Invention Grant
- Patent Title: Systems and methods for perfect forward secrecy (PFS) traffic monitoring via a hardware security module
-
Application No.: US15248876Application Date: 2016-08-26
-
Publication No.: US10425234B2Publication Date: 2019-09-24
- Inventor: Phanikumar Kancharla , Ram Kumar Manapragada , Tejinder Singh , Girish Kumar Yerra
- Applicant: Cavium, LLC
- Applicant Address: US CA Santa Clara
- Assignee: Cavium, LLC
- Current Assignee: Cavium, LLC
- Current Assignee Address: US CA Santa Clara
- Main IPC: H04L9/08
- IPC: H04L9/08 ; H04L9/32 ; H04L29/06

Abstract:
A new approach is proposed to support monitoring Perfect Forward Secrecy (PFS) network traffic by utilizing a hardware security module (HSM) appliance. Here, the HSM appliance is a high-performance, Federal Information Processing Standards (FIPS) 140-compliant security hardware with embedded firmware, which can be used for management and sharing of ephemeral keys used in a secured PFS communication session between two parties. Specifically, the HSM allows a server to share one or more of its ephemeral keys and/or parameters used in PFS traffic during the session with a third party under specified access rights and/or authorization, wherein the third party can be but is not limited to a traffic monitoring module. The HSM allows the third party to access the ephemeral keys stored on the HSM under the specified access rights and/or authorization so that the third party may decrypt and run analytics on the PFS traffic captured during the session.
Public/Granted literature
- US20180062854A1 SYSTEMS AND METHODS FOR PERFECT FORWARD SECRECY (PFS) TRAFFIC MONITORING VIA A HARDWARE SECURITY MODULE Public/Granted day:2018-03-01
Information query