IP Library Granted Patent US 11,418,542
Granted Patent B2
US 11,418,542 · App. 16/750,499 · Granted Aug 16, 2022

Identification of unknown traffic based on transport layer security extensions

Inventors: Jenny Anniina Heino (Espoo, FI); Tuomo Syvanne (Espoo, FI); Welf Christian Jalio (Espoo, FI); Olli-Pekka Niemi (Espoo, FI)
Assignee: FORCEPOINT LLC
H04L63/166H04L63/18H04L63/20H04L67/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,418,542
App. No.
16/750,499
Granted
Aug 16, 2022
Kind
B2
Abstract

A system for providing network data processing, comprising a processor operating one of more algorithms that are configured to interface with one or more clients to receive a client hello data message. A transport layer security extension extraction system operating on the processor and configured to extract an extension from the client hello data message. A transport layer security extension identification system operating on the processor and configured to process the extension from the client hello data message and to identify a data networking session using the extension.

Claims (36)

1. A system for providing network data processing, comprising:

a processor operating one of more algorithms that are configured to interface with one or more clients to receive a client hello data message;

a transport layer security extension extraction system operating on the processor and configured to extract a protocol negotiation extension from the client hello data message;

a transport layer security extension identification system operating on the processor and configured to process the protocol negotiation extension from the client hello data message and to identify a data networking session protocol using the protocol negotiation extension; and

a transport layer security based security system configured to process the protocol negotiation extension from the client hello data message, to identify the data networking session security protocol using the protocol negotiation extension and to modify the data networking session security protocol in response to the identified data networking session security protocol.

2. The system of claim 1 further comprising the processor configured to interface with one or more servers and to receive a server hello data message and to modify the data networking session security protocol in response to the server hello data message.

3. The system of claim 2 further comprising the transport layer security extension extraction system configured to extract an extension from the server hello data message and the processor configured to modify the data networking session security protocol in response to the extracted extension from the server hello data message.

4. The system of claim 3 further comprising the transport layer security extension identification system configured to process the protocol negotiation extension from the server hello data message and to implement a Next Protocol Negotiation.

5. The system of claim 3 further comprising the transport layer security based security system configured to process the protocol negotiation extension from the server hello data message and to identify whether the data networking session is secure using the protocol negotiation extension.

6. The system of claim 1 wherein the processor is configured to determine whether client-server communications have been compromised.

7. The system of claim 1 wherein the processor is configured to set a flag to indicate that client-server communications may have been compromised.

8. The system of claim 1 wherein the processor is configured to set a flag to indicate that client-server communications may have been compromised and to determine whether data traffic is secure if the flag indicates that client-server communications may have been compromised.

9. The system of claim 1 wherein the processor is configured to add security values to application layer protocols.

10. The system of claim 1 wherein the processor is configured to add security values to application layer protocols and to use the security values to verify that client-server communications have not been compromised by a third party.

11. A method for providing network data processing, comprising:

interfacing with one or more clients to receive a client hello data message using a processor;

extracting a protocol negotiation extension from the client hello data message using the processor;

processing the protocol negotiation extension from the client hello data message to identify a data networking session using the protocol negotiation extensions;

processing the protocol negotiation extension from the client hello data message to identify the data networking session security protocol using the protocol negotiation extension; and

modifying the data networking session security protocol in response to the identified data networking session security protocol.

12. The method of claim 11 further comprising using the processor to interface with one or more servers and to receive a server hello data message and to determine whether client-server communications have been compromised.

13. The method of claim 12 further comprising extracting the protocol negotiation extension from the server hello data message with the processor.

14. The method of claim 13 further comprising processing the protocol negotiation extension from the server hello data message using the processor to identify the data networking session using the protocol negotiation extension.

15. The method of claim 13 further comprising processing the protocol negotiation extension from the server hello data message with the processor to identify whether the data networking session is secure using the protocol negotiation extension.

16. A method for providing network data processing, comprising:

interfacing with one or more servers to receive a server hello data message using a processor;

extracting a protocol negotiation extension from the server hello data message using the processor;

processing the protocol negotiation extension from the server hello data message to identify a data networking session using the protocol negotiation extension; and

processing the protocol negotiation extension from the client hello data message, to identify the data networking session security protocol using the protocol negotiation extension; and

modifying the data networking session security protocol in response to the identified data networking session security protocol.

17. The method of claim 16 further comprising:

using the processor to interface with one or more clients and to receive a client hello data message;

determining whether the server hello message and the client hello message are associated with the data networking session.

18. The method of claim 17 further comprising extracting the protocol negotiation extension from the client hello data message with the processor.

19. The method of claim 18 further comprising processing the protocol negotiation extension from the client hello data message using the processor to identify the data networking session using the protocol negotiation extension.

20. The method of claim 18 further comprising processing the protocol negotiation extension from the client hello data message with the processor to identify whether the data networking session is secure using the protocol negotiation extension.

Assignments (7)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
PATENT SECURITY AGREEMENT Recorded Aug 31, 2021
From: FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS THE COLLATERAL AGENT
Reel/Frame 057651/0150 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 056294/0618 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056216/0204 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055452/0207 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Feb 27, 2020
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 052045/0482 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 23, 2020
From: HEINO, JENNY ANNIINA; SYVANNE, TUOMO; JALIO, WELF CHRISTIAN; NIEMI, OLLI-PEKKA
To: FORCEPOINT LLC
Reel/Frame 051599/0674 →
Continuity (1)
Related Publication 20210234895A1 · Jul 29, 2021