Optimized mutual transport layer security (MTLS) authentication
Systems and methods for secure digital communication with reduced resource utilization are provided. Systems and methods may include utilizing an intermediate node. Systems and methods may include establishing secure communication links between one or more client nodes and the intermediate node and between the intermediate node and one or more server nodes.
1 . A method for secure digital communication with reduced resource utilization, the method comprising:
transmitting, from a client node, a client digital certificate, wherein said client digital certificate comprises a unique client identifier;
receiving, at an intermediate node, the client digital certificate;
validating, at the intermediate node, the client digital certificate, wherein said validating comprises confirming that the client digital certificate is non-expired and is associated with a trusted certificate authority (CA);
when the client digital certificate is successfully validated at the intermediate node:
establishing a first secure communication link between the client node and the intermediate node;
transmitting, from the intermediate node to a server node, the unique client identifier and an intermediate node digital certificate; and
validating, at the server node, the intermediate node digital certificate and the unique client identifier, wherein validating the unique client identifier comprises confirming that the unique client identifier is included in a list of trusted clients that is stored at the server node; and
when the intermediate node digital certificate and the unique client identifier are successfully validated at the server node:
establishing a second secure communication link between the intermediate node and the server node; and
transmitting messages bi-directionally between the client node and the server node through the first and second secure communication links via the intermediate node.
2 . The method of claim 1 wherein:
as part of establishing the first secure communication link, the intermediate node transmits the intermediate node digital certificate to the client node; and
as part of establishing the second secure communication link, the server node transmits a server digital certificate to the intermediate node.
3 . The method of claim 2 wherein the first and second secure communication links each separately implement mutual transport layer security (mTLS) communication protocol.
4 . The method of claim 1 wherein:
the client node is one of a plurality of client nodes;
the server node is one of a plurality of server nodes; and
the intermediate node is a single intermediate node that supports the first and second secure communication links with the plurality of client nodes and the plurality of server nodes.
5 . The method of claim 1 further comprising, when the client digital certificate fails validation at the intermediate node or when the unique client identifier fails validation at the server node, terminating connection between the client node and the intermediate and server nodes.
6 . The method of claim 1 wherein the intermediate node is a load balancer.
7 . The method of claim 6 wherein the load balancer is a Layer 7 load balancer.
8 . The method of claim 6 wherein the load balancer is a Local Traffic Manager (LTM) load balancer.
9 . The method of claim 1 wherein the client and intermediate node digital certificates implement X.509 digital certificate protocol.
10 . The method of claim 1 wherein the transmitting of the unique client identifier from the intermediate node to the server node comprises embedding the unique client identifier in a header of a request packet transmitted from the intermediate node to the server node.
11 . A system for secure digital communication with reduced resource utilization, the system comprising a processor, a non-transitory memory, and a set of computer executable instruction stored in the memory that, when run on the processor, are configured to:
transmit, from a client node, a client digital certificate, wherein said client digital certificate comprises a unique client identifier;
receive, at an intermediate node, the client digital certificate;
validate, at the intermediate node, the client digital certificate, wherein said validating comprises confirming that the client digital certificate is non-expired and is associated with a trusted certificate authority (CA);
when the client digital certificate is successfully validated at the intermediate node:
establish a first secure communication link between the client node and the intermediate node;
transmit, from the intermediate node to a server node, the unique client identifier and an intermediate node digital certificate;
validate, at the server node, the intermediate node digital certificate and the unique client identifier, wherein validating the unique client identifier comprises confirming that the unique client identifier is included in a list of trusted clients that is stored at the server node; and
when the intermediate node digital certificate and the unique client identifier are successfully validated at the server node:
establish a second secure communication link between the intermediate node and the server node; and
transmit messages bi-directionally between the client node and the server node through the first and second secure communication links via the intermediate node.
12 . The system of claim 11 wherein:
as part of establishing the first secure communication link, the intermediate node transmits the intermediate node digital certificate to the client node; and
as part of establishing the second secure communication link, the server node transmits a server digital certificate to the intermediate node.
13 . The system of claim 12 wherein the first and second secure communication links each separately implement mutual transport layer security (mTLS) communication protocol.
14 . The system of claim 11 wherein:
the client node is one of a plurality of client nodes;
the server node is one of a plurality of server nodes; and
the intermediate node is a single intermediate node that supports the first and second secure communication links with the plurality of client nodes and the plurality of server nodes.
15 . The system of claim 11 further configured, when the client digital certificate fails validation at the intermediate node or when the unique client identifier fails validation at the server node, to terminate connection between the client node and the intermediate and server nodes.
16 . The system of claim 11 wherein the intermediate node is a load balancer.
17 . The system of claim 16 wherein the load balancer is a Layer 7 load balancer.
18 . The system of claim 16 wherein the load balancer is a Local Traffic Manager (LTM) load balancer.
19 . The system of claim 11 wherein the client and intermediate node digital certificates implement X.509 digital certificate protocol.
20 . The system of claim 11 wherein to transmit the unique client identifier from the intermediate node to the server node the unique client identifier is embedded in a header of a request packet transmitted from the intermediate node to the server node.