Method and apparatus for decryption of encrypted ssl data from packet traces
Abstract
An example first device disclosed herein is to obtain, from a library of the first device, a pre-master secret value and a master secret value associated with a session key for a communication session between the first device and a second device, the library instrumented to log the pre-master and master secret values during handshaking, the session key based on the pre-master secret value, the master secret value and data strings exchanged during the handshaking. The disclosed example first device is also to capture a packet level trace corresponding to the communication session, the packet level trace including the data strings and encrypted data. The disclosed example first device is further to determine the session key based on the pre-master secret value, the master secret value and the data strings without use of a proxy, and decrypt the encrypted data with the session key to obtain decrypted data.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A first device comprising:
a memory including computer readable instructions; and a processor to execute the computer readable instructions to perform operations, the operations comprising:
obtaining a pre-master secret value associated with a session key for a communication session between the first device and a second device, the session key being based on a master secret value and data strings exchanged between the first device and the second device during handshaking;
determining the session key based on the master secret value and the data strings without use of a proxy, wherein the determining of the session key comprises:
evaluating a function with the pre-master secret value and the data strings to determine an output value of the function as the master secret value; and
utilizing the output value of the function as the master secret value to determine that the master secret value is associated with encrypted data corresponding to the communication session; and
decrypting the encrypted data with the session key to obtain decrypted data.
2 . The first device of claim 1 , wherein the function is a first function, wherein the first function is a publicly known function, and wherein the determining of the session key further includes evaluating a second function with the master secret value and the data strings to determine the session key.
3 . The first device of claim 1 , wherein the encrypted data is of a packet level trace corresponding to the communication session, and wherein the packet level trace is captured by recording the packet level trace in a packet capture format.
4 . The first device of claim 1 , wherein the communication session corresponds to one of a secure socket layer protocol session or a transport layer security protocol session.
5 . The first device of claim 1 , wherein the decrypting of the encrypted data with the session key to obtain the decrypted data occurs after the communication session has ended.
6 . The first device of claim 1 , wherein the decrypting of the encrypted data with the session key is to obtain the decrypted data for traffic measurement.
7 . The first device of claim 1 , wherein the data strings are exchanged between the first device and the second device in plain text.
8 . The first device of claim 1 , wherein the first device comprises a smart phone.
9 . A non-transitory computer readable memory comprising computer readable instructions that, when executed by a processor of a first device, cause the processor to perform operations, the operations comprising:
obtaining a pre-master secret value associated with a session key for a communication session between the first device and a second device, the first device and the second device having engaged in a handshaking process, and the session key being based on a master secret value and data strings exchanged between the first device and the second device during the handshaking process; determining the session key based on the master secret value and the data strings, the session key being determined without use of a proxy, the determining of the session key comprising:
evaluation of a function with the pre-master secret value and the data strings to determine an output value of the function as the master secret value; and
utilization of the output value of the function as the master secret value to determine that the master secret value is associated with encrypted data of a packet level trace that corresponds to the communication session; and
obtaining decrypted data by decrypting the encrypted data with the session key.
10 . The non-transitory computer readable memory of claim 9 , wherein the function is a first function, wherein the determining of the session key further includes evaluation of a second function with the master secret value and the data strings to determine the session key, and wherein the second function is a publicly known function.
11 . The non-transitory computer readable memory of claim 9 , wherein the packet level trace is captured by recording the packet level trace in a packet capture format.
12 . The non-transitory computer readable memory of claim 9 , wherein the communication session corresponds to one of a secure socket layer protocol session or a transport layer security protocol session.
13 . The non-transitory computer readable memory of claim 9 , wherein the data strings are exchanged between the first device and the second device in plain text.
14 . The non-transitory computer readable memory of claim 9 , wherein the first device comprises a smart phone.
15 . A method comprising:
obtaining a pre-master secret value associated with a session key for a communication session between a first device and a second device, the first device and the second device having engaged in a handshaking process, the session key being based on a master secret value and data strings exchanged between the first device and the second device during the handshaking process, and the first device comprising a processor; determining, by executing instructions with the processor of the first device, the session key based on the master secret value and the data strings without use of a proxy, wherein the determining of the session key comprises:
evaluating a function with the pre-master secret value and the data strings to determine the master secret value; and
utilizing the master secret value that was determined by evaluating the function to determine that the master secret value is associated with encrypted data corresponding to the communication session; and
decrypting, by executing second instructions with the processor of the first device, the encrypted data with the session key to obtain decrypted data.
16 . The method of claim 15 , wherein the function is a first function, and the determining of the session key further includes evaluating a second function with the master secret value and the data strings to determine the session key.
17 . The method of claim 15 , wherein the encrypted data is of a packet level trace corresponding to the communication session, and wherein the packet level trace is captured by recording the packet level trace in a packet capture format.
18 . The method of claim 15 , wherein the communication session corresponds to one of a secure socket layer protocol session or a transport layer security protocol session.
19 . The method of claim 15 , wherein the data strings are exchanged between the first device and the second device in plain text.
20 . The method of claim 15 , wherein the first device comprises a smart phone.Join the waitlist — get patent alerts
Track US2022109695A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.