IP Library › Granted Patent US 11,483,141
Granted Patent B2
US 11,483,141 · App. 16/891,871 · Granted Oct 25, 2022

Key broker for a network monitoring device, and applications thereof

Inventors: John Watson (Falls Church, VA); Christopher Roosenraad (Vienna, VA); Peter P. Kofira (Powhatan, VA); Travis Scheponik (Midlothian, VA); Aaron Eppert (Lawrenceburg, IN)
Assignee: Capital One Services, LLC
H04L9/083H04L9/0891H04L9/0894H04L43/12H04L63/306H04L69/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,483,141
App. No.
16/891,871
Granted
Oct 25, 2022
Kind
B2
Abstract

A key broker monitors network traffic metadata and determines which decryption keys are required at one or more packet brokers in order to decrypt relevant traffic required by various network monitoring devices. The key broker retrieves the required keys from a secure keystore distributes them, as needed, to the network packet brokers, and dynamically updates the decryption keys stored in the network packet brokers in response to changes in network traffic.

Claims (56)

1. A system for managing distribution of digital security keys, the system comprising:

a network terminal access point (TAP) configured to intercept a packet on a computer network;

a network monitoring device comprising a key datastore and configured to receive the intercepted packet and decrypt the intercepted packet when a corresponding decryption key is stored in the key datastore;

a secure keystore configured to store decryption keys;

a key broker configured to:

receive metadata corresponding to the intercepted packet;

retrieve from the secure keystore, based on the metadata, the decryption key corresponding to the intercepted packet;

provide the decryption key to the network monitoring device for storage in the key datastore; and

wherein the key broker is further configured to remove the decryption key from the network monitoring device based on a decryption key storage limit of the network monitoring device and a priority of the decryption key.

2. The system of claim 1 , further comprising:

an intrusion detection system configured to:

collect the metadata, corresponding to packets to be decrypted, based on a server name indication (SNI) field retrieved from network traffic, or a common name (CN) field, or a subject alternative name (SAN) field of a security certificate retrieved from network traffic; and

send the metadata to the key broker; and

wherein the key broker is further configured to:

store the metadata in a tracking database.

3. The system of claim 1 , wherein the key broker is further configured to store tracking data corresponding to both the network monitoring device and the decryption key provided to the network monitoring device.

4. The system of claim 1 , wherein the key broker is further configured to store a lease time corresponding to the decryption key.

5. The system of claim 4 , wherein the key broker is further configured to remove the decryption key from the network monitoring device in response to expiration of the lease time.

6. The system of claim 1 , wherein the metadata comprises domain information or an unencrypted destination corresponding to the packet.

7. The system of claim 1 , wherein the secure keystore comprises an offline storage device.

8. The system of claim 1 , wherein the key broker is further configured to:

receive a request from the network monitoring device; and

provide the decryption key in response to the request.

9. A method of managing decryption keys in a network environment, the method comprising:

receiving, by a processor, metadata related to an encrypted network packet intercepted from network traffic;

retrieving, based on the metadata, a decryption key from a secure keystore;

providing the retrieved decryption key to a network monitoring device;

storing tracking data corresponding to both the network monitoring device and the decryption key provided to the network monitoring device;

updating the decryption key provided to the network monitoring device;

updating the tracking data in response to the updating of the decryption key; and

removing the decryption key from the network monitoring device based on a decryption key storage limit of the network monitoring device and a priority of the decryption key.

10. The method of claim 9 , wherein the storing of the tracking data comprises storing an identifier of the decryption key and an identifier of the network monitoring device.

11. The method of claim 9 , wherein the updating of the decryption key comprises updating the decryption key in response to a change in the network traffic.

12. The method of claim 9 , wherein the storing of the tracking data comprises storing a lease time corresponding to the decryption key; and

wherein the updating of the decryption key comprises removing the decryption key from the network monitoring device in response to expiration of the lease time.

13. The method of claim 9 , further comprising:

receiving a request, comprising the metadata, from the network monitoring device;

wherein the retrieving comprises retrieving, in response to the request, the decryption key from the secure keystore;

wherein the providing of the retrieved decryption key comprises storing the decryption key on a key datastore of the network monitoring device.

14. The method of claim 9 , wherein the metadata comprises one or more of: domain information, an unencrypted portion of a network packet, or an identifier of a security certificate corresponding to the decryption key.

15. A non-volatile computer-readable device storing instructions that, when executed by a processor, cause the processor to perform the method steps of:

receiving, by the processor, metadata related to an encrypted network packet intercepted from network traffic;

retrieving, based on the metadata, a decryption key from a secure keystore;

providing the retrieved decryption key to a network monitoring device;

storing tracking data corresponding to both the network monitoring device and the decryption key provided to the network monitoring device;

updating the decryption key provided to the network monitoring device;

updating the tracking data in response to the updating of the decryption key; and

removing the decryption key from the network monitoring device based on a decryption key storage limit of the network monitoring device and a priority of the decryption key.

16. The non-volatile computer-readable device of claim 15 , wherein the storing of the tracking data comprises storing an identifier of the decryption key and an identifier of the network monitoring device.

17. The non-volatile computer-readable device of claim 15 , wherein the updating of the decryption key comprises updating the decryption key, in response to a change in the network traffic.

18. The non-volatile computer-readable device of claim 15 , wherein the storing of the tracking data comprises storing a lease time corresponding to the decryption key; and

wherein the updating of the decryption key comprises removing the decryption key from the network monitoring device in response to expiration of the lease time.

19. The non-volatile computer-readable device of claim 15 , wherein the method steps further comprise:

receiving a request, comprising the metadata, from the network monitoring device;

wherein the retrieving comprises retrieving, in response to the request, the decryption key from the secure keystore;

wherein the providing of the retrieved decryption key comprises storing the decryption key on a key datastore of the network monitoring device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 11, 2020
From: WATSON, JOHN; ROOSENRAAD, CHRISTOPHER; KOFIRA, PETER P.; SCHEPONIK, TRAVIS; EPPERT, AARON
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 052905/0182 →
Continuity (1)
Related Publication 20210385070A1 · Dec 9, 2021
Cited By (1)
US 12,231,545