IP Library Granted Patent US 12,489,789
Granted Patent B2
US 12,489,789 · App. 18/220,057 · Granted Dec 2, 2025

Eliminating double encryption in zero-trust network access authenticated sessions

Inventors: George Mathew Koikara (Bangalore, IN); Pruthvi Panyam Nataraj (Bangalore, IN); Naveen Gujje (Bangalore, IN)
Assignee: Cisco Technology, Inc.
H04L63/166H04L63/0435H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,489,789
App. No.
18/220,057
Granted
Dec 2, 2025
Kind
B2
Abstract

Techniques and architecture are described for eliminating double encryption in zero-trust network access authenticated sessions. The techniques include an endpoint client-based proxy of a network receiving, from a browser, a request to access a protected private service. The endpoint client-based proxy pauses access of the browser to the protected private service and establishes a transport layer security (TLS) connection between the endpoint client-based proxy and a zero-trust network access (ZTNA) gateway. The ZTNA gateway determines whether the protected private service uses a secure transport mechanism and establishes either a null cipher encrypted tunnel between at least the endpoint client-based proxy and the ZTNA gateway or a non-null cipher encrypted tunnel between at least the endpoint client-based proxy and the ZTNA gateway. The endpoint client-based proxy resumes access of the browser to the protected private service.

Claims (71)

1 . A method comprising:

receiving, by an endpoint client-based proxy of a network from a browser, a request to access a protected private service;

pausing, by the endpoint client-based proxy, access of the browser to the protected private service;

authenticating, by the endpoint client-based proxy, a user of the browser;

establishing, by the endpoint client-based proxy, a transport layer security (TLS) connection between the endpoint client-based proxy and a zero-trust network access (ZTNA) gateway;

determining, by the ZTNA gateway, whether traffic between the browser and the protected private service needs to be inspected, wherein determining whether traffic between the browser and the protected private service needs to be inspected comprises determining, by the ZTNA gateway, whether traffic between the browser and the protected private service needs to be inspected based at least in part on a subject name and issuer (SNI) token associated with the protected private service;

one of:

based at least in part on determining, by the ZTNA gateway, the protected private service uses a secure transport mechanism, establishing, by the ZTNA gateway, a null cipher encrypted tunnel between at least the endpoint client-based proxy and the ZTNA gateway; or

based at least in part on determining, by the ZTNA gateway, the protected private service uses a non-secure transport mechanism, establishing, by the ZTNA gateway, a non-null cipher encrypted tunnel between at least the endpoint client-based proxy and the ZTNA gateway;

generating, by the ZTNA gateway, a unique SNI token;

providing, by the ZTNA gateway to the endpoint client-based proxy, the unique SNI token; and

resuming, by the endpoint client-based proxy, access of the browser to the protected private service, wherein resuming access of the browser to the protected private service comprises replacing the SNI token associated with the protected private service in a client hello packet with the unique SNI token.

2 . The method of claim 1 , wherein the ZTNA gateway determines that traffic between the browser and the protected private service needs to be inspected and the method further comprises:

inspecting, by an intrusion prevention service (IPS) engine, traffic between the browser and the protected private service.

3 . The method of claim 2 , wherein the ZTNA gateway determines the protected private service uses the secure transport mechanism and the method further comprises:

establishing, by the ZTNA gateway, a null cipher encrypted tunnel between the endpoint client-based proxy and the ZTNA gateway.

4 . The method of claim 2 , wherein the ZTNA gateway determines the protected private service uses the non-secure transport mechanism and the method further comprises:

establishing, by the ZTNA gateway, a non-null cipher encrypted tunnel between the endpoint client-based proxy and the ZTNA gateway.

5 . The method of claim 1 , wherein the ZTNA gateway determines that traffic between the browser and the protected private service does not need to be inspected and the method further comprises:

establishing, by the ZTNA gateway, a null cipher encrypted tunnel between the endpoint client-based proxy and the ZTNA gateway.

6 . The method of claim 1 , further comprising:

replacing, by the ZTNA gateway, the unique SNI token in the client hello packet with the SNI token associated with the protected private service; and

forwarding, by the ZTNA gateway to the protected private service, the client hello packet with the SNI token associated with the protected private service.

7 . A system comprising:

one or more processors; and

one or more non-transitory computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform actions comprising:

receiving, by an endpoint client-based proxy of a network from a browser, a request to access a protected private service;

pausing, by the endpoint client-based proxy, access of the browser to the protected private service;

authenticating, by the endpoint client-based proxy, a user of the browser;

establishing, by the endpoint client-based proxy, a transport layer security (TLS) connection between the endpoint client-based proxy and a zero-trust network access (ZTNA) gateway;

determining, by the ZTNA gateway, whether traffic between the browser and the protected private service needs to be inspected, wherein determining whether traffic between the browser and the protected private service needs to be inspected comprises determining, by the ZTNA gateway, whether traffic between the browser and the protected private service needs to be inspected based at least in part on a subject name and issuer (SNI) token associated with the protected private service;

one of:

based at least in part on determining, by the ZTNA gateway, the protected private service uses a secure transport mechanism, establishing, by the ZTNA gateway, a null cipher encrypted tunnel between at least the endpoint client-based proxy and the ZTNA gateway; or

based at least in part on determining, by the ZTNA gateway, the protected private service uses a non-secure transport mechanism, establishing, by the ZTNA gateway, a non-null cipher encrypted tunnel between at least the endpoint client-based proxy and the ZTNA gateway;

generating, by the ZTNA gateway, a unique SNI token;

providing, by the ZTNA gateway to the endpoint client-based proxy, the unique SNI token; and

resuming, by the endpoint client-based proxy, access of the browser to the protected private service, wherein resuming access of the browser to the protected private service comprises replacing the SNI token associated with the protected private service in a client hello packet with the unique SNI token.

8 . The system of claim 7 , wherein the ZTNA gateway determines that traffic between the browser and the protected private service needs to be inspected and the actions further comprise:

inspecting, by an intrusion prevention service (IPS) engine, traffic between the browser and the protected private service.

9 . The system of claim 8 , wherein the ZTNA gateway determines the protected private service uses the secure transport mechanism and the actions further comprise:

establishing, by the ZTNA gateway, a null cipher encrypted tunnel between the endpoint client-based proxy and the ZTNA gateway.

10 . The system of claim 8 , wherein the ZTNA gateway determines the protected private service uses the non-secure transport mechanism and the actions further comprise:

establishing, by the ZTNA gateway, a non-null cipher encrypted tunnel between the endpoint client-based proxy and the ZTNA gateway.

11 . The system of claim 7 , wherein the ZTNA gateway determines that traffic between the browser and the protected private service does not need to be inspected and the actions further comprise:

establishing, by the ZTNA gateway, a null cipher encrypted tunnel between the endpoint client-based proxy and the ZTNA gateway.

12 . The system of claim 7 , further comprising:

replacing, by the ZTNA gateway, the unique SNI token in the client hello packet with the SNI token associated with the protected private service; and

forwarding, by the ZTNA gateway to the protected private service, the client hello packet with the SNI token associated with the protected private service.

13 . One or more non-transitory computer-readable media storing computer-executable instructions that, when executed by one or more processors, cause the one or more processors to perform actions comprising:

receiving, by an endpoint client-based proxy of a network from a browser, a request to access a protected private service;

pausing, by the endpoint client-based proxy, access of the browser to the protected private service;

authenticating, by the endpoint client-based proxy, a user of the browser;

establishing, by the endpoint client-based proxy, a transport layer security (TLS) connection between the endpoint client-based proxy and a zero-trust network access (ZTNA) gateway;

determining, by the ZTNA gateway, whether traffic between the browser and the protected private service needs to be inspected, wherein determining whether traffic between the browser and the protected private service needs to be inspected comprises determining, by the ZTNA gateway, whether traffic between the browser and the protected private service needs to be inspected based at least in part on a subject name and issuer (SNI) token associated with the protected private service;

one of:

based at least in part on determining, by the ZTNA gateway, the protected private service uses a secure transport mechanism, establishing, by the ZTNA gateway, a null cipher encrypted tunnel between at least the endpoint client-based proxy and the ZTNA gateway; or

based at least in part on determining, by the ZTNA gateway, the protected private service uses a non-secure transport mechanism, establishing, by the ZTNA gateway, a non-null cipher encrypted tunnel between at least the endpoint client-based proxy and the ZTNA gateway;

generating, by the ZTNA gateway, a unique SNI token;

providing, by the ZTNA gateway to the endpoint client-based proxy, the unique SNI token; and

resuming, by the endpoint client-based proxy, access of the browser to the protected private service, wherein resuming access of the browser to the protected private service comprises replacing the SNI token associated with the protected private service in a client hello packet with the unique SNI token.

14 . The one or more non-transitory computer-readable media of claim 13 , wherein the ZTNA gateway determines that traffic between the browser and the protected private service needs to be inspected and the actions further comprise:

inspecting, by an intrusion prevention service (IPS) engine, traffic between the browser and the protected private service.

15 . The one or more non-transitory computer-readable media of claim 14 , wherein the ZTNA gateway determines the protected private service uses the secure transport mechanism and the actions further comprise:

establishing, by the ZTNA gateway, a null cipher encrypted tunnel between the endpoint client-based proxy and the ZTNA gateway.

16 . The one or more non-transitory computer-readable media of claim 14 , wherein the ZTNA gateway determines the protected private service uses the non-secure transport mechanism and the actions further comprise:

establishing, by the ZTNA gateway, a non-null cipher encrypted tunnel between the endpoint client-based proxy and the ZTNA gateway.

17 . The one or more non-transitory computer-readable media of claim 13 , wherein the ZTNA gateway determines that traffic between the browser and the protected private service does not need to be inspected and the actions further comprise:

establishing, by the ZTNA gateway, a null cipher encrypted tunnel between the endpoint client-based proxy and the ZTNA gateway.

18 . The one or more non-transitory computer-readable media of claim 13 , further comprising:

replacing, by the ZTNA gateway, the unique SNI token in the client hello packet with the SNI token associated with the protected private service; and

forwarding, by the ZTNA gateway to the protected private service, the client hello packet with the SNI token associated with the protected private service.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 10, 2023
From: KOIKARA, GEORGE MATHEW; NATARAJ, PRUTHVI PANYAM; GUJJE, NAVEEN
To: CISCO TECHNOLOGY, INC.
Reel/Frame 064238/0539 →
Continuity (1)
Related Publication 20250023915A1 · Jan 16, 2025
References Cited (17)
US 20100235620A1 · Nylander · 2010 [cited by applicant]
US 20140019751A1 · Hsu et al. · 2014 [cited by applicant]
US 20160285823A1 · Herrero · 2016 [cited by examiner]
US 20160315920A1 · Kurmala et al. · 2016 [cited by applicant]
US 20180332003A1 · Deriso · 2018 [cited by examiner]
US 20190109820A1 · Clark · 2019 [cited by examiner]
US 20190222571A1 · Fausak · 2019 [cited by examiner]
US 20200186507A1 · Dhanabalan · 2020 [cited by examiner]
US 20200204519A1 · Isaev · 2020 [cited by examiner]
US 20210273927A1 · Dhanabalan et al. · 2021 [cited by applicant]
US 20210314359A1 · Thyagaturu · 2021 [cited by examiner]
US 20220070154A1 · Mestery et al. · 2022 [cited by applicant]
EP 4369656A1 · 2024 [cited by applicant]
WO WO20230108394A1 · 2023 [cited by applicant]
E. Rescorla, “RFC 8446 The Transport Layer Security (TLS) Protocol Version 1.3”, Internet Engineering Task Force (IETF Aug. 2018) (Year: 2018). [cited by examiner]
Search Report and Written Opinion for International Application No. PCT/US24/35441, Dated Oct. 4, 2024, 14 pages. [cited by applicant]
Hicks, Richard, “Direct Access IP-HTTPS Null Cipher Suites Not Available,” richardhicks.com, published Jan. 17, 2017, 42 pages. [cited by applicant]