IP Library Granted Patent US 11,665,207
Granted Patent B2
US 11,665,207 · App. 17/515,963 · Granted May 30, 2023

Inline secret sharing

Inventors: Benjamin Thomas Higgins (Shoreline, WA); Jesse Abraham Rothstein (Seattle, WA)
Assignee: ExtraHop Networks, Inc.
H04L63/30G06F21/606H04L43/12H04L63/0218H04L63/0428H04L63/061H04L63/062H04L63/065G06F21/50H04L43/026H04L43/062H04L63/166H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,665,207
App. No.
17/515,963
Filed
Nov 1, 2021
Granted
May 30, 2023
Kind
B2
Art Unit
2442
USPC
709/224
Abstract

Embodiments are directed to monitoring communication between computers using network monitoring computers (NMCs). NMCs identify a secure communication session established between two of the computers based on an exchange of handshake information associated with the secure communication session. Key information that corresponds to the secure communication session may be obtained from a key provider such that the key information may be encrypted by the key provider. NMCs may decrypt the key information. NMCs may derive the session key based on the decrypted key information and the handshake information. NMCs may decrypt network packets included in the secure communication session. NMCs may be employed to inspect the one or more decrypted network packets to execute one or more rule-based policies.

Claims (41)

1. A method for monitoring communication over a network between a plurality of computers, with one or more network monitoring computers (NMCs) that perform actions, comprising:

employing handshake information communicated between two computers to determine establishment of a secure communication session;

determining a session key based on decryption of encrypted key information that corresponds to the secure communication session, wherein decrypted key information is added to the handshake information; and

employing the session key to decrypt one or more encrypted network packets that are included in the secure communication session.

2. The method of claim 1 , further comprising:

employing the one or more decrypted network packets to execute one or more rule-based policies.

3. The method of claim 1 , further comprising:

selectively decrypting the one or more network packets based on one or more characteristics of one or more other network flows unassociated with the secure communication session.

4. The method of claim 1 , further comprising:

selectively decrypt one or more network flows associated with the secure communication channel based on one or more characteristics of one or more other flows unassociated with the secure communication session.

5. The method of claim 1 , further comprising:

providing inline proxying of communication over the secure communication session for the two computers.

6. The method of claim 1 , wherein the two computers further comprise employing a different secure communication protocol for the secure communication session than the other computer.

7. A system for monitoring communication over a network between two or more computers, comprising:

one or more network monitoring computers (NMCs) that communicate over the network, including:

a memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

employing handshake information communicated between two computers to determine establishment of a secure communication session;

determining a session key based on decryption of encrypted key information that corresponds to the secure communication session, wherein decrypted key information is added to the handshake information; and

employing the session key to decrypt one or more encrypted network packets that are included in the secure communication session.

8. The system of claim 7 , further comprising:

employing the one or more decrypted network packets to execute one or more rule-based policies.

9. The system of claim 7 , further comprising:

selectively decrypting the one or more network packets based on one or more characteristics of one or more other network flows unassociated with the secure communication session.

10. The system of claim 7 , further comprising:

selectively decrypt one or more network flows associated with the secure communication channel based on one or more characteristics of one or more other flows unassociated with the secure communication session.

11. The system of claim 7 , further comprising:

providing inline proxying of communication over the secure communication session for the two computers.

12. The system of claim 7 , wherein the two computers further comprise employing a different secure communication protocol for the secure communication session than the other computer.

13. A processor readable non-transitory storage media that includes instructions for monitoring communication over a network between two or more computers, wherein execution of the instructions by one or more processors on one or more network monitoring computers (NMCs) performs actions, comprising:

employing handshake information communicated between two computers to determine establishment of a secure communication session;

determining a session key based on decryption of encrypted key information that corresponds to the secure communication session, wherein decrypted key information is added to the handshake information; and

employing the session key to decrypt one or more encrypted network packets that are included in the secure communication session.

14. The processor readable non-transitory storage media of claim 13 , wherein execution of the instructions performs further actions, comprising:

employing the one or more decrypted network packets to execute one or more rule-based policies.

15. The processor readable non-transitory storage media of claim 13 , wherein execution of the instructions performs further actions, comprising:

selectively decrypting the one or more network packets based on one or more characteristics of one or more other network flows unassociated with the secure communication session.

16. The processor readable non-transitory storage media of claim 13 , wherein execution of the instructions performs further actions, comprising:

selectively decrypt one or more network flows associated with the secure communication channel based on one or more characteristics of one or more other flows unassociated with the secure communication session.

17. The processor readable non-transitory storage media of claim 13 , wherein execution of the instructions performs further actions, comprising:

providing inline proxying of communication over the secure communication session for the two computers.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 1, 2021
From: HIGGINS, BENJAMIN THOMAS; ROTHSTEIN, JESSE ABRAHAM
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 057982/0789 →
Continuity (3)
Continuation 15971843 · May 4, 2018
Continuation 15793880 · Oct 25, 2017
Related Publication 20220060518A1 · Feb 24, 2022
Cited By (7)
US 12,225,030 US 12,309,192 US 12,355,816 US 12,483,384 US 12,587,535 US 12,647,441 US 12,652,312