryption requirement and a firmware-version requirement;

in response to verifying that the computing device is in compliance with the compliance rule, sending the first public key to the computing device to use for encrypting the sensitive data;

receiving the encrypted sensitive data;

decrypting the sensitive data using the first private key;

negotiating the secure channel with the network destination;

sending the sensitive data to the network destination; and

operating as a certificate authority for the spoofed security certificate.

7. The method of claim 6 , wherein negotiating the secure channel includes re-encrypting the sensitive data using a second public key of a destination security certificate, the destination security certificate being received from the certificate authority associated with the network destination.

8. The method of claim 6 , further comprising:

installing a root certificate for the certificate authority for the spoofed security certificate on the computing device.

9. The method of claim 8 , further comprising:

installing a second root certificate for the certificate authority for the destination security certificate on the network destination.

10. The method of claim 6 , wherein the network destination comprises a second computing device.

11. A non-transitory, computer-readable medium containing instructions that cause a processor to perform operations for providing a cryptographic proxy service, the operations comprising:

receiving identification of a network destination where a computing device is attempting to transmit sensitive data, wherein the sensitive data is identified by the computing device, prior to transmitting the sensitive data, based on content evaluation rules that cause the computing device to search the sensitive data for keywords and compare the network destination to a list of network destinations;

conditionally blocking transmission of the sensitive data based on a determination that a secure channel cannot be established between the computing device and the network destination identified in the list of network destinations;

generating a spoofed security certificate that impersonates the network destination, the spoofed security certificate including a first public key and a first private key;

verifying that the computing device is in compliance with a compliance rule specifying at management restrictions that must be satisfied to establish compliance, the management restrictions comprising an encryption requirement and a firmware-version requirement;

in response to verifying that the computing device is in compliance with the compliance rule, sending the first public key to the computing device to use for encrypting the sensitive data;

receiving the encrypted sensitive data;

decrypting the sensitive data using the first private key;

negotiating the secure channel with the network destination;

sending the sensitive data to the network destination;

operating as a certificate authority for the spoofed security certificate.

12. The non-transitory, computer-readable medium of claim 11 , wherein negotiating the secure channel includes re-encrypting the sensitive data using a second public key of a destination security certificate, the destination security certificate being received from the certificate authority associated with the network destination.

13. The non-transitory, computer-readable medium of claim 11 , the operations further comprising:

installing a root certificate for the certificate authority for the spoofed security certificate on the computing device.

14. The non-transitory, computer-readable medium of claim 13 , the operations further comprising:

installing a second root certificate for the certificate authority for the destination security certificate on the network destination.

Assignments (5)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: VMWARE LLC
To: OMNISSA, LLC
Reel/Frame 068327/0365 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2024
From: STUNTEBECK, ERICH
To: AIRWATCH LLC
Reel/Frame 067879/0115 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2024
From: AIRWATCH LLC
To: VMWARE, INC.
Reel/Frame 067879/0157 →
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0395 →