US2017142100A1PendingUtilityA1

Secure distribution of session credentials from client-side to server-side traffic management devices

Assignee: F5 NETWORKS INCPriority: Mar 19, 2010Filed: Nov 18, 2016Published: May 18, 2017
Est. expiryMar 19, 2030(~3.6 yrs left)· nominal 20-yr term from priority
H04L 63/0853H04L 63/0442H04L 63/061H04L 63/166H04L 67/56H04L 63/0428H04L 63/0245G06F 21/604H04L 63/306H04L 67/14H04L 63/0884H04L 9/0844H04L 63/0823G06F 21/606
58
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A traffic management device (TMD), system, and processor-readable storage medium are directed to securely transferring session credentials from a client-side traffic management device (TMD) to a second server-side TMD that replaces a first server-side TMD. In one embodiment, a client-side TMD and the first server-side TMD have copies of secret data associated with an encrypted session between a client device and a server device, including a session key. For any of a variety of reasons, the first server-side TMD is replaced with the second server-side TMD, which may not have the secret data. In response to a request to create an encrypted connection associated with the encrypted session, the client-side TMD encrypts the secret data using the server device's public key and transmits the encrypted secret data to the second server-side TMD. If the second server-side TMD has a copy of the server device's private key, and is therefore considered to be an authentic and trusted TMD, the second sever-side TMD decrypts the secret data and participates in the encrypted connection.

Claims

exact text as granted — not AI-modified
What is claimed as new and desired to be protected by Letters Patent of the United States is: 
     
         1 . A traffic management device (TMD) for managing network traffic between a client device and a server device, comprising:
 a transceiver to send and receive data over a network; and   a processor, in communication with the transceiver, that performs actions, including:
 intercepting a request to initiate an encrypted connection associated with an established encrypted session, wherein the established encrypted session includes a client device and a first server-side TMD in communication with the TMD, and wherein the first server-side TMD is in communication with a server device; 
 encrypting a set of cryptographic primitives associated with the established encrypted session using a public key associated with the server device; and 
 transmitting the encrypted set of cryptographic primitives to a second server-side TMD, wherein the second server-side TMD replaces the first server-side TMD and the second server-side TMD is enabled to decrypt data associated with the encrypted session.

Join the waitlist — get patent alerts

Track US2017142100A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.