Invention Grant
- Patent Title: Decrypting network traffic on a middlebox device using a trusted execution environment
-
Application No.: US16021950Application Date: 2018-06-28
-
Publication No.: US10447663B2Publication Date: 2019-10-15
- Inventor: Yuqiong Sun , Daniel Marino , Susanta K. Nanda , Saurabh Shintre , Brian T. Witten , Ronald A. Frederick , Qing Li
- Applicant: SYMANTEC CORPORATION
- Applicant Address: US CA Mountain View
- Assignee: SYMANTEC CORPORATION
- Current Assignee: SYMANTEC CORPORATION
- Current Assignee Address: US CA Mountain View
- Agency: Maschoff Brennan
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/62

Abstract:
Decrypting network traffic on a middlebox device using a trusted execution environment (TEE). In one embodiment, a method may include loading a kernel application inside the TEE, loading a logic application outside the TEE, intercepting, by the logic application, encrypted network traffic, forwarding, from the logic application to the kernel application, the encrypted network traffic, decrypting, at the kernel application, the encrypted network traffic, inspecting, at the kernel application, the decrypted network traffic according to a sensitivity policy to determine whether the decrypted network traffic includes sensitive data, forwarding, from the kernel application to the logic application, filtered decrypted network traffic that excludes the sensitive data, processing, at the logic application, the filtered decrypted network traffic, forwarding, from the logic application to the kernel application, the filtered decrypted network traffic after the processing by the logic application, and forwarding, from the kernel application, the encrypted network traffic.
Public/Granted literature
- US20190253398A1 DECRYPTING NETWORK TRAFFIC ON A MIDDLEBOX DEVICE USING A TRUSTED EXECUTION ENVIRONMENT Public/Granted day:2019-08-15
Information query