Secure distribution of session credentials from client-side to server-side traffic management devices
Abstract
A traffic management device (TMD), system, and processor-readable storage medium are directed to securely transferring session credentials from a client-side traffic management device (TMD) to a second server-side TMD that replaces a first server-side TMD. In one embodiment, a client-side TMD and the first server-side TMD have copies of secret data associated with an encrypted session between a client device and a server device, including a session key. For any of a variety of reasons, the first server-side TMD is replaced with the second server-side TMD, which may not have the secret data. In response to a request to create an encrypted connection associated with the encrypted session, the client-side TMD encrypts the secret data using the server device's public key and transmits the encrypted secret data to the second server-side TMD. If the second server-side TMD has a copy of the server device's private key, and is therefore considered to be an authentic and trusted TMD, the second sever-side TMD decrypts the secret data and participates in the encrypted connection.
Claims
exact text as granted — not AI-modifiedWhat is claimed as new and desired to be protected by Letters Patent of the United States is:
1 . A traffic management device (TMD) for managing network traffic between a client device and a server device, comprising:
a transceiver to send and receive data over a network; and a processor, in communication with the transceiver, that performs actions, including:
intercepting a request to initiate an encrypted connection associated with an established encrypted session, wherein the established encrypted session includes a client device and a first server-side TMD in communication with the TMD, and wherein the first server-side TMD is in communication with a server device;
encrypting a set of cryptographic primitives associated with the established encrypted session using a public key associated with the server device; and
transmitting the encrypted set of cryptographic primitives to a second server-side TMD, wherein the second server-side TMD replaces the first server-side TMD and the second server-side TMD is enabled to decrypt data associated with the encrypted session.Join the waitlist — get patent alerts
Track US2017142100A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.