IP Library › Granted Patent US 12,231,545
Granted Patent B2
US 12,231,545 · App. 17/969,798 · Granted Feb 18, 2025

Key broker for a network monitoring device, and applications thereof

Inventors: John Watson (Falls Church, VA); Christopher Roosenraad (Vienna, VA); Peter P. Kofira (Powhatan, VA); Travis Scheponik (Midlothian, VA); Aaron Eppert (Lawrenceburg, IN)
Assignee: Capital One Services, LLC
H04L9/083H04L9/0891H04L9/0894H04L43/12H04L63/306H04L69/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,231,545
App. No.
17/969,798
Filed
Oct 20, 2022
Granted
Feb 18, 2025
Kind
B2
Examiner
LE, CHAU D
Art Unit
2408
USPC
380/277
Abstract

A key broker monitors network traffic metadata and determines which decryption keys are required at one or more packet brokers in order to decrypt relevant traffic required by various network monitoring devices. The key broker retrieves the required keys from a secure keystore distributes them, as needed, to the network packet brokers, and dynamically updates the decryption keys stored in the network packet brokers in response to changes in network traffic.

Claims (57)

1. A system for managing distribution of digital security keys, the system comprising:

one or more network sensors comprising network terminal access points (TAPs) configured to intercept encrypted packets on a computer network;

one or more servers including:

a website category service configured to identify the encrypted packets that should or should not be decrypted based on a privacy policy, wherein the privacy policy designates the encrypted packets related to health care or personal banking data as the encrypted packets that should not be decrypted;

a key broker configured to:

remove one or more decryption keys for the encrypted packets based on a storage limit and a priority of the one or more decryption keys, and

examine the encrypted packets to determine whether they should be decrypted based on the privacy policy; and

a key ingestion service configured to remove the one or more decryption keys identified as those that should not be decrypted based on the privacy policy.

2. The system of claim 1 , wherein the one or more servers further includes a key datastore configured to decrypt the encrypted packets identified as those that should be decrypted based on the privacy policy.

3. The system of claim 2 , wherein the key broker is further configured to:

provide the one or more decryption keys to a network monitoring device to distribute to the key datastore for storage in the key datastore.

4. The system of claim 3 , wherein the key broker is further configured to:

store tracking data corresponding to both the network monitoring device and the one or more decryption keys.

5. The system of claim 3 , wherein the key broker is further configured to:

remove the one or more decryption keys from the network monitoring device in response to expiration of a lease time of the one or more decryption keys.

6. The system of claim 3 , wherein the key broker is further configured to:

receive a request from the network monitoring device; and

provide the one or more decryption keys in response to the request.

7. The system of claim 1 , wherein the one or more servers further includes:

an intrusion detection system configured to:

collect metadata corresponding to the encrypted packets, wherein the metadata includes a server name indication (SNI) field retrieved from network traffic, a common name (CN) field, or a subject alternative name (SAN) field of a security certificate retrieved from network traffic;

send the metadata to the key broker; and

wherein the key broker is further configured to:

store the metadata in a tracking database.

8. The system of claim 7 , wherein the metadata comprises domain information or an unencrypted destination corresponding to the encrypted packets.

9. The system of claim 1 , wherein the key broker is further configured to:

store a lease time corresponding to the one or more decryption keys.

10. A method for managing distribution of digital security keys, the method comprising:

intercepting, by network terminal access points (TAPs), encrypted packets on a computer network;

identifying, by a website category service, the encrypted packets that should or should not be decrypted based on a privacy policy, wherein the privacy policy designates the encrypted packets related to health care or personal banking data as the encrypted packets that should not be decrypted;

examining, by a key broker, the encrypted packets to determine whether they should be decrypted based on the privacy policy;

removing, by a key ingestion service, one or more decryption keys for the encrypted packets identified as those that should not be decrypted based on the privacy policy; and

removing, by the key broker, the one or more decryption keys based on a storage limit and a priority of the one or more decryption keys.

11. The method of claim 10 , further comprising decrypting, by a key datastore, the encrypted packets identified as those that should be decrypted based on the privacy policy.

12. The method of claim 11 , further comprising:

providing, by the key broker, the one or more decryption keys to a network monitoring device to be distributed to the key datastore for storage in the key datastore.

13. The method of claim 12 , further comprising:

storing, by the key broker, tracking data corresponding to both the network monitoring device and the one or more decryption keys.

14. The method of claim 12 , further comprising:

removing, by the key broker, the one or more decryption keys from the network monitoring device in response to expiration of a lease time of the one or more decryption keys.

15. The method of claim 12 , further comprising:

receiving, by the key broker, a request from the network monitoring device; and

providing, by the key broker, the one or more decryption keys in response to the request.

16. The method of claim 10 , further comprising:

collecting, by an intrusion detection system, metadata corresponding to the encrypted packets, wherein the metadata includes a server name indication (SNI) field retrieved from network traffic, a common name (CN) field, or a subject alternative name (SAN) field of a security certificate retrieved from network traffic;

sending, by the intrusion detection system, the metadata to the key broker; and

storing, by the key broker, the metadata in a tracking database.

17. The method of claim 16 , wherein the metadata comprises domain information or an unencrypted destination corresponding to the encrypted packets.

18. The method of claim 10 , further comprising:

storing, by the key broker, a lease time corresponding to the one or more decryption keys.

19. A non-transitory computer-readable storage device having instructions stored thereon, execution of which, by one or more processors, causes the one or more processors to perform operations comprising:

intercepting, by network terminal access points (TAPs), encrypted packets on a computer network;

identifying, by a website category service, the encrypted packets that should or should not be decrypted based on a privacy policy, wherein the privacy policy designates the encrypted packets related to health care or personal banking data as the encrypted packets that should not be decrypted;

examining, by a key broker, the encrypted packets to determine whether they should be decrypted based on the privacy policy;

removing, by a key ingestion service, one or more decryption keys identified as those that should not be decrypted based on the privacy policy; and

removing, by the key broker, the one or more decryption keys for the encrypted packets based on a storage limit and a priority of the one or more decryption keys.

20. The non-transitory computer readable storage device of claim 19 , wherein operations further comprise decrypting, by a key datastore, the encrypted packets identified as those that should be decrypted based on the privacy policy.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 20, 2022
From: WATSON, JOHN; ROOSENRAAD, CHRISTOPHER; KOFIRA, PETER B.; SCHEPONIK, TRAVIS; EPPERT, AARON
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 061479/0829 →
Continuity (2)
Continuation 16891871 · Jun 3, 2020
Related Publication 20230040466A1 · Feb 9, 2023
References Cited (34)
US 6134660A · Boneh · 2000 [cited by examiner]
US 7590844B1 · Sherman et al. · 2009 [cited by applicant]
US 8590057B1 · Mayblum et al. · 2013 [cited by applicant]
US 9489519B2 · Feroz · 2016 [cited by examiner]
US 10205712B2 · Smith et al. · 2019 [cited by applicant]
US 10291651B1 · Chaubey · 2019 [cited by examiner]
US 10326741B2 · Rothstein et al. · 2019 [cited by applicant]
US 11483141B2 · Watson et al. · 2022 [cited by applicant]
US 20090060195A1 · Mikami et al. · 2009 [cited by applicant]
US 20090240947A1 · Goyal · 2009 [cited by examiner]
US 20110154019A1 · Wang · 2011 [cited by examiner]
US 20130046993A1 · Jueneman et al. · 2013 [cited by applicant]
US 20130160145A1 · Henzie · 2013 [cited by examiner]
US 20130276065A1 · Kumar · 2013 [cited by examiner]
US 20140351573A1 · Martini · 2014 [cited by examiner]
US 20150082035A1 · Medvinsky · 2015 [cited by applicant]
US 20150261972A1 · Lee · 2015 [cited by examiner]
US 20170163736A1 · Jiang et al. · 2017 [cited by applicant]
US 20170237777A1 · Joch et al. · 2017 [cited by applicant]
US 20180054304A1 · Tanizawa · 2018 [cited by examiner]
US 20180062854A1 · Kancharla et al. · 2018 [cited by applicant]
US 20180191501A1 · Lindermann · 2018 [cited by applicant]
US 20180288021A1 · Basin · 2018 [cited by applicant]
US 20190068564A1 · Putatunda et al. · 2019 [cited by applicant]
US 20190097791A1 · Hersans et al. · 2019 [cited by applicant]
US 20190229908A1 · Peddada · 2019 [cited by examiner]
US 20190319786A1 · Das · 2019 [cited by examiner]
US 20190356694A1 · Wang · 2019 [cited by examiner]
US 20210111879A1 · Mistry · 2021 [cited by examiner]
US 20210243168A1 · Giblin · 2021 [cited by applicant]
International Search Report and Written Opinion of the International Searching Authority directed to related International Patent Application No. PCT/US 21/35746, mailed Oct. 18, 2021; 30 pages. [cited by applicant]
Sarah Diesburg et al., “TrueErase: Per-File Secure Deletion for the Storage Data Path”, ACM, p. 439-448 (2012). [cited by applicant]
Aashaka Shah, “Analyzing the impact of (GDPR) on storage systems”, 11th USENIZ Workshop, 7 pages (2019). [cited by applicant]
J. Li, S. Singhal, “Managing Data Retention Policies at Scale”, IEEE Transactions On Network and Service Management, vol. 9, No. 4, Dec. 2012, 397-406. [cited by applicant]