TWI362871B - System and method for mapping an encrypted https network packet to a specific url name and other data without decryption outside of a secure web server - Google Patents

System and method for mapping an encrypted https network packet to a specific url name and other data without decryption outside of a secure web server Download PDF

Info

Publication number
TWI362871B
TWI362871B TW095106170A TW95106170A TWI362871B TW I362871 B TWI362871 B TW I362871B TW 095106170 A TW095106170 A TW 095106170A TW 95106170 A TW95106170 A TW 95106170A TW I362871 B TWI362871 B TW I362871B
Authority
TW
Taiwan
Prior art keywords
network
request packet
encrypted
nickname
module
Prior art date
Application number
TW095106170A
Other languages
English (en)
Chinese (zh)
Other versions
TW200640217A (en
Inventor
Paul Fredric Klein
Jesse Nicholas Perez
Original Assignee
Ibm
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Family has litigation
First worldwide family litigation filed litigation Critical https://patents.darts-ip.com/?family=36273444&utm_source=google_patent&utm_medium=platform_link&utm_campaign=public_patent_search&patent=TWI362871(B) "Global patent litigation dataset” by Darts-ip is licensed under a Creative Commons Attribution 4.0 International License.
Application filed by Ibm filed Critical Ibm
Publication of TW200640217A publication Critical patent/TW200640217A/zh
Application granted granted Critical
Publication of TWI362871B publication Critical patent/TWI362871B/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/04Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0428Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/16Implementing security features at a particular protocol layer
    • H04L63/168Implementing security features at a particular protocol layer above the transport layer
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/02Protocols based on web technology, e.g. hypertext transfer protocol [HTTP]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • H04L63/1425Traffic logging, e.g. anomaly detection

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Storage Device Security (AREA)
  • Computer And Data Communications (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Peptides Or Proteins (AREA)
  • Information Transfer Between Computers (AREA)
TW095106170A 2005-02-28 2006-02-23 System and method for mapping an encrypted https network packet to a specific url name and other data without decryption outside of a secure web server TWI362871B (en)

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
US11/067,990 US7657737B2 (en) 2005-02-28 2005-02-28 Method for mapping an encrypted https network packet to a specific url name and other data without decryption outside of a secure web server

Publications (2)

Publication Number Publication Date
TW200640217A TW200640217A (en) 2006-11-16
TWI362871B true TWI362871B (en) 2012-04-21

Family

ID=36273444

Family Applications (1)

Application Number Title Priority Date Filing Date
TW095106170A TWI362871B (en) 2005-02-28 2006-02-23 System and method for mapping an encrypted https network packet to a specific url name and other data without decryption outside of a secure web server

Country Status (10)

Country Link
US (1) US7657737B2 (https=)
EP (1) EP1854243B1 (https=)
JP (1) JP4596554B2 (https=)
CN (1) CN100544289C (https=)
AT (1) ATE441264T1 (https=)
BR (1) BRPI0608276B1 (https=)
CA (1) CA2598227C (https=)
DE (1) DE602006008749D1 (https=)
TW (1) TWI362871B (https=)
WO (1) WO2006089879A1 (https=)

Families Citing this family (19)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7865511B2 (en) 2004-06-25 2011-01-04 Apple Inc. News feed browser
US8612844B1 (en) * 2005-09-09 2013-12-17 Apple Inc. Sniffing hypertext content to determine type
US7882091B2 (en) * 2008-01-09 2011-02-01 Stephen Schneider Record tagging, storage and filtering system and method
US20100132007A1 (en) * 2008-11-25 2010-05-27 Cisco Technology, Inc. Accelerating channel change time with external picture property markings
US8850013B2 (en) * 2010-05-10 2014-09-30 Jaron Waldman Server load balancing using geodata
KR20120132013A (ko) * 2011-05-27 2012-12-05 주식회사 팬택 휴대용 단말, 휴대용 단말의 하드웨어 모듈간에 전송되는 데이터의 보안 방법
CN102811426A (zh) * 2011-05-30 2012-12-05 网秦无限(北京)科技有限公司 移动设备的消息的加密发送和接收的方法和系统
TWI581124B (zh) * 2012-01-13 2017-05-01 精品科技股份有限公司 網際網路之資料封包防護系統與方法
US9176838B2 (en) 2012-10-19 2015-11-03 Intel Corporation Encrypted data inspection in a network environment
US9043593B2 (en) * 2013-03-11 2015-05-26 International Business Machines Corporation Session attribute propagation through secure database server tiers
GB2516050A (en) * 2013-07-09 2015-01-14 Ibm A Network Security System
CN103701819B (zh) * 2013-12-30 2017-04-05 北京网康科技有限公司 超文本传输协议解密的处理方法及装置
CN105812345B (zh) * 2014-12-31 2019-08-23 广州市动景计算机科技有限公司 一种实现网页到客户端通信的方法及装置
US9774572B2 (en) * 2015-05-11 2017-09-26 Salesforce.Com, Inc. Obfuscation of references to network resources
JP6700894B2 (ja) * 2016-03-25 2020-05-27 キヤノン株式会社 画像処理装置、制御方法、プログラム
CN109165511B (zh) * 2018-08-08 2022-07-15 深圳前海微众银行股份有限公司 Web安全漏洞处理方法、系统及计算机可读存储介质
EP4611313A3 (en) 2020-05-04 2025-09-10 Juniper Networks, Inc. Efficient encryption and decryption of duplicate packets communicated via a virtual private network
US11575653B2 (en) * 2020-05-04 2023-02-07 Juniper Networks, Inc. Efficient encryption and decryption of duplicate packets communicated via a virtual private network
EP4009602B1 (en) * 2020-12-07 2022-11-09 Siemens Healthcare GmbH Providing a first digital certificate and a dns response

Family Cites Families (30)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP3263878B2 (ja) * 1993-10-06 2002-03-11 日本電信電話株式会社 暗号通信システム
WO1998011702A1 (en) 1996-09-10 1998-03-19 Accrue Software, Inc. Apparatus and methods for capturing, analyzing and viewing live network information
GB2319705B (en) * 1996-11-21 2001-01-24 Motorola Ltd Arrangement for encryption/decryption of data and data carrier incorporating same
US6065046A (en) * 1997-07-29 2000-05-16 Catharon Productions, Inc. Computerized system and associated method of optimally controlled storage and transfer of computer programs on a computer network
US6092196A (en) * 1997-11-25 2000-07-18 Nortel Networks Limited HTTP distributed remote user authentication system
US6148336A (en) * 1998-03-13 2000-11-14 Deterministic Networks, Inc. Ordering of multiple plugin applications using extensible layered service provider with network traffic filtering
US6363477B1 (en) * 1998-08-28 2002-03-26 3Com Corporation Method for analyzing network application flows in an encrypted environment
US6324648B1 (en) * 1999-12-14 2001-11-27 Gte Service Corporation Secure gateway having user identification and password authentication
US6510464B1 (en) * 1999-12-14 2003-01-21 Verizon Corporate Services Group Inc. Secure gateway having routing feature
US7325127B2 (en) * 2000-04-25 2008-01-29 Secure Data In Motion, Inc. Security server system
US7673329B2 (en) * 2000-05-26 2010-03-02 Symantec Corporation Method and apparatus for encrypted communications to a secure server
US20020035559A1 (en) * 2000-06-26 2002-03-21 Crowe William L. System and method for a decision engine and architecture for providing high-performance data querying operations
US20020035681A1 (en) * 2000-07-31 2002-03-21 Guillermo Maturana Strategy for handling long SSL messages
US8364798B2 (en) * 2001-01-23 2013-01-29 Verizon Business Global Llc Method and system for providing software integration for a telecommunications services on-line procurement system
US9219708B2 (en) * 2001-03-22 2015-12-22 DialwareInc. Method and system for remotely authenticating identification devices
US7409714B2 (en) 2001-06-13 2008-08-05 Mcafee, Inc. Virtual intrusion detection system and method of using same
US7149892B2 (en) * 2001-07-06 2006-12-12 Juniper Networks, Inc. Secure sockets layer proxy architecture
GB0119488D0 (en) * 2001-08-10 2001-10-03 Cellectivity Ltd E-commerce method for mobile telephones
US20030065941A1 (en) * 2001-09-05 2003-04-03 Ballard Clinton L. Message handling with format translation and key management
US6970918B2 (en) * 2001-09-24 2005-11-29 International Business Machines Corporation System and method for transcoding support of web content over secure connections
US7010608B2 (en) * 2001-09-28 2006-03-07 Intel Corporation System and method for remotely accessing a home server while preserving end-to-end security
US7181141B1 (en) * 2001-11-02 2007-02-20 Ciena Corporation Method and system for collecting network topology in an optical communications network
US7093121B2 (en) * 2002-01-10 2006-08-15 Mcafee, Inc. Transferring data via a secure network connection
JP2003209570A (ja) * 2002-01-11 2003-07-25 Fujitsu Ltd 中継方法そのクライアント、サーバ、中継装置
US20030163608A1 (en) * 2002-02-21 2003-08-28 Ashutosh Tiwary Instrumentation and workload recording for a system for performance testing of N-tiered computer systems using recording and playback of workloads
US7260623B2 (en) * 2002-06-27 2007-08-21 Sun Microsystems, Inc. Remote services system communication module
JP3794491B2 (ja) * 2002-08-20 2006-07-05 日本電気株式会社 攻撃防御システムおよび攻撃防御方法
US7386723B2 (en) * 2002-11-22 2008-06-10 Intel Corporation Method, apparatus and system for compressing IPSec-protected IP packets
US7412539B2 (en) * 2002-12-18 2008-08-12 Sonicwall, Inc. Method and apparatus for resource locator identifier rewrite
US7627669B2 (en) * 2003-05-21 2009-12-01 Ixia Automated capturing and characterization of network traffic using feedback

Also Published As

Publication number Publication date
EP1854243A1 (en) 2007-11-14
EP1854243B1 (en) 2009-08-26
BRPI0608276A2 (pt) 2009-12-15
JP4596554B2 (ja) 2010-12-08
ATE441264T1 (de) 2009-09-15
CA2598227C (en) 2014-10-07
JP2008532398A (ja) 2008-08-14
US7657737B2 (en) 2010-02-02
TW200640217A (en) 2006-11-16
BRPI0608276B1 (pt) 2019-02-05
CA2598227A1 (en) 2006-08-31
US20060195687A1 (en) 2006-08-31
CN100544289C (zh) 2009-09-23
CN101107812A (zh) 2008-01-16
WO2006089879A1 (en) 2006-08-31
DE602006008749D1 (de) 2009-10-08

Similar Documents

Publication Publication Date Title
TWI362871B (en) System and method for mapping an encrypted https network packet to a specific url name and other data without decryption outside of a secure web server
US7441116B2 (en) Secure resource distribution through encrypted pointers
US8825999B2 (en) Extending encrypting web service
US8145898B2 (en) Encryption/decryption pay per use web service
CN101299753B (zh) 具有web服务安全控制机制的代理服务器
JP2018160919A (ja) 要求によって供給される鍵を用いたデータセキュリティ
US20090285118A1 (en) Proxy terminal, service device, proxy terminal communication path setting method, and server device communication path setting method
US20130291089A1 (en) Data communication method and device and data interaction system based on browser
US20120163598A1 (en) Session secure web content delivery
CN104378379B (zh) 一种数字内容加密传输方法、设备和系统
WO2014066610A2 (en) Methods and systems for the secure exchange of information
US20080306875A1 (en) Method and system for secure network connection
WO2000018078A1 (en) Secure message exchange method using intermediaries
US20050076057A1 (en) Method and system for transferring video and audio files to portable computing devices
US8520840B2 (en) System, method and computer product for PKI (public key infrastructure) enabled data transactions in wireless devices connected to the internet
US12032713B1 (en) Systems and methods for sending and receiving encrypted submessages
US20090254756A1 (en) Data communication method
GB2551580A (en) Data communications
JP6125196B2 (ja) ネットワークシステム、ネットワークシステム用電子データの管理方法、そのためのプログラム及び、プログラムの記録媒体
CN107209751B (zh) 业务处理方法及装置
CN106464684A (zh) 业务处理方法及装置
CN117014483B (zh) Ssl会话建立方法、服务器及存储介质
CN119276591A (zh) 一种数据通信方法、装置、设备及计算机可读存储介质
WO2010133459A1 (fr) Procede de chiffrement de parties particulieres d' un document pour les utilisateurs privileges

Legal Events

Date Code Title Description
MM4A Annulment or lapse of patent due to non-payment of fees