The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Mar. 11, 2025

Filed:

May. 24, 2022
Applicant:

Bitdefender Ipr Management Ltd., Nicosia, CY;

Inventors:

Ovidiu M. Craciun, Buchare, RO;

Bogdan C. Firuti, Buchare, RO;

Daniel I. A. Fetti, Salva, RO;

Constantin D. Cernat, Buchare, RO;

Assignee:
Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 9/08 (2006.01); H04L 61/4511 (2022.01);
U.S. Cl.
CPC ...
H04L 9/0825 (2013.01); H04L 9/0866 (2013.01); H04L 61/4511 (2022.05);
Abstract

Described systems and methods protect client devices such as personal computers and IoT devices against harmful or inappropriate Internet content. When a client uses an encrypted handshake to hide the identity of the end server, e.g., in applications implementing an encrypted client hello (ECH), some embodiments employ a modified DNS server to provide a surrogate key to the client instead of the genuine handshake key. A traffic filter executing for instance on a network gateway may then intercept and decrypt the handshake and apply an access policy to selectively allow or deny access to the respective end server. When access is allowed, the traffic filter may re-encrypt the server identifier using the genuine handshake key before forwarding the handshake to its destination. Communication privacy is maintained since the illustrated methods only decrypt the handshake, and not the actual payload.


Find Patent Forward Citations

Loading…