IP Library › Granted Patent US 12,463,799
Granted Patent B2
US 12,463,799 · App. 18/646,320 · Granted Nov 4, 2025

Sharing cryptographic session keys among a cluster of network security platforms monitoring network traffic flows

Inventors: Manikandan A. Kenyan (Saratoga, CA); Anil Abraham (Bangalore, IN)
Assignee: McAfee, LLC
H04L9/0819H04L9/0869H04L9/3242H04L63/0428
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,463,799
App. No.
18/646,320
Granted
Nov 4, 2025
Kind
B2
Abstract

An example apparatus disclosed herein is to select a first network security platform based on a first value associated with a first message associated a client and a second value associated with a second message associated with a server, the first message and the second message associated with establishment of an encrypted network traffic flow between the client and the server. The disclosed example apparatus is also to cause a cryptographic session key associated with the encrypted network traffic flow to be sent to the first network security platform.

Claims (35)

1 . A server comprising:

interface circuitry;

computer readable instructions; and

at least one programmable circuit to be programmed by the computer readable instructions to:

access a first message received from a client via a network and access a second message to be transmitted from the server to the client via the network, the first message and the second message associated with establishment of an encrypted network traffic flow between the client and the server;

hash a first value associated with the first message and a second value associated with the second message to determine a hash value;

process the hash value with a modulo operation to determine a third value, the modulo operation based on a number of network security platforms;

identify a first network security platform of a plurality of the network security platforms based on the third value; and

cause a cryptographic session key that is able to decrypt the encrypted network traffic flow to be sent via the network to the first network security platform.

2 . The server of claim 1 , wherein the first message is a first hello message sent by the client to establish the encrypted network traffic flow between the client and the server, the first value is a first random number included in the first hello message, the second message is a second hello message to be sent by the server in response to the first hello message, and the second value is a second random number included in the second hello message.

3 . The server of claim 1 , wherein one or more of the at least one programmable circuit is to:

obtain configuration information that includes respective platform selection values to identify respective ones of the network security platforms; and

identify the first network security platform based on the third value corresponding to a first one of the respective platform selection values that identifies the first network security platform.

4 . The server of claim 1 , wherein one or more of the at least one programmable circuit is to include the cryptographic session key, the first value and the second value in a third message to the first network security platform.

5 . The server of claim 1 , wherein the first network security platform is different from a second network security platform that is to monitor the encrypted network traffic flow.

6 . At least one non-transitory computer readable medium comprising computer readable instructions to cause at least one programmable circuit to at least:

access a first message from a client via a network and access a second message to be sent to the client via the network, the first message and the second message associated with establishment of an encrypted network traffic flow with the client;

hash a first parameter value in the first message and a second parameter value in the second message to determine a hash value;

process the hash value with a modulo operation based on a number of network security platforms included in a cluster of network security platforms to determine a platform selection value;

identify a first one of the cluster of network security platforms based on the platform selection value; and

cause transmission of a cryptographic session key that is able to decrypt the encrypted network traffic flow to the first one of the cluster of network security platforms via the network.

7 . The at least one non-transitory computer readable medium of claim 6 , wherein the first message is a first hello message sent by the client to establish the encrypted network traffic flow with the client, the first parameter value is a first random number included in the first hello message, the second message is a second hello message to be sent to the client in response to the first hello message, and the second parameter value is a second random number included in the second hello message.

8 . The at least one non-transitory computer readable medium of claim 6 , wherein the computer readable instructions are to cause one or more of the at least one programmable circuit to cause the cryptographic session key to be transmitted in a third message to the first one of a cluster of network security platforms, the third message including the cryptographic session key, the first parameter value and the second parameter value.

9 . The at least one non-transitory computer readable medium of claim 6 , wherein the computer readable instructions are to cause one or more of the at least one programmable circuit to cause transmission of the second message to a second one of the network security platforms different from the first one of the network security platforms.

10 . The at least one non-transitory computer readable medium of claim 9 , wherein the computer readable instructions are to cause one or more of the at least one programmable circuit to cause the second message to be sent to the second one of the network security platforms in response to receipt of the first message from the client via the second one of the network security platforms.

11 . A method comprising:

accessing first information received from a client via a network and accessing second information to be sent from a server to the client via the network, the first information and the second information associated with establishment of an encrypted network traffic flow between the client and the server;

hashing, by at least one programmable circuit of the server that is programmed by at least one instruction, the first information and the second information to determine a hash value;

processing, by one or more of the at least one programmable circuit, the hash value with a modulo operation to determine a selection value, the modulo operation based on a number of network security platforms;

identifying, by one or more of the at least one programmable circuit, a first network security platform of a plurality of the network security platforms based on the selection value; and

transmitting a cryptographic session key that is able to decrypt the encrypted network traffic flow from the server to the first network security platform.

12 . The method of claim 11 , wherein the first information is based on a first message from the client, the first message to establish the encrypted network traffic flow between the client and the server, and the second information is based on a second message to be sent by the server in response to the first message.

13 . The method of claim 11 , including obtaining configuration information that includes respective platform values to identify respective ones of the network security platforms, and the identifying of the first network security platform includes selecting the first network security platform based on the selection value corresponding to a first one of the respective platform values that identifies the first network security platform.

14 . The method of claim 11 , including generating a message including the cryptographic session key, the first information and the second information, wherein the transmitting of the cryptographic session key includes transmitting the message to the first network security platform.

15 . The method of claim 11 , wherein the first network security platform is different from a second network security platform that is to monitor the encrypted network traffic flow.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 16, 2024
From: KENYAN, MANIKANDAN A.; ABRAHAM, ANIL
To: MCAFEE, LLC
Reel/Frame 067438/0357 →
Continuity (3)
Division 17379523 · Jul 19, 2021
Division 16230806 · Dec 21, 2018
Related Publication 20240283633A1 · Aug 22, 2024
References Cited (48)
US 6212633B1 · Levy · 2001 [cited by applicant]
US 6980521B1 · Jarvis · 2005 [cited by applicant]
US 7778194B1 · Yung · 2010 [cited by applicant]
US 8842833B2 · Natarajan · 2014 [cited by examiner]
US 8966267B1 · Pahl · 2015 [cited by applicant]
US 8996873B1 · Pahl · 2015 [cited by examiner]
US 9338147B1 · Rothstein · 2016 [cited by applicant]
US 9608810B1 · Ghetti et al. · 2017 [cited by applicant]
US 9705769B1 · Sarangapani · 2017 [cited by applicant]
US 9967292B1 · Higgins et al. · 2018 [cited by applicant]
US 10121026B1 · Ryland · 2018 [cited by applicant]
US 11070363B1 · Kenyan et al. · 2021 [cited by applicant]
US 20020039420A1 · Shacham · 2002 [cited by examiner]
US 20060280207A1 · Guarini · 2006 [cited by applicant]
US 20120134266A1 · Roitshtein · 2012 [cited by applicant]
US 20120304244A1 · Xie · 2012 [cited by applicant]
US 20130262655A1 · Deschenes · 2013 [cited by applicant]
US 20140115702A1 · Li · 2014 [cited by applicant]
US 20150215236A1 · Joshi · 2015 [cited by applicant]
US 20150288514A1 · Pahl · 2015 [cited by applicant]
US 20150288679A1 · Ben-Nun · 2015 [cited by applicant]
US 20160013935A1 · Pahl · 2016 [cited by applicant]
US 20160043870A1 · Avanzi · 2016 [cited by examiner]
US 20160112381A1 · Bhattacharyya · 2016 [cited by applicant]
US 20170034844A1 · Khoury · 2017 [cited by examiner]
US 20170039841A1 · Wilson et al. · 2017 [cited by applicant]
US 20170331822A1 · Mikulski · 2017 [cited by applicant]
US 20180278419A1 · Higgins · 2018 [cited by examiner]
US 20190068564A1 · Putatunda · 2019 [cited by applicant]
US 20190146849A1 · Leonard · 2019 [cited by applicant]
US 20190173671A1 · Yang · 2019 [cited by applicant]
US 20190199683A1 · Kenyan · 2019 [cited by applicant]
US 20190199684A1 · Kenyan · 2019 [cited by applicant]
US 20190387049A1 · Patil · 2019 [cited by applicant]
US 20200067700A1 · Bergeron · 2020 [cited by applicant]
US 20200145391A1 · Sasidharan et al. · 2020 [cited by applicant]
US 20200320199A1 · Sheth · 2020 [cited by applicant]
US 20210218714A1 · Wang · 2021 [cited by examiner]
WO WO2020131740A1 · 2020 [cited by examiner]
International Searching Authority, “Written Opinion of the International Searching Authority,” issued in connection with International Patent Application No. PCT/US2019/066613, mailed on Mar. 17, 2020, 8 pages. [cited by applicant]
International Searching Authority, “International Search Report,” issued in connection with International Patent Application No. PCT/US2019/066613, mailed on Mar. 17, 2020, 5 pages. [cited by applicant]
United States Patent and Trademark Office, “Notice of Allowance,” issued in connection with U.S. Appl. No. 16/230,806 on Mar. 16, 2021, 17 pages. [cited by applicant]
International Searching Authority, “International Preliminary Report on Patentability,” issued in connection with International Application No. PCT/US2019/066613, issued on Jun. 16, 2021, 9 pages. [cited by applicant]
United States Patent and Trademark Office, “Requirement for Restriction / Election,” issued in connection with U.S. Appl. No. 17/379,523, dated Oct. 21, 2022, 6 pages. [cited by applicant]
United States Patent and Trademark Office, “Non-Final Office Action,” issued in connection with U.S. Appl. No. 17/379,523, dated Feb. 1, 2023, 9 pages. [cited by applicant]
United States Patent and Trademark Office, “Final Office Action,” issued in connection with U.S. Appl. No. 17/379,523, mailed on Aug. 23, 2023, 9 pages. [cited by applicant]
European Patent Office, “Communication pursuant to Article 94(3) EPC,” issued in connection with European Patent Application No. 19 842 447.5-1218, dated Nov. 27, 2023, 4 pages. [cited by applicant]
United States Patent and Trademark Office, “Notice of Allowance,” issued in connection with U.S. Appl. No. 17/379,523, dated Jan. 17, 2024, 14 pages. [cited by applicant]