Patent · US Active

Decrypting network traffic on a middlebox device using a trusted execution environment

US10044691B1 · kind B1 · utility

0Cited by
0References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateFeb 12, 2018
Grant dateAug 7, 2018
Priority date
Expiry dateFeb 12, 2038

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/0281
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Decrypting network traffic on a middlebox device using a trusted execution environment (TEE). In one embodiment, a method may include loading a kernel application inside the TEE, loading a logic application outside the TEE, intercepting, by the logic application, encrypted network traffic, forwarding, from the logic application to the kernel application, the encrypted network traffic, decrypting, at the kernel application, the encrypted network traffic, inspecting, at the kernel application, the decrypted network traffic according to a sensitivity policy to determine whether the decrypted network traffic includes sensitive data, forwarding, from the kernel application to the logic application, filtered decrypted network traffic that excludes the sensitive data, processing, at the logic application, the filtered decrypted network traffic, forwarding, from the logic application to the kernel application, the filtered decrypted network traffic after the processing by the logic application, and forwarding, from the kernel application, the encrypted network traffic.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.