CNIPA.AI
返回搜索
档案

Client-Rooted Decryption Public Key Infrastructure (PKI) for Secure Cloud-Based Inspection of Encrypted Traffic

发明专利审中
2浏览
20权利要求 · 3 独立
§ Ⅰ

卷宗概要

发明人

Loren Weith; Yaroslav Rosomakho; John A. Chanak; Vadim Tarnavsky; Lidor Pergament

IPC 分类

H4L 9/32H4L 9/40

CPC 分类

H4L9/3263H4L63/428H4L63/1416

Techniques for implementing a client-rooted decryption Public Key Infrastructure (PKI) to securely inspect encrypted traffic in cloud-based proxy environments are disclosed. A proxy node generates an intermediate Certificate Authority (CA) certificate signing request (CSR) and sends it to a client device equipped with a locally-managed root CA. The client device cross-signs the CSR, creating a client-specific intermediate CA certificate, which it returns to the proxy node. This client-specific intermediate CA certificate is scoped uniquely to the individual client device, significantly reducing the potential blast radius in case of CA key compromise. The proxy node uses the client-specific CA certificate to dynamically generate short-lived, scoped decryption certificates for inspecting encrypted traffic. This architecture provides client-level control of trust boundaries, enhanced traceability, reduced complexity, and improved scalability of encrypted traffic inspection, minimizing the operational risks associated with conventional centralized certificate management.

原文(中文)

Techniques for implementing a client-rooted decryption Public Key Infrastructure (PKI) to securely inspect encrypted traffic in cloud-based proxy environments are disclosed. A proxy node generates an intermediate Certificate Authority (CA) certificate signing request (CSR) and sends it to a client device equipped with a locally-managed root CA. The client device cross-signs the CSR, creating a client-specific intermediate CA certificate, which it returns to the proxy node. This client-specific intermediate CA certificate is scoped uniquely to the individual client device, significantly reducing the potential blast radius in case of CA key compromise. The proxy node uses the client-specific CA certificate to dynamically generate short-lived, scoped decryption certificates for inspecting encrypted traffic. This architecture provides client-level control of trust boundaries, enhanced traceability, reduced complexity, and improved scalability of encrypted traffic inspection, minimizing the operational risks associated with conventional centralized certificate management.