Invention Grant
- Patent Title: Selective modification of encrypted application layer data in a transparent security gateway
- Patent Title (中): 在透明安全网关中选择性修改加密的应用层数据
-
Application No.: US14833013Application Date: 2015-08-21
-
Publication No.: US09553892B2Publication Date: 2017-01-24
- Inventor: Ido Kelson , Dmitry Babich
- Applicant: Imperva, Inc.
- Applicant Address: US CA Redwood City
- Assignee: IMPERVA, INC.
- Current Assignee: IMPERVA, INC.
- Current Assignee Address: US CA Redwood City
- Agency: Nicholson de vos Webster & Elliott, LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L29/08

Abstract:
According to one embodiment, a transparent security gateway is coupled between a client end station (CES) and a web application server (WAS). The security gateway monitors an encryption protocol handshake between the CES and the WAS to capture, using a provided private key of the WAS, a generated symmetric key to be used for an encryption layer connection. Using the captured symmetric key, the security gateway receives an encrypted connection record of the encryption layer connection, decrypts the encrypted connection record to yield a plaintext connection record, modifies the plaintext connection record, encrypts the modified plaintext connection record using the symmetric key, and transmits one or more packets carrying the encrypted modification plaintext connection record instead of the received encrypted connection record such that neither the CES or WAS is aware of the modification of the encrypted data.
Public/Granted literature
- US20150381657A1 SELECTIVE MODIFICATION OF ENCRYPTED APPLICATION LAYER DATA IN A TRANSPARENT SECURITY GATEWAY Public/Granted day:2015-12-31
Information query