IP Library Granted Patent US 10,298,615
Granted Patent B2
US 10,298,615 · App. 15/955,382 · Granted May 21, 2019

Splicing into an active TLS session without a certificate or private key

Inventors: Charles E. Gero (Quincy, MA); Michael R. Stone (Cambridge, MA)
Assignee: Akamai Technologies, Inc.
H04L63/166H04L9/0618H04L9/0891H04L9/14H04L9/3242H04L63/00H04L63/0272H04L63/0281H04L63/0428H04L63/0435H04L63/168H04L67/142H04L9/0844
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,298,615
App. No.
15/955,382
Granted
May 21, 2019
Kind
B2
Abstract

An origin server selectively enables an intermediary (e.g., an edge server) to shunt into and out of an active TLS session that is on-going between a client and the origin server. The technique allows for selective pieces of a data stream to be delegated from an origin to the edge server for the transmission (by the edge server) of authentic cached content, but without the edge server having the ability to obtain control of the entire stream or to decrypt arbitrary data after that point. The technique enables an origin to authorize the edge server to inject cached data at certain points in a TLS session, as well as to mathematically and cryptographically revoke any further access to the stream until the origin deems appropriate.

Claims (12)

1. A method operative within a machine operating as a second computing entity in association with an intermediary, the intermediary located between a first computing entity and the second computing entity, the first and second computing entities having established between them an active cryptographic session, comprising:

providing to the intermediary a first instruction to splice into the active cryptographic session, wherein responsive to receipt of the first instruction the intermediary splices into the active cryptographic session and carries out at least one action with respect to information within one of: an encrypted request, and an encrypted response flowing through the intermediary; and

providing to the intermediary a second instruction to shunt out of the active cryptographic session, wherein responsive to receipt of the second instruction the intermediary shunts out of the active cryptographic session, after which access by the intermediary to information within the encrypted request or the encrypted response is revoked.

2. The method as described in claim 1 wherein the active cryptographic session is a TLS session.

3. The method as described in claim 1 wherein the first instruction includes a decryption key associated with the active cryptographic session.

4. The method as described in claim 1 wherein the second instruction is associated with a renegotiation of the active cryptographic session.

5. The method as described in claim 1 wherein the first computing entity is a client application, and the second computing entity is an origin server.

6. The method as described in claim 1 wherein the at least one action injects into the active cryptographic session content cached at the machine.

7. The method as described in claim 1 further including restricting visibility into an encrypted request or encrypted response except upon the second computing entity providing the first instruction.

8. The method as described in claim 1 wherein upon receipt of the first instruction the intermediary decrypts data while inhibiting contribution to the active cryptographic session.

9. The method as described in claim 1 wherein upon receipt of the first instruction the intermediary performs a write operation with respect to the active cryptographic session.

10. The method as described in claim 9 wherein the write operation is a one-time write operation.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 8, 2018
From: GERO, CHARLES E.; STONE, MICHAEL
To: AKAMAI TECHNOLOGIES, INC.
Reel/Frame 045740/0400 →
Continuity (5)
Continuation 15390599 · Dec 26, 2016
Continuation 14850991 · Sep 11, 2015
Continuation 14268657 · May 2, 2014
Provisional Application 61818979 · May 3, 2013
Related Publication 20180241776A1 · Aug 23, 2018
Cited By (3)
US 12,192,304 US 12,627,523 US 12,652,247