Invention Grant
- Patent Title: Transparently converting a TLS session connection to facilitate session resumption
-
Application No.: US15611202Application Date: 2017-06-01
-
Publication No.: US10547641B2Publication Date: 2020-01-28
- Inventor: Cheng-Ta Lee , Wei-Hsiang Hsiung , Wei-Shiau Suen , Ming-Hsun Wu
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agent Jeffrey S. LaBaw; David H. Judson
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L9/30 ; H04L9/08 ; H04L9/32 ; H04L29/08

Abstract:
A network-based appliance includes a mechanism to provide TLS inspection with session resumption, but without requiring that a session cache be maintained. To this end, the inspector is configured to cause the TLS client to participate in maintaining the session context, in effect on behalf of the TLS inspector. In operation, when the inspector first receives a session ID from the TLS server, the inspector generates and issues to the client a session ticket that includes the original session ID and other session context information. In this manner, the inspector converts the Session ID-based connection to a Session Ticket-based connection. The session ticket is encrypted by the inspector to secure the session information. When the TLS client presents the session ticket to resume the TLS connection, the inspector decrypts the ticket and retrieves the session ID from it directly. The inspector then uses the original session ID to resume the TLS session.
Public/Granted literature
- US20180351997A1 Transparently converting a TLS session connection to facilitate session resumption Public/Granted day:2018-12-06
Information query