The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jun. 27, 2017

Filed:

Dec. 26, 2016
Applicant:

Akamai Technologies, Inc., Cambridge, MA (US);

Inventors:

Charles E. Gero, Quincy, MA (US);

Philip A. Lisiecki, Santa Barbara, CA (US);

Assignee:

Akamai Technologies, Inc., Cambridge, MA (US);

Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); H04L 9/08 (2006.01); H04L 9/06 (2006.01);
U.S. Cl.
CPC ...
H04L 63/061 (2013.01); H04L 9/0643 (2013.01); H04L 9/0825 (2013.01); H04L 9/0869 (2013.01); H04L 63/0442 (2013.01); H04L 63/166 (2013.01); H04L 2209/76 (2013.01);
Abstract

An infrastructure delivery platform provides a RSA proxy service as an enhancement to the TLS/SSL protocol to off-load, from an edge server to an external cryptographic server, the decryption of an encrypted pre-master secret. The technique provides forward secrecy in the event that the edge server is compromised, preferably through the use of a cryptographically strong hash function that is implemented separately at both the edge server and the cryptographic server. To provide the forward secrecy for this particular leg, the edge server selects an ephemeral value, and applies a cryptographic hash the value to compute a server random value, which is then transmitted back to the requesting client. That server random value is later re-generated at the cryptographic server to enable the cryptographic server to compute a master secret. The forward secrecy is enabled by ensuring that the ephemeral value does not travel on the wire.


Find Patent Forward Citations

Loading…