US2020028822A1PendingUtilityA1

Granular offloading of a proxied secure session

Assignee: JUNIPER NETWORKS INCPriority: Feb 10, 2017Filed: Sep 30, 2019Published: Jan 23, 2020
Est. expiryFeb 10, 2037(~10.5 yrs left)· nominal 20-yr term from priority
H04L 63/0281H04L 63/0428H04L 63/306H04L 63/0464H04L 63/0227H04L 67/14H04L 2209/76H04L 63/166H04L 63/061H04L 63/1416
51
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A device may receive encrypted traffic associated with a secure session. The device may determine, based on the encrypted traffic, information associated with an offload service to be applied to the encrypted traffic associated with the secure session. The information associated with the offload service may indicate whether the encrypted traffic is permitted to bypass inspection by one or more security services. The device may selectively permit the encrypted traffic, associated with the secure session, to bypass inspection by the one or more security services based on the information associated with the offload service.

Claims

exact text as granted — not AI-modified
1 - 20 . (canceled) 
     
     
         21 . A method comprising:
 determining, by a device, that no security service, of one or more security services, is to inspect all traffic of a session;   determining, by the device and based on determining that no security services is to inspect all traffic of the session, that a security service, of the one or more security services, is to inspect traffic in a client-to-server (C2S) direction;   determining, by the device and based on determining that the security service is to inspect traffic in the C2S direction, that an offload service includes inspecting traffic traveling in the C2S direction;   identifying, by the device, the offload service based on determining that the offload service includes inspecting the traffic traveling in the C2S direction; and   applying, by the device, the offload service based on identifying the offload service.   
     
     
         22 . The method of  claim 21 ,
 wherein the session is a secure session, and   wherein the traffic traveling in the C2S direction includes encrypted traffic.   
     
     
         23 . The method of  claim 21 , further comprising:
 determining, based on determining that no security services is to inspect all traffic of the session, that no security service, of the one or more security services, is to inspect traffic in a server-to-client (S2C) direction,
 wherein determining that the offload service includes inspecting the traffic traveling in the C2S direction includes:
 determining, based on determining that the security service is to inspect traffic in the C2S direction and based on determining that no security service, of the one or more security services, is to inspect the traffic in the S2C direction, that the offload service includes inspecting the traffic traveling in the C2S direction. 
 
   
     
     
         24 . The method of  claim 21 , wherein the offload service is identified during an establishment of the session. 
     
     
         25 . The method of  claim 21 , wherein the offload service is identified after an establishment of the session. 
     
     
         26 . The method of  claim 21 , wherein the offload service is identified based on a request provided by a client device or a service device. 
     
     
         27 . The method of  claim 21 , wherein the offload service is identified based on a change to at the one or more security services. 
     
     
         28 . The method of  claim 21 , further comprising:
 storing information associated with the offload service after identifying the offload service.   
     
     
         29 . The method of  claim 28 , wherein the information associated with the offload service comprises one or more of:
 information that describes the manner in which encrypted traffic may bypass decryption and re-encryption by the device,   information that identifies the session,   information that identifies at least one of a client device or a server device, or   information that identifies a threshold amount of encrypted traffic to be inspected in one or more of the C2S direction or the S2C directions.   
     
     
         30 . A system, comprising:
 one or more memories; and   one or more processors communicatively coupled to the one or more memories, configured to:
 determine that no security service, of one or more security services, is to inspect all traffic of a session; 
 determine, based on determining that no security services is to inspect all traffic of the session, that a security service, of the one or more security services, is to inspect traffic in a client-to-server (C2S) direction; 
 determine, based on determining that the security service is to inspect traffic in the C2S direction, that an offload service includes inspecting traffic traveling in the C2S direction; 
 identify the offload service based on determining that the offload service includes inspecting the traffic traveling in the C2S direction; and 
 apply the offload service based on identifying the offload service. 
   
     
     
         31 . The system of  claim 30 , wherein the one or more processors are further configured to:
 determine, based on determining that no security services is to inspect all traffic of the session, that no security service, of the one or more security services, is to inspect traffic in a server-to-client (S2C) direction,
 wherein, when determining that the offload service includes inspecting the traffic traveling in the C2S direction, the one or more processors are configured to:
 determine, based on determining that the security service is to inspect traffic in the C2S direction and based on determining that no security service, of the one or more security services, is to inspect the traffic in the S2C direction, that the offload service includes inspecting the traffic traveling in the C2S direction. 
 
   
     
     
         32 . The system of  claim 30 , wherein the offload service is identified during an establishment of the session. 
     
     
         33 . The system of  claim 30 , wherein the offload service is identified based on a change to at the one or more security services. 
     
     
         34 . The system of  claim 30 , wherein the one or more processors are further configured to:
 store information associated with the offload service after identifying the offload service.   
     
     
         35 . A non-transitory computer-readable medium storing instructions, the instructions comprising:
 one or more instructions that, when executed by one or more processors, cause the one or more processors to:
 determine that no security service, of one or more security services, is to inspect all traffic of a session; 
 determine, based on determining that no security services is to inspect all traffic of the session, that a security service, of the one or more security services, is to inspect traffic in a client-to-server (C2S) direction; 
 determine, based on determining that the security service is to inspect traffic in the C2S direction, that an offload service includes inspecting traffic traveling in the C2S direction; 
 identify the offload service based on determining that the offload service includes inspecting the traffic traveling in the C2S direction; and 
 apply the offload service based on identifying the offload service. 
   
     
     
         36 . The non-transitory computer-readable medium of  claim 35 , wherein the one or more instructions, when executed by the one or more processors, further cause the one or more processors to:
 determine, based on determining that no security services is to inspect all traffic of the session, that no security service, of the one or more security services, is to inspect traffic in a server-to-client (S2C) direction,
 wherein the one or more instructions to determine that the offload service includes inspecting the traffic traveling in the C2S direction comprise one or more instructions to:
 determine, based on determining that the security service is to inspect traffic in the C2S direction and based on determining that no security service, of the one or more security services, is to inspect the traffic in the S2C direction, that the offload service includes inspecting the traffic traveling in the C2S direction. 
 
   
     
     
         37 . The non-transitory computer-readable medium of  claim 35 , wherein the offload service is identified after an establishment of the session. 
     
     
         38 . The non-transitory computer-readable medium of  claim 35 , wherein the offload service is identified based on a request provided by a client device or a service device. 
     
     
         39 . The non-transitory computer-readable medium of  claim 35 , wherein the offload service is identified based on a change to at the one or more security services. 
     
     
         40 . The non-transitory computer-readable medium of  claim 35 , wherein the one or more instructions, when executed by the one or more processors, further cause the one or more processors to:
 store information associated with the offload service after identifying the offload service.

Join the waitlist — get patent alerts

Track US2020028822A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.