US2024031135A1PendingUtilityA1
Key broker for a network monitoring device, and applications thereof
Est. expiryJun 3, 2040(~13.9 yrs left)· nominal 20-yr term from priority
H04L 9/083H04L 43/04H04L 63/166H04L 9/3263H04L 9/0891H04L 63/18H04L 9/0894H04L 9/088H04L 63/0227H04L 63/0464H04L 63/062H04L 43/12
67
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A key broker monitors network traffic metadata and determines which decryption keys are required at one or more packet brokers in order to decrypt relevant traffic required by various network monitoring devices. The key broker retrieves the required keys from a secure keystore distributes them, as needed, to the network packet brokers, and dynamically updates the decryption keys stored in the network packet brokers in response to changes in network traffic.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A system for managing ephemeral keys, the system comprising:
a key agent comprising computer-executable instructions on an endpoint device that, when executed by a processor on the endpoint device, performs operations comprising:
passively collecting one or more ephemeral keys in response to a transport layer security handshake; and
sending, through out-of-band communications, the one or more ephemeral keys to a key ingestion service;
a secure keystore configured to store the one or more ephemeral keys; a network terminal access point (TAP) configured to capture a packet on a computer network; and a key broker comprising computer-executable instructions on a server that, when executed by a processor on the server, performs operations comprising:
receiving metadata corresponding to the captured packet;
retrieving an ephemeral key corresponding to the captured packet, from the secure keystore, based on the metadata;
providing the ephemeral key to a network monitoring device; and
removing the ephemeral key from the network monitoring device in response to determining that the ephemeral key is no longer required based on an amount of traffic corresponding to the ephemeral key.
2 . The system of claim 1 , wherein the key ingestion service further comprises computer-executable instructions on the server that, when executed by the processor on the server, performs operations comprising:
determining, based on a privacy policy, whether to discard the one or more ephemeral keys or send the one or more ephemeral keys to the secure keystore.
3 . The system of claim 1 , wherein the metadata comprises: domain information, an unencrypted destination corresponding to the captured packet, or an identifier of a security certificate corresponding to the ephemeral keys.
4 . The system of claim 1 , wherein the operations performed by the key broker further comprises:
storing tracking data associated with the ephemeral key, wherein the tracking data comprises an identifier for the ephemeral key, an identifier of the network monitoring device to which the ephemeral key was distributed, a lease time for the ephemeral key, a number of times the lease time for the ephemeral key was reset, and a number of times the ephemeral key was distributed to network monitoring devices.
5 . The system of claim 4 , wherein the operations performed by the key broker further comprises:
receiving a request for the ephemeral key from the network monitoring device; determining, based on the tracking data, that the ephemeral key has previously been provided to the network monitoring device; resetting the lease time for the ephemeral key in response to determining that the ephemeral key has already been provided to the network monitoring device; and updating the number of times that the lease time has been reset in the tracking data.
6 . The system of claim 5 , wherein the operations performed by the key broker further comprises:
generating an audit trail for the ephemeral key based on the tracking data.
7 . The system of claim 5 , wherein the operations performed by the key broker further comprises:
removing the ephemeral key from the network monitoring device in response to expiration of the lease time.
8 . The system of claim 1 , wherein the operations performed by the key broker further comprises:
setting a time-to-live (TTL) value for each of the one or more ephemeral keys based on a retention policy for captured network traffic; and deleting the one or more ephemeral keys from the secure keystore after expiration of the TTL value.
9 . A method of managing ephemeral keys in a network environment, the method comprising:
passively collecting one or more ephemeral keys in response to a transport layer security handshake; determining, based on a privacy policy, whether to discard the one or more ephemeral keys or send the one or more ephemeral keys to a secure keystore; capturing a packet on a computer network; receiving metadata corresponding to the captured packet; retrieving, based on the metadata, an ephemeral key corresponding to the captured packet from the secure keystore; providing the ephemeral key to a network monitoring device; and removing the ephemeral key from the network monitoring device in response to determining that the ephemeral key is no longer required based on an amount of traffic corresponding to the ephemeral key.
10 . The method of claim 9 , wherein the metadata comprises: domain information, an unencrypted destination corresponding to the captured packet, or an identifier of a security certificate corresponding to the ephemeral keys.
11 . The method of claim 8 , further comprising storing tracking data associated with the ephemeral key, wherein the tracking data comprises an identifier for the ephemeral key, an identifier of the network monitoring device to which the ephemeral key was distributed, a lease time for the ephemeral key, a number of times the lease time for the ephemeral key was reset, and a number of times the ephemeral key was distributed to network monitoring devices.
12 . The method of claim 11 , further comprising:
receiving a request for the ephemeral key from the network monitoring device; determining, based on the tracking data, that the ephemeral key has previously been provided to the network monitoring device; resetting the lease time for the ephemeral key in response to determining that the ephemeral key has already been provided to the network monitoring device; and updating the number of times that the lease time has been reset in the tracking data.
13 . The method of claim 12 , further comprising generating an audit trail for the ephemeral key based on the tracking data.
14 . The method of claim 12 , further comprising removing the ephemeral key from the network monitoring device in response to expiration of the lease time.
15 . The method of claim 9 , further comprising:
setting a time-to-live (TTL) value for each of the one or more ephemeral keys based on a retention policy for captured network traffic; and deleting the one or more ephemeral keys from the secure keystore after expiration of the TTL value.
16 . A non-transitory computer-readable medium storing instructions that, when executed by a processor, cause the processor to perform operations comprising:
passively collecting one or more ephemeral keys in response to a transport layer security handshake; determining, based on a privacy policy, whether to discard the one or more ephemeral keys or send the one or more ephemeral keys to a secure keystore; capturing a packet on a computer network; receiving metadata corresponding to the captured packet; retrieving, based on the metadata, an ephemeral key corresponding to the captured packet from the secure keystore; providing the ephemeral key to a network monitoring device; and removing the ephemeral key from the network monitoring device in response to determining that the ephemeral key is no longer required based on an amount of traffic corresponding to the ephemeral key.
17 . The non-transitory computer readable medium of claim 16 , wherein the metadata comprises: domain information, an unencrypted destination corresponding to the captured packet, or an identifier of a security certificate corresponding to the ephemeral keys.
18 . The non-transitory computer readable medium of claim 16 , the operations further comprising storing tracking data associated with the ephemeral key, wherein the tracking data comprises an identifier for the ephemeral key, an identifier of the network monitoring device to which the ephemeral key was distributed, a lease time for the ephemeral key, a number of times the lease time for the ephemeral key was reset, and a number of times the ephemeral key was distributed to network monitoring devices.
19 . The non-transitory computer readable medium of claim 18 , the operations further comprising:
receiving a request for the ephemeral key from the network monitoring device; determining, based on the tracking data, that the ephemeral key has previously been provided to the network monitoring device; resetting the lease time for the ephemeral key in response to determining that the ephemeral key has already been provided to the network monitoring device; and updating the number of times that the lease time has been reset in the tracking data.
20 . The non-transitory computer readable medium of claim 16 , the operations further comprising:
setting a time-to-live (TTL) value for each of the one or more ephemeral keys based on a retention policy for captured network traffic; and deleting the one or more ephemeral keys from the secure keystore after expiration of the TTL value.Join the waitlist — get patent alerts
Track US2024031135A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.