Method and apparatus for split-terminating a secure network connection, with client authentication
US8438628B2 · kind B2 · utility
Assignee
Inventors
Key dates
| Filing date | Jun 29, 2010 |
| Grant date | May 7, 2013 |
| Priority date | — |
| Expiry date | Oct 19, 2030 |
Classification
- Technology area (CPC H)Electricity
- CPC primaryH04L2209/76
- WIPO fieldDigital communication
- WIPO sectorElectrical engineering
Abstract
A method and apparatus are provided for split-terminating a secure client-server communication connection, with client authentication. During handshaking between the client and the server, cooperating network intermediaries relay the handshaking messages, without altering the messages. At least one of the intermediaries possesses a private key of the server, and extracts a set of data fields from the handshaking messages, including a Client-Key-Exchange message that can be decrypted with the private key. The intermediary uses the extracted data to compute the client-server session key separate from the client's and the server's similar computation, and may transmit the key to the other intermediary via a secure communication channel. The client and the server thus establish the end-to-end client-server connection, and may authenticate each other, after which the network intermediaries may intercept and optimize the client-server communications transparently to the client and the server.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.