IP Library Granted Patent US 12,095,747
Granted Patent B2
US 12,095,747 · App. 17/357,336 · Granted Sep 17, 2024

Cryptographic proxy service

Inventor: Erich Stuntebeck (Johns Creek, GA)
Assignee: Omnissa, LLC
H04L63/0464H04L9/14H04L9/30H04L9/3263H04L63/0281H04L63/0823H04L63/1408G06F21/6245H04L63/0428H04L63/0471H04L67/01H04W4/80H04W12/02H04W12/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,095,747
App. No.
17/357,336
Granted
Sep 17, 2024
Kind
B2
Abstract

A cryptographic proxy service may be provided. Upon determining that data associated with a network destination comprises at least some sensitive data, a cryptographic service may provide a security certificate associated with the network destination. The plurality of data may be encrypted according to the security certificate associated with the network destination and provided to the cryptographic service for re-encryption and transmission to the network destination.

Claims (44)

1. A method for providing a cryptographic proxy service, the method comprising:

identifying a network destination to which a computing device is requesting or attempting to transmit sensitive data, the sensitive data being identified prior to transmission based on comparing the network destination to a list of network destinations;

obtaining a spoofed security certificate of the network destination;

sending a first public key, which is a public key of the spoofed security certificate, to the computing device for encrypting the sensitive data;

receiving the encrypted sensitive data;

decrypting the sensitive data using a private key of the spoofed security certificate;

determining whether or not an actual security certificate of the network destination has already been obtained;

determining data to be the sensitive data by applying a plurality of content evaluation rules to the data, wherein the applied content evaluation rules include keywords, expressions for types of data, and destination domain comparison;

responsive to determining that the actual security certificate of the network destination has already been obtained, encrypting the sensitive data according to a public key of the actual security certificate, forwarding the encrypted sensitive data to the network destination; and

responsive to determining that the security certificate of the network destination has not already been obtained, obtaining a second public key from a certificate authority associated with the network destination, encrypting the sensitive data using the second public key, and forwarding the encrypted sensitive data to the network destination.

2. The method of claim 1 , further comprising operating as a certificate authority for the spoofed security certificate.

3. The method of claim 1 , further comprising installing a root certificate on the computing device based on which the computing device accepts the first public key.

4. The method of claim 1 , further comprising verifying, as a condition for sending the first public key, that the computing device is in compliance with a compliance rule specifying at least one of an encryption requirement and a firmware-version requirement.

5. The method of claim 1 , further comprising storing the second public key for future use in establishing a secure channel with the network destination.

6. A non-transitory, computer-readable medium containing instructions that, when executed by a hardware-based processor, performs stages for providing a cryptographic proxy service, the stages comprising:

identifying a network destination to which a computing device is requesting or attempting to transmit sensitive data, the sensitive data being identified prior to transmission based on comparing the network destination to a list of network destinations;

obtaining a spoofed security certificate of the network destination;

sending a first public key, which is a public key of the spoofed security certificate, to the computing device for encrypting the sensitive data;

receiving the encrypted sensitive data;

decrypting the sensitive data using a private key of the spoofed security certificate;

determining whether or not an actual security certificate of the network destination has already been obtained;

determining data to be the sensitive data by applying a plurality of content evaluation rules to the data, wherein the applied content evaluation rules include keywords, expressions for types of data, and destination domain comparison;

responsive to determining that the actual security certificate of the network destination has already been obtained, encrypting the sensitive data according to a public key of the actual security certificate, forwarding the encrypted sensitive data to the network destination; and

responsive to determining that the security certificate of the network destination has not already been obtained, obtaining a second public key from a certificate authority associated with the network destination, encrypting the sensitive data using the second public key, and forwarding the encrypted sensitive data to the network destination.

7. The non-transitory, computer-readable medium of claim 6 , the stages further comprising operating as a certificate authority for the spoofed security certificate.

8. The non-transitory, computer-readable medium of claim 6 , the stages further comprising installing a root certificate on the computing device based on which the computing device accepts the first public key.

9. The non-transitory, computer-readable medium of claim 6 , the stages further comprising verifying, as a condition for sending the first public key, that the computing device is in compliance with a compliance rule specifying at least one of an encryption requirement and a firmware-version requirement.

10. The non-transitory, computer-readable medium of claim 6 , the stages further comprising storing the second public key for future use in establishing a secure channel with the network destination.

11. A cryptographic proxy system comprising:

a memory storage including a non-transitory, computer-readable medium comprising instructions; and

a server including a hardware-based processor that executes the instructions to carry out stages comprising:

identifying a network destination to which a computing device is requesting or attempting to transmit sensitive data, the sensitive data being identified prior to transmission based on comparing the network destination to a list of network destinations;

obtaining a spoofed security certificate of the network destination;

sending a first public key, which is a public key of the spoofed security certificate, to the computing device for encrypting the sensitive data;

receiving the encrypted sensitive data;

decrypting the sensitive data using a private key of the spoofed security certificate;

determining whether or not an actual security certificate of the network destination has already been obtained;

determining data to be the sensitive data by applying a plurality of content evaluation rules to the data, wherein the applied content evaluation rules include keywords, expressions for types of data, and destination domain comparison;

responsive to determining that the actual security certificate of the network destination has already been obtained, encrypting the sensitive data according to a public key of the actual security certificate, forwarding the encrypted sensitive data to the network destination; and

responsive to determining that the security certificate of the network destination has not already been obtained, obtaining a second public key from a certificate authority associated with the network destination, encrypting the sensitive data using the second public key, and forwarding the encrypted sensitive data to the network destination.

12. The system of claim 11 , the stages further comprising operating as a certificate authority for the spoofed security certificate.

13. The system of claim 11 , the stages further comprising installing a root certificate on the computing device based on which the computing device accepts the first public key.

14. The system of claim 11 , the stages further comprising verifying, as a condition for sending the first public key, that the computing device is in compliance with a compliance rule specifying at least one of an encryption requirement and a firmware-version requirement.

15. The system of claim 11 , the stages further comprising storing the second public key for future use in establishing a secure channel with the network destination.

Assignments (2)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: AIRWATCH LLC
To: OMNISSA, LLC
Reel/Frame 068327/0670 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
Continuity (4)
Continuation 16595818 · Oct 8, 2019
Continuation 15439349 · Feb 22, 2017
Division 14311385 · Jun 23, 2014
Related Publication 20210320906A1 · Oct 14, 2021
Cited By (2)
US 12,457,195 US 12,627,706