IP Library Granted Patent US 12,309,295
Granted Patent B2
US 12,309,295 · App. 17/843,095 · Granted May 20, 2025

Cloud-based man-in-the-middle inspection of encrypted traffic using cloud-based multi-tenant HSM infrastructure

Inventors: Vijay Bulusu (Fremont, CA); Akshat Maheshwari (Bangalore, IN); Harpreet Singh (San Jose, CA); Sujay Kumar (Bangalore, IN); Lidor Pergament (San Mateo, CA); Srikanth Devarajan (Cupertino, CA)
Assignee: Zscaler, Inc.
H04L9/3263H04L63/0428H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,309,295
App. No.
17/843,095
Granted
May 20, 2025
Kind
B2
Abstract

A method implemented by a node in a cloud-based system includes responsive to monitoring a user device, detecting a request for encrypted traffic to a domain from the user device; checking if a domain certificate for the domain is available in cache; responsive to the domain certificate being in the cache, creating a first tunnel to the domain and a second tunnel to the user device; and, responsive to the domain certificate not being in the cache, generating the domain certificate with a cloud hardware security module (HSM) system, and creating the first tunnel and the second tunnel.

Claims (51)

1. A method implemented by a node in a cloud-based system, the method comprising steps of:

responsive to monitoring a user device, detecting a request for encrypted traffic to a domain from the user device;

checking if a domain certificate for the domain is available in cache;

responsive to the domain certificate being in the cache, creating a first tunnel to the domain and a second tunnel to the user device; and

responsive to the domain certificate not being in the cache, generating the domain certificate in the cloud-based system, and creating the first tunnel and the second tunnel.

2. The method of claim 1 , wherein the steps include

responsive to generating the domain certificate, caching the domain certificate and synchronizing with other nodes in the cloud-based system.

3. The method of claim 1 , wherein the steps include

monitoring the encrypted traffic for one or more security functions.

4. The method of claim 3 , wherein the steps include

one of blocking or allowing the encrypted traffic based on the one or more security functions.

5. The method of claim 1 , wherein the steps include

prior to the detecting, enrolling the domain in the cloud HSM with a customer certificate authority.

6. The method of claim 5 , wherein a cleartext private key associated with the customer certificate authority is constrained to a hardware security module (HSM).

7. The method of claim 1 , wherein the generating includes

generating a key pair and certificate signing request;

requesting a cloud hardware security module (HSM) in or connected to the cloud-based system asymmetrically sign;

receiving a digital signature from the cloud HSM; and

merging the digital signature and a certificate.

8. The method of claim 1 , wherein the first tunnel and the second tunnel are created based on a plurality of certificates including a customer root certificate that resides in a customer hardware security module (HSM), customer intermediate certificates previously stored in the cloud HSM, and the domain certificates issued at runtime or from the cache.

9. A non-transitory computer-readable medium comprising instructions executed by one or more nodes in a cloud-based system to perform steps of:

responsive to monitoring a user device, detecting a request for encrypted traffic to a domain from the user device;

checking if a domain certificate for the domain is available in cache;

responsive to the domain certificate being in the cache, creating a first tunnel to the domain and a second tunnel to the user device; and

responsive to the domain certificate not being in the cache, generating the domain certificate in the cloud-based system, and creating the first tunnel and the second tunnel.

10. The non-transitory computer-readable medium of claim 9 , wherein the steps include

responsive to generating the domain certificate, caching the domain certificate and synchronizing with other nodes in the cloud-based system.

11. The non-transitory computer-readable medium of claim 10 , wherein the steps include

one of blocking or allowing the encrypted traffic based on the one or more security functions.

12. The non-transitory computer-readable medium of claim 9 , wherein the steps include

monitoring the encrypted traffic for one or more security functions.

13. The non-transitory computer-readable medium of claim 12 , wherein a cleartext private key associated with the customer certificate authority is constrained to a hardware security module (HSM).

14. The non-transitory computer-readable medium of claim 9 , wherein the steps include prior to the detecting, enrolling the domain with a customer certificate authority.

15. The non-transitory computer-readable medium of claim 9 , wherein the generating includes

generating a key pair and certificate signing request;

requesting a cloud hardware security module (HSM) asymmetrically sign;

receiving a digital signature from the cloud HSM; and

merging the digital signature and a certificate.

16. The non-transitory computer-readable medium of claim 9 , wherein the first tunnel and the second tunnel are created based on a plurality of certificates including a customer root certificate that resides in a customer hardware security module (HSM), customer intermediate certificates previously stored in the cloud HSM, and the domain certificates issued at runtime or from the cache.

17. A node in a cloud-based system, the node comprising:

one or more processors and memory storing instructions that, when executed, cause the one or more processors to:

responsive to monitoring a user device, detect a request for encrypted traffic to a domain from the user device;

check if a domain certificate for the domain is available in cache;

responsive to the domain certificate being in the cache, create a first tunnel to the domain and a second tunnel to the user device; and

responsive to the domain certificate not being in the cache, generate the domain certificate in the cloud-based system, and create the first tunnel and the second tunnel.

18. The node of claim 17 , wherein the instructions that, when executed, further cause the one or more processors to:

responsive to generating the domain certificate, cache the domain certificate and synchronizing with other nodes in the cloud-based system.

19. The node of claim 17 , wherein the instructions that, when executed, further cause the one or more processors to:

monitor the encrypted traffic for one or more security functions.

20. The node of claim 19 , wherein the instructions that, when executed, further cause the one or more processors to:

one of block or allow the encrypted traffic based on the one or more security functions.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 17, 2022
From: BULUSU, VIJAY; MAHESHWARI, AKSHAT; SINGH, HARPREET; KUMAR, SUJAY; PERGAMENT, LIDOR; DEVARAJAN, SRIKANTH
To: ZSCALER, INC.
Reel/Frame 060236/0648 →
Continuity (3)
Continuation In Part 17715137 · Apr 7, 2022
Continuation 16863475 · Apr 30, 2020
Related Publication 20220329442A1 · Oct 13, 2022
References Cited (29)
US 9602291B2 · Ashley et al. · 2017 [cited by applicant]
US 20030028606A1 · Koopmans et al. · 2003 [cited by applicant]
US 20030053448A1 · Craig et al. · 2003 [cited by applicant]
US 20040210674A1 · Gbadegesin · 2004 [cited by applicant]
US 20050144328A1 · McBeath · 2005 [cited by applicant]
US 20060031407A1 · Dispensa et al. · 2006 [cited by applicant]
US 20100024026A1 · Yionen · 2010 [cited by applicant]
US 20100318665A1 · Demmer et al. · 2010 [cited by applicant]
US 20140325087A1 · Barreto et al. · 2014 [cited by applicant]
US 20150143504A1 · Desai et al. · 2015 [cited by applicant]
US 20160149898A1 · Parla et al. · 2016 [cited by applicant]
US 20160234104A1 · Hoffmann · 2016 [cited by applicant]
US 20160248812A1 · Desai et al. · 2016 [cited by applicant]
US 20170064749A1 · Jain et al. · 2017 [cited by applicant]
US 20170078328A1 · McGinnity et al. · 2017 [cited by applicant]
US 20170142068A1 · Devarajan et al. · 2017 [cited by applicant]
US 20170325113A1 · Markopoulou et al. · 2017 [cited by applicant]
US 20170346853A1 · Wyatt et al. · 2017 [cited by applicant]
US 20180063077A1 · Tumuluru · 2018 [cited by applicant]
US 20180181431A1 · Vincent et al. · 2018 [cited by applicant]
US 20180288062A1 · Goyal et al. · 2018 [cited by applicant]
US 20190238592A1 · Qureshi et al. · 2019 [cited by applicant]
US 20190386814A1 · Ahmed · 2019 [cited by examiner]
US 20200092264A1 · Rahkonen et al. · 2020 [cited by applicant]
US 20200236093A1 · Bannister et al. · 2020 [cited by applicant]
US 20210344511A1 · Devarajan · 2021 [cited by examiner]
EP 3905629A1 · 2021 [cited by applicant]
K. Walsh, “TLS with Trustworthy Certificate Authorities,” 2016 IEEE Conference on Communication and Network Security (CNS), IEEE, Oct. 17, 2016, pp. 516-524. [cited by applicant]
Oct. 18, 2023, Extended European Search Report for EP Application No. 23153577.4. [cited by applicant]