- Patent Title: Managing encrypted server-name-indication (ESNI) at proxy devices
-
Application No.: US17833458Application Date: 2022-06-06
-
Publication No.: US11722463B2Publication Date: 2023-08-08
- Inventor: Jianxin Wang , Hari Shankar
- Applicant: Cisco Technology, Inc.
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Lee & Hayes, P.C.
- Main IPC: H04L9/40
- IPC: H04L9/40 ; H04L9/08

Abstract:
In one embodiment, a network security device is configured to monitor data traffic between a first device and a second device. The network security device may be configured to intercept a first initial message of a first encrypted handshaking procedure for a first secure communication session between the first device and the second device, the first initial message specifying a hostname that has been encrypted using first key information associated with the network security device, decrypt at least a portion of the first initial message using the first key information to determine the hostname, re-encrypt the hostname using second key information associated with the second device, and send, to the second device, a second initial message of a second encrypted handshaking procedure for a second secure communication session between the network security device and the second device, the second initial message specifying the hostname re-encrypted using the second key information.
Public/Granted literature
- US20220303251A1 Managing Encrypted Server-Name-Indication (ESNI) at Proxy Devices Public/Granted day:2022-09-22
Information query