IP Library Granted Patent US 11,075,893
Granted Patent B2
US 11,075,893 · App. 16/595,818 · Granted Jul 27, 2021

Cryptographic proxy service

Inventor: Erich Stuntebeck (Marietta, GA)
Assignee: VMware, Inc.
H04L63/0464H04L9/14H04L9/30H04L9/3263H04L63/0281H04L63/0823H04L63/1408H04W12/02H04W12/033G06F21/6245H04L63/0428H04L63/0471H04L67/42H04W4/80
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,075,893
App. No.
16/595,818
Granted
Jul 27, 2021
Kind
B2
Abstract

A cryptographic proxy service may be provided. Upon determining that data associated with a network destination comprises at least some sensitive data, a cryptographic service may provide a security certificate associated with the network destination. The plurality of data may be encrypted according to the security certificate associated with the network destination and provided to the cryptographic service for re-encryption and transmission to the network destination.

Claims (52)

1. A method for providing a cryptographic proxy service, the method comprising:

receiving identification of a network destination where a computing device is attempting to transmit sensitive data, the sensitive data being identified prior to transmission based on comparing the network destination to a list of network destinations;

obtaining a spoofed security certificate that impersonates the network destination;

sending a first public key of the spoofed security certificate to the computing device for encrypting the sensitive data;

operating as a first certificate authority for the spoofed security certificate;

receiving the encrypted sensitive data;

decrypting the sensitive data using a private key of the spoofed security certificate;

conditionally blocking transmission of the sensitive data based on a status of a secure channel;

negotiating the secure channel with the network destination, wherein negotiating the secure channel comprises obtaining a second public key from a second certificate authority associated with the network destination;

encrypting the sensitive data according to the second public key; and

forwarding the encrypted sensitive data to the network destination based on the negotiating of the secure channel.

2. The method of claim 1 , wherein operating as the certificate authority includes installing a root certificate on the computing device that causes the computing device to accept the first public key.

3. The method of claim 1 , further comprising verifying, as a condition for sending the first public key, the computing device is in compliance with a compliance rule specifying at least one of an encryption requirement and a firmware-version requirement.

4. The method of claim 1 , wherein negotiating the secure channel includes accessing the second public key as previously received from the network destination.

5. The method of claim 1 , further comprising:

determining the secure channel cannot be established; and

notifying the computing device the secure channel cannot be established,

wherein forwarding the sensitive data includes forwarding the sensitive data to the network destination based on receiving an authorization from the computing device to send the sensitive data insecurely.

6. A non-transitory, computer-readable medium containing instructions that, when executed by a hardware-based processor, performs stages for providing a cryptographic proxy service, the stages comprising:

receiving identification of a network destination where a computing device is attempting to transmit sensitive data, the sensitive data being identified prior to transmission based on comparing the network destination to a list of network destinations;

obtaining a spoofed security certificate that impersonates the network destination;

sending a first public key of the spoofed security certificate to the computing device for encrypting the sensitive data;

operating as a first certificate authority for the spoofed security certificate;

receiving the encrypted sensitive data;

decrypting the sensitive data using a private key of the spoofed security certificate;

conditionally blocking transmission of the sensitive data based on a status of a secure channel;

negotiating the secure channel with the network destination, wherein negotiating the secure channel comprises obtaining a second public key from a second certificate authority associated with the network destination;

encrypting the sensitive data according to the second public key; and

forwarding the encrypted sensitive data to the network destination based on the negotiating of the secure channel.

7. The non-transitory, computer-readable medium of claim 6 , wherein operating as the certificate authority includes installing a root certificate on the computing device that causes the computing device to accept the first public key.

8. The non-transitory, computer-readable medium of claim 6 , the stages further comprising verifying, as a condition for sending the first public key, the computing device is in compliance with a compliance rule specifying at least one of an encryption requirement and a firmware-version requirement.

9. The non-transitory, computer-readable medium of claim 6 , wherein negotiating the secure channel includes accessing the second public key as previously received from the network destination.

10. The non-transitory, computer-readable medium of claim 6 , the stages further comprising:

determining the secure channel cannot be established; and

notifying the computing device the secure channel cannot be established,

wherein forwarding the sensitive data includes forwarding the sensitive data to the network destination based on receiving an authorization from the computing device to send the sensitive data insecurely.

11. A cryptographic proxy system comprising:

a memory storage including a non-transitory, computer-readable medium comprising instructions; and

a computing device including a hardware-based processor that executes the instructions to carry out stages comprising:

receiving identification of a network destination where a computing device is attempting to transmit sensitive data, the sensitive data being identified prior to transmission based on comparing the network destination to a list of network destinations;

obtaining a spoofed security certificate that impersonates the network destination;

sending a first public key of the spoofed security certificate to the computing device for encrypting the sensitive data;

operating as a first certificate authority for the spoofed security certificate;

receiving the encrypted sensitive data;

decrypting the sensitive data using a private key of the spoofed security certificate;

conditionally blocking transmission of the sensitive data based on a status of a secure channel;

negotiating the secure channel with the network destination, wherein negotiating the secure channel comprises obtaining a second public key from a second certificate authority associated with the network destination;

encrypting the sensitive data according to the second public key; and

forwarding the encrypted sensitive data to the network destination based on the negotiating of the secure channel.

12. The system of claim 11 , wherein operating as the certificate authority includes installing a root certificate on the computing device that causes the computing device to accept the first public key.

13. The system of claim 11 , the stages further comprising verifying, as a condition for sending the first public key, the computing device is in compliance with a compliance rule specifying at least one of an encryption requirement and a firmware-version requirement.

14. The system of claim 11 , wherein negotiating the secure channel includes accessing the second public key as previously received from the network destination.

Assignments (5)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: VMWARE LLC
To: OMNISSA, LLC
Reel/Frame 068327/0365 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2024
From: STUNTEBECK, ERICH
To: AIRWATCH LLC
Reel/Frame 067879/0135 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2024
From: AIRWATCH LLC
To: VMWARE, INC.
Reel/Frame 067879/0157 →
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0314 →