IP Library › Granted Patent US 11,411,924
Granted Patent B2
US 11,411,924 · App. 16/226,661 · Granted Aug 9, 2022

Method for performing TLS/SSL inspection based on verified subject name

Inventors: Pavel Isaev (Ashkelon, IL); Idan Sayag (Tel Aviv, IL); Alexey Volodin (Tel Aviv, IL); Tamir Zegman (Tel Aviv, IL)
Assignee: CHECK POINT SOFTWARE TECHNOLOGIES LTD.
H04L63/029H04L9/3268H04L63/166
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,411,924
App. No.
16/226,661
Granted
Aug 9, 2022
Kind
B2
Abstract

Methods and systems for processing cryptographically secured connections by a gateway, between a client and a server, are performed. Upon receiving TCP and TLS/SSL handshakes associated with a client side connection, from a client (client computer) to the gateway, a probing connection is established. The probing connection completes the handshakes, and based on the completion of the handshakes, the gateway renders a decision, to bypass, block or inspect, the connections between the client and the server, allowing or not allowing data to pass through the connections between the client and the server.

Claims (41)

1. A method for processing cryptographically secured connections by a gateway between a client and a server comprising:

receiving from the client a connection request that includes an indication of a site hosted by the server to which the client is attempting to connect;

upon receiving the connection request, always responding to the received connection request by initiating a probing connection to the server, the probing connection including:

performing a cryptographic protocol with the server, the cryptographic protocol including causing the server to provide an indicator to a site hosted by the server;

receiving data from the server including an indicator to a site hosted by the server; and,

analyzing the received indicator to determine the identity of the site hosted by the server; and,

processing the connection based, at least in part, on the determined identity of the site hosted by the server.

2. The method of claim 1 , wherein the processing the connection includes a decision to block, inspect, or bypass the connection, where the decision is, at least in part, based on the determined identity.

3. The method of claim 1 , wherein the cryptographic protocol includes a Transport Control Protocol (TCP) handshake and a Transport Layer Security (TLS) handshake.

4. The method of claim 3 , wherein the received connection request includes a Client Hello message, and the TLS handshake includes a copy of the Client Hello message sent by the client including a Server Name Indication (SNI) extension.

5. The method of claim 4 , wherein the indicator received from the server includes a server certificate.

6. The method of claim 1 , wherein the site includes a website hosted by the server.

7. The method of claim 2 wherein the protocol includes at least one of: a Datagram Transport Layer Security (DTLS) handshake or a Quick UDP Internet Connections (QUIC) handshake.

8. A computer system for processing cryptographically secured connections by a gateway between a client and a server comprising:

a storage medium for storing computer components; and,

at least one processor for executing the computer components comprising:

a first computer component for receiving from the client a connection request that includes an indication of a site hosted by the server to which the client is attempting to connect;

a second computer component for, upon receiving the connection request, always responding to the received connection request by initiating a probing connection to the server, the probing connection including:

performing a cryptographic protocol with the server, the cryptographic protocol including causing the server to provide an indicator to a site hosted by the server;

receiving data from the server including an indicator to a site hosted by the server; and,

analyzing the received indicator to determine the identity of the site hosted by the server; and,

a third component for processing the connection based, at least in part, on the determined identity of the site hosted by the server.

9. The computer system of claim 8 , additionally comprising a fourth component for deciding to block, inspect, or bypass the connection, where the decision is, at least in part, based on the determined identity.

10. The computer system of claim 9 , wherein the cryptographic protocol includes a Transport Control Protocol (TCP) handshake and a Transport Layer Security (TLS) handshake.

11. The computer system of claim 10 , wherein the received connection request includes a Client Hello message, and the TLS handshake includes a copy of the Client Hello message sent by the client including a Server Name Indication (SNI) extension.

12. The computer system of claim 11 , wherein the indicator received from the server includes a server certificate.

13. The computer system of claim 8 , wherein the site includes a website hosted by the server.

14. The computer system of claim 9 , wherein the protocol includes at least one of: a Datagram Transport Security Protocol (DTLS) handshake or a Quick UDP Internet Connections (QUIC) handshake.

15. A computer usable non-transitory storage medium having a computer program embodied thereon for causing a suitably programmed system to process cryptographically secured connections by a gateway between a client and a server, by performing the following steps when such program is executed on the system, the steps comprising:

receiving from the client a connection request that includes an indication of a site hosted by the server to which the client is attempting to connect;

upon receiving the connection request, always responding to the received connection request by initiating a probing connection to the server, the probing connection including:

performing a cryptographic protocol with the server, the cryptographic protocol including causing the server to provide an indicator to a site hosted by the server;

receiving data from the server including an indicator to a site hosted by the server; and,

analyzing the received indicator to determine the identity of the site hosted by the server; and,

processing the connection based, at least in part, on the determined identity of the site hosted by the server.

16. The computer usable non-transitory storage medium of claim 15 , wherein the processing the connection includes a decision to block, inspect, or bypass the connection, where the decision is, at least in part, based on the determined identity.

17. The computer usable non-transitory storage medium of claim 16 , wherein the cryptographic protocol includes a Transport Control Protocol (TCP) handshake and a Transport Layer Security (TLS) handshake.

18. The computer usable non-transitory storage medium of claim 17 , wherein the received connection request includes a Client Hello message, and the TLS handshake includes a copy of the Client Hello message sent by the client including a Server Name Indication (SNI) extension.

19. The computer usable non-transitory storage medium of claim 18 , wherein the indicator received from the server includes a server certificate.

20. The computer usable non-transitory storage medium of claim 15 , wherein the site includes a website hosted by the server.

21. The computer usable non-transitory storage medium of claim 16 , wherein the protocol includes at least one of: a Datagram Transport Security Protocol (DTLS) handshake or a Quick UDP Internet Connections (QUIC) handshake.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 20, 2018
From: ISAEV, PAVEL; SAYAG, IDAN; VOLODIN, ALEXEY; ZEGMAN, TAMIR
To: CHECK POINT SOFTWARE TECHNOLOGIES LTD.
Reel/Frame 047822/0622 →
Continuity (1)
Related Publication 20200204519A1 · Jun 25, 2020