IP Library Granted Patent US 12,438,732
Granted Patent B2
US 12,438,732 · App. 18/318,496 · Granted Oct 7, 2025

Systems and methods for automatic secure sockets layer (SSL) bypass

Inventors: Lidor Pergament (San Mateo, CA); Srikanth Devarajan (Cupertino, CA); Akshat Maheshwari (Bangalore, IN)
Assignee: Zscaler, Inc.
H04L9/3263H04L63/0428H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,438,732
App. No.
18/318,496
Granted
Oct 7, 2025
Kind
B2
Abstract

The present disclosure relates to systems and methods for automatically bypassing SSL connections responsive to client SSL handshake failures. Various embodiments include detecting a first failed client SSL connection, creating a cache entry including a traffic fingerprint of the first failed client SSL connection, and bypassing subsequent connections matching the cached fingerprint of the first failed client SSL connection. Embodiments further include cache entries that include a TTL, wherein connections can be matched to the entries during the configured TTL. The present systems and methods are provided to alleviate issues associated SSL traffic interruptions and breakdowns.

Claims (28)

1. A method comprising steps of:

detecting a first failed client Secure Sockets Layer (SSL) connection based on a client SSL handshake error;

creating a cache entry including a traffic fingerprint derived from handshake metadata of the first failed client SSL connection; and

bypassing SSL inspection for subsequent connections matching the cached fingerprint of the first failed client SSL connection, without performing content-type determination or using destination-based bypass lists.

2. The method of claim 1 , wherein cache entries include a Time-To-Live (TTL), and wherein responsive to there being no cache entry matches within the TTL of the entry, creating a new entry.

3. The method of claim 2 , further comprising steps of:

incrementing a cache entry responsive to a connection matching the cached fingerprint of the first failed client SSL connection.

4. The method of claim 1 , wherein the steps are performed by an enforcement node of a cloud-based system.

5. The method of claim 1 , wherein the steps are only performed if an SSL inspection bypass rule is enabled.

6. The method of claim 5 , wherein responsive to the SSL inspection bypass rule being enabled, presenting a dropdown including a plurality of possible error codes for which a customer intends to bypass SSL traffic.

7. The method of claim 6 , wherein a connection is bypassed responsive to the connection matching one or more chosen error codes of the plurality of error codes.

8. The method of claim 1 , wherein cache entries are stored in a cache at an enforcement node in a cloud-based system.

9. The method of claim 8 , wherein the cache is not persisted.

10. The method of claim 1 , wherein the cache entry includes the reason why the client SSL connection failed.

11. A non-transitory computer-readable medium comprising instructions that, when executed, cause one or more processors to perform steps of:

detecting a first failed client Secure Sockets Layer (SSL) connection based on a client SSL handshake error;

creating a cache entry including a traffic fingerprint derived from handshake metadata of the first failed client SSL connection; and

bypassing SSL inspection for subsequent connections matching the cached fingerprint of the first failed client SSL connection, without performing content-type determination or using destination-based bypass lists.

12. The non-transitory computer-readable medium of claim 11 , wherein cache entries include a Time-To-Live (TTL), and wherein responsive to there being no cache entry matches within the TTL of the entry, creating a new entry.

13. The non-transitory computer-readable medium of claim 12 , further comprising steps of:

incrementing a cache entry responsive to a connection matching the cached fingerprint of the first failed client SSL connection.

14. The non-transitory computer-readable medium of claim 11 , wherein the steps are performed by an enforcement node of a cloud-based system.

15. The non-transitory computer-readable medium of claim 11 , wherein the steps are only performed if an SSL inspection bypass rule is enabled.

16. The non-transitory computer-readable medium of claim 15 , wherein responsive to the SSL inspection bypass rule being enabled, presenting a dropdown including a plurality of possible error codes for which a customer intends to bypass SSL traffic.

17. The non-transitory computer-readable medium of claim 16 , wherein a connection is bypassed responsive to the connection matching one or more chosen error codes of the plurality of error codes.

18. The non-transitory computer-readable medium of claim 11 , wherein cache entries are stored in a cache at an enforcement node in a cloud-based system.

19. The non-transitory computer-readable medium of claim 18 , wherein the cache is not persisted.

20. The non-transitory computer-readable medium of claim 11 , wherein the cache entry includes the reason why the client SSL connection failed.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 16, 2023
From: PERGAMENT, LIDOR; DEVARAJAN, SRIKANTH; MAHESHWARI, AKSHAT
To: ZSCALER, INC.
Reel/Frame 063659/0011 →
Priority Claims (1)
IN 202311023890 · Mar 30, 2023 · national
Continuity (3)
Continuation In Part 17715137 · Apr 7, 2022
Continuation 16863475 · Apr 30, 2020
Related Publication 20230308293A1 · Sep 28, 2023
References Cited (27)
US 9602291B2 · Ashley et al. · 2017 [cited by applicant]
US 20030028606A1 · Koopmans et al. · 2003 [cited by applicant]
US 20030053448A1 · Craig et al. · 2003 [cited by applicant]
US 20040210674A1 · Gbadegesin · 2004 [cited by applicant]
US 20050144328A1 · McBeath · 2005 [cited by applicant]
US 20060031407A1 · Dispensa et al. · 2006 [cited by applicant]
US 20080216150A1 · Brabson · 2008 [cited by examiner]
US 20100024026A1 · Yionen et al. · 2010 [cited by applicant]
US 20100318665A1 · Demmer et al. · 2010 [cited by applicant]
US 20120209942A1 · Zehavi · 2012 [cited by examiner]
US 20140325087A1 · Barreto et al. · 2014 [cited by applicant]
US 20150143504A1 · Desai et al. · 2015 [cited by applicant]
US 20160149898A1 · Parla et al. · 2016 [cited by applicant]
US 20160234104A1 · Hoffmann · 2016 [cited by applicant]
US 20160248812A1 · Desai et al. · 2016 [cited by applicant]
US 20170064749A1 · Jain et al. · 2017 [cited by applicant]
US 20170078328A1 · McGinnity et al. · 2017 [cited by applicant]
US 20170142068A1 · Devarajan et al. · 2017 [cited by applicant]
US 20170325113A1 · Markopoulou et al. · 2017 [cited by applicant]
US 20170346853A1 · Wyatt et al. · 2017 [cited by applicant]
US 20180063077A1 · Tumuluru · 2018 [cited by applicant]
US 20180181431A1 · Vincent et al. · 2018 [cited by applicant]
US 20180288062A1 · Goyal et al. · 2018 [cited by applicant]
US 20180309795A1 · Ithal · 2018 [cited by examiner]
US 20190238592A1 · Qureshi et al. · 2019 [cited by applicant]
US 20200092264A1 · Rahkonen et al. · 2020 [cited by applicant]
US 20200236093A1 · Bannister et al. · 2020 [cited by applicant]