CloudFlare can provide its caching service without your SSL keys

The company said it has made an encryption breakthrough that will put financial institutions at ease

CloudFlare says it has engineered a novel way to handle sensitive encryption keys that allow organizations such as financial institutions  to retain their SSL keys but still use its services.

CloudFlare says it has engineered a novel way to handle sensitive encryption keys that allow organizations such as financial institutions to retain their SSL keys but still use its services.

CloudFlare said it has engineered a novel way to handle sensitive encryption keys that allows organizations such as financial institutions to still use its caching service to fend off cyberattacks.

The breakthrough, called "Keyless SSL," is a new method for handling SSL (Secure Socket Layer) keys, which are used to encrypt content between a client and a service and are a fundamental defense to prevent intercepted data from being read by an attacker.

The company's popular services protect websites from distributed denial-of-service and other attacks by using a network of global data centers to detect and filter attack traffic and keep websites online through extensive caching.

Websites using SSL could be accommodated by CloudFlare, but those operators had to turn over their SSL encryption keys. That's risky, since the safety of the data is dependent on how well a third-party provider protects those keys.

If a bank's SSL key is lost, for example, the incident is so serious that it must be reported to the Federal Reserve, wrote Matthew Prince, CloudFlare's CEO, in a blog post on Thursday.

A stolen SSL key would allow attackers to decrypt traffic they've intercepted or set up a fake website that appears to be legitimate.

According to a technical writeup, Keyless SSL works like this: a person's Web browser connects to the closest CloudFlare server and sends a bit of data, called a secret, that has been encrypted with a bank's public SSL key.

CloudFlare's server authenticates itself to a key server and sends its own encrypted secret, which the key server decrypts and sends it back over an encrypted tunnel. The shared secret is then used to connect the Web browser and the bank's online service via CloudFlare.

One of the company's edge nodes, or session server, does have to decrypt, inspect and re-encrypt the traffic before it goes back to the bank's site, CloudFlare said.

Keyless SSL has been audited by iSEC Partners and Matasano Security, according to CloudFlare. The company will offer Keyless SSL initially for customers on its enterprise plan.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

Join the Good Gear Guide newsletter!

Error: Please check your email address.

Tags securityCloudFlareencryption

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Jeremy Kirk

IDG News Service
Show Comments

Cool Tech

Crucial Ballistix Elite 32GB Kit (4 x 8GB) DDR4-3000 UDIMM

Learn more >

Gadgets & Things

Lexar® Professional 1000x microSDHC™/microSDXC™ UHS-II cards

Learn more >

Family Friendly

Lexar® JumpDrive® S57 USB 3.0 flash drive 

Learn more >

Stocking Stuffer

Plox Star Wars Death Star Levitating Bluetooth Speaker

Learn more >

Christmas Gift Guide

Click for more ›

Most Popular Reviews

Latest News Articles

Resources

GGG Evaluation Team

Kathy Cassidy

STYLISTIC Q702

First impression on unpacking the Q702 test unit was the solid feel and clean, minimalist styling.

Anthony Grifoni

STYLISTIC Q572

For work use, Microsoft Word and Excel programs pre-installed on the device are adequate for preparing short documents.

Steph Mundell

LIFEBOOK UH574

The Fujitsu LifeBook UH574 allowed for great mobility without being obnoxiously heavy or clunky. Its twelve hours of battery life did not disappoint.

Andrew Mitsi

STYLISTIC Q702

The screen was particularly good. It is bright and visible from most angles, however heat is an issue, particularly around the Windows button on the front, and on the back where the battery housing is located.

Simon Harriott

STYLISTIC Q702

My first impression after unboxing the Q702 is that it is a nice looking unit. Styling is somewhat minimalist but very effective. The tablet part, once detached, has a nice weight, and no buttons or switches are located in awkward or intrusive positions.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?