IP Library Granted Patent US 11,991,268
Granted Patent B2
US 11,991,268 · App. 17/379,523 · Granted May 21, 2024

Sharing cryptographic session keys among a cluster of network security platforms monitoring network traffic flows

Inventors: Manikandan A. Kenyan (Saratoga, CA); Anil Abraham (Bangalore, IN)
Assignee: McAfee, LLC
H04L9/0819H04L9/0869H04L9/3242H04L63/0428
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,991,268
App. No.
17/379,523
Granted
May 21, 2024
Kind
B2
Abstract

A first example network security platform disclosed herein is to store a cryptographic session key from a server, the cryptographic session key associated with an encrypted network traffic flow between the server and a client different from the first network security platform. This disclosed first example network security platform is also to access a query from a second network security platform requesting the cryptographic session key, and generate a response including the cryptographic session key to send to the second network security platform.

Claims (25)

1. At least one non-transitory computer readable medium comprising computer readable instructions which, when executed, cause at least one processor of a first network security platform to at least:

buffer a query from a second network security platform for a cryptographic session key until at least receipt of the cryptographic session key from a server, the cryptographic session key associated with an encrypted network traffic flow between the server and a client, the server and the client to be different from the first network security platform and the second network security platform, the first network security platform to be identifiable as a recipient of the cryptographic session key from the server based on a platform selection value, the platform selection value based on a first parameter value associated with a first message from the client and a second parameter value associated with a second message from the server;

store the cryptographic session key from the server; and

after the receipt of the cryptographic session key from the server, generate a response including the cryptographic session key to send to the second network security platform.

2. The at least one non-transitory computer readable medium of claim 1 , wherein the computer readable instructions cause the at least one processor to obtain the cryptographic session key from a third message from the server, the third message including the cryptographic session key, the third message also including the first parameter value and the second parameter value to identify the cryptographic session key.

3. The at least one non-transitory computer readable medium of claim 2 , wherein the first message and the second message are associated with establishment of the encrypted network traffic flow between the client and the server.

4. The at least one non-transitory computer readable medium of claim 3 , wherein the first message is a first hello message sent by the client to establish the encrypted network traffic flow between the client and the server, the first parameter value is a first random number included in the first hello message, the second message is a second hello message to be sent by the server in response to the first hello message, and the second parameter value is a second random number included in the second hello message.

5. The at least one non-transitory computer readable medium of claim 2 , wherein the query from the second network security platform includes the first parameter value and the second parameter value.

6. A first network security platform comprising:

a key database to store a cryptographic session key from a server, the cryptographic session key associated with an encrypted network traffic flow between the server and a client, the server and the client to be different from the first network security platform;

instructions in the first network security platform; and

processor circuitry to execute the instructions to at least:

buffer a query from a second network security platform requesting the cryptographic session key until at least receipt of the cryptographic session key from the server, the first network security platform to be identifiable as a recipient of the cryptographic session key from the server based on a platform selection value, the platform selection value based on a first parameter value associated with a first message from the client and a second parameter value associated with a second message from the server; and

after the receipt of the cryptographic session key from the server, generate a response including the cryptographic session key to send to the second network security platform.

7. The first network security platform of claim 6 , wherein the key database is to obtain the cryptographic session key from a third message from the server, the third message including the cryptographic session key, the third message also including the first parameter value and the second parameter value to identify the cryptographic session key.

8. The first network security platform of claim 7 , wherein the first message and the second message are associated with establishment of the encrypted network traffic flow between the client and the server.

9. The first network security platform of claim 8 , wherein the first message is a first hello message sent by the client to establish the encrypted network traffic flow between the client and the server, the first parameter value is a first random number included in the first hello message, the second message is a second hello message to be sent by the server in response to the first hello message, and the second parameter value is a second random number included in the second hello message.

10. The first network security platform of claim 7 , wherein the query from the second network security platform includes the first parameter value and the second parameter value.

11. A method comprising:

buffering, at a first network security platform, a query from a second network security platform for a cryptographic session key until at least receipt of the cryptographic session key from a server, the cryptographic session key associated with an encrypted network traffic flow between the server and a client different from the first network security platform, the first network security platform to be identifiable as a recipient of the cryptographic session key from the server based on a platform selection value, the platform selection value based on a first parameter value associated with a first message from the client and a second parameter value associated with a second message from the server;

storing, by executing an instruction with at least one processor, the cryptographic session key from the server; and

after receiving the cryptographic session key from the server, generating, by executing an instruction with at least one processor, a response including the cryptographic session key to send to the second network security platform.

12. The method of claim 11 , further including obtaining the cryptographic session key from a third message from the server, the third message including the cryptographic session key, the third message also including the first parameter value and the second parameter value to identify the cryptographic session key.

13. The method of claim 12 , wherein the first message and the second message are associated with establishment of the encrypted network traffic flow between the client and the server.

14. The method of claim 13 , wherein the first message is a first hello message sent by the client to establish the encrypted network traffic flow between the client and the server, the first parameter value is a first random number included in the first hello message, the second message is a second hello message to be sent by the server in response to the first hello message, and the second parameter value is a second random number included in the second hello message.

Assignments (3)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2021
From: KENYAN, MANIKANDAN A.; ABRAHAM, ANIL
To: MCAFEE, LLC
Reel/Frame 057315/0083 →
Continuity (2)
Division 16230806 · Dec 21, 2018
Related Publication 20210351918A1 · Nov 11, 2021