IP Library › Granted Patent US 11,569,986
Granted Patent B2
US 11,569,986 · App. 15/894,654 · Granted Jan 31, 2023

Decryption of secure sockets layer sessions having enabled perfect forward secrecy using a Diffie-Hellman key exchange

Inventors: Rajeev Chaubey (Bangalore, IN); Venkata Rama Raju Manthena (Cupertino, CA)
Assignee: Juniper Networks, Inc.
H04L9/0841H04L63/061H04L63/168
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,569,986
App. No.
15/894,654
Granted
Jan 31, 2023
Kind
B2
Abstract

A device may receive client cipher information, associated with initiating a secure session, identifying at least one key exchange cipher supported by a client device associated with the secure session. The device may determine, based on the client cipher information, that a Diffie-Hellman key exchange is to be used to establish the secure session. The device may determine whether a server device, associated with the secure session, supports use of the Diffie-Hellman key exchange. The device may manage establishment of the secure session using a first decryption technique based on determining that the server device does not support the use of the Diffie-Hellman key exchange, or manage establishment of the secure session using a second decryption technique based on determining that the server device supports the use of the Diffie-Hellman key exchange or being unable to determine whether the server device supports the use of the Diffie-Hellman key exchange.

Claims (80)

1. A method comprising:

identifying, by a device, priority information associated with key exchange ciphers;

determining, by the device and based on the priority information, a first priority of a Diffie-Hellman key exchange;

determining, by the device and based on the priority information, a second priority of an RSA key exchange;

determining, by the device, that a particular decryption technique is to be used to manage encrypted traffic associated with a session;

determining, by the device and after determining that the particular decryption technique is to be used to manage the encrypted traffic associated with the session, a preference for using the Diffie-Hellman key exchange based on the first priority of the Diffie-Hellman key exchange and the second priority of the RSA key exchange; and

establishing, by the device, a session based on determining the preference for using the Diffie-Hellman key exchange.

2. The method of claim 1 , further comprising:

receiving a message associated with initiating the session; and

determining client cipher information included in the message,

the client cipher information including the priority information associated with the key exchange ciphers.

3. The method of claim 1 , further comprising:

performing a server cipher preference cache lookup based on a message, for initiating the session, after determining the preference for using the Diffie-Hellman key exchange,

where establishing the session comprises:

establishing the session based on performing the server cipher preference cache lookup.

4. The method of claim 3 , further comprising:

receiving the message for initiating the session,

the message including a server indicator for a server device associated with initiating the session,

wherein performing the server cipher preference cache lookup comprises:

performing the server cipher preference cache lookup, using the server indicator, to determine whether the server device supports use of the Diffie-Hellman key exchange to establish the session.

5. The method of claim 1 , further comprising:

determining whether a server device, associated with the session, supports use of the Diffie-Hellman key exchange to establish the session,

where establishing the session comprises:

establishing the session based on determining whether the server device, associated with the session, supports use of the Diffie-Hellman key exchange to establish the session.

6. The method of claim 5 , where the session is established after determining that it is unknown whether the server device supports use of the Diffie-Hellman key exchange.

7. A device comprising:

a memory; and

one or more processors to:

identify priority information associated with key exchange ciphers;

determine, based on the priority information, a preference for using a Diffie-Hellman key exchange;

perform a server cipher preference cache lookup based on a message, for initiating a session, after determining the preference for using the Diffie-Hellman key exchange; and

establish the session based on performing the server cipher preference cache lookup.

8. The device of claim 7 , where the one or more processors are further to:

receive the message for initiating the session; and

determine client cipher information included in the message,

the client cipher information including the priority information associated with the key exchange ciphers.

9. The device of claim 7 ,

where the one or more processors are further to:

determine that a particular decryption technique is to be used to manage encrypted traffic associated with the session, and

where, when determining the preference for using the Diffie-Hellman key exchange, the one or more processors are to:

determine, based on the priority information, the preference for using the Diffie-Hellman key exchange after determining that the particular decryption technique is to be used to manage the encrypted traffic associated with the session.

10. The device of claim 7 , where, when determining the preference for using the Diffie-Hellman key exchange, the one or more processors are to:

determine, based on the priority information, a first priority of the Diffie-Hellman key exchange,

determine, based on the priority information, a second priority of an RSA key exchange, and

determine the preference for using the Diffie-Hellman key exchange based on the first priority of the Diffie-Hellman key exchange and the second priority of the RSA key exchange.

11. The device of claim 7 ,

where the one or more processors are further to:

determine whether a server device, associated with the session, supports use of the Diffie-Hellman key exchange to establish the session, and where, when establishing the session, the one or more processors are to:

establish the session based on determining whether the server device, associated with the session, supports use of the Diffie-Hellman key exchange to establish the session.

12. The device of claim 11 , where the session is established after determining that it is unknown whether the server device supports use of the Diffie-Hellman key exchange.

13. The device of claim 7 , where the one or more processors are further to:

receive the message for initiating the session,

wherein the message includes a server indicator for a server device associated with initiating the session, and

wherein the server cipher preference cache lookup is performed using the server indicator.

14. A non-transitory computer-readable medium storing instructions, the instructions comprising:

one or more instructions that, when executed by a device, cause the device to:

identify priority information associated with key exchange ciphers;

determine, based on the priority information, a first priority of a Diffie-Hellman key exchange;

determine, based on the priority information, a second priority of an RSA key exchange;

determine, based on the first priority of the Diffie-Hellman key exchange and the second priority of the RSA key exchange, a preference for using the Diffie-Hellman key exchange;

determine that it is unknown whether a server device, associated with a session, supports use of the Diffie-Hellman key exchange to establish the session; and

establish, after determining that is unknown whether the server device supports use of the Diffie-Hellman key exchange to establish the session, the session based on determining the preference for using the Diffie-Hellman key exchange.

15. The non-transitory computer-readable medium of claim 14 , where the instructions further comprise:

one or more instructions that, when executed by the device, cause the device to:

receive a message associated with initiating the session; and

determine client cipher information included in the message,

the client cipher information including the priority information associated with the key exchange ciphers.

16. The non-transitory computer-readable medium of claim 14 ,

where the instructions further comprise:

one or more instructions that, when executed by the device, cause the device to:

determine that a particular decryption technique is to be used to manage encrypted traffic associated with the session, and

where the preference for using the Diffie-Hellman key exchange is determined after determining that the particular decryption technique is to be used to manage the encrypted traffic associated with the session.

17. The non-transitory computer-readable medium of claim 14 ,

where the instructions further comprise:

one or more instructions that, when executed by the device, cause the device to:

receiving a message associated with initiating the session.

18. The non-transitory computer-readable medium of claim 17 , wherein the message includes a server indicator for the server device.

19. The non-transitory computer-readable medium of claim 14 , wherein the one or more instructions to determine that it is unknown whether the server device supports use of the Diffie-Hellman key exchange to establish the session comprise:

one or more instructions that, when executed by the device, cause the device to:

perform a server cipher preference cache lookup, using a server indicator of the server device, to determine that it is unknown whether the server device supports use of the Diffie-Hellman key exchange to establish the session.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 10, 2023
From: CHAUBEY, RAJEEV; MANTHENA, VENKATA RAMA RAJU
To: JUNIPER NETWORKS, INC.
Reel/Frame 062659/0398 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2018
From: CHAUBEY, RAJEEV; MANTHENA, VENKATA RAMA RAJU
To: JUNIPER NETWORKS, INC.
Reel/Frame 044975/0402 →
Continuity (2)
Continuation 14751605 · Jun 26, 2015
Related Publication 20180167207A1 · Jun 14, 2018