SSi Service Strategies Inc.

SSL Aggregation

 

 

 

Home
Request Information
Contact SSi
Glossary of Terms
Site Contents
Site Search
Notices

 

SSi

SSL Aggregation and Session Re-use

SSL Aggregation

SSL Aggregation is an extension of SonicWALL’s SSL Initiation capabilities. When initiating outbound SSL traffic, the SonicWALL Offloader has the ability to take advantage of a characteristic of SSL known as Session re-use. Session re-use, introduced in SSLv3, was designed to reduce the burden of establishing a new SSL session by reusing previously established SSL Session ID’s. The SSL Session ID is a 32 byte sequence that is used to uniquely identify an SSL session, and to allow SSL clients and servers to maintain an index of ID’s and corresponding key material.

Typical SSL Session

Referring to the figure above, the SSL Session ID is initially presented by the server to the client as part of the Server Hello, one of the early messages exchanged during SSL session establishment. As long as communications between the client and server use the same TCP session after session establishment, there is no need for session renegotiation, and all application data will re-use the same symmetric key. In subsequent communications, i.e. where new TCP sessions are opened, the client has the option to include the previously established Session ID in the Client Hello, telling the server to re-use the already shared key material. This helps to substantially reduce the intensiveness of establishing a new SSL Session.

SSL Aggregation

SSL Aggregation allows for thousands of front-end SSL sessions (e.g. Internet-based clients to a SonicWALL SSL offloader) to be combined into a single SSL Session ID to the back-end SSL server over discrete TCP connections. The relationship between front-end clients and back-end TCP connections remains 1:1, but the relationship between front-end clients and back-end SSL session is n:1.

SonicWALL’s ability to perform SSL Aggregation positions it as a perfect replacement for server-based SSL solutions (either software or PCI/SCSI based accelerators) because it retains the strong security of end-to-end encryption, but it does so at a fraction of the processing overhead normally associated with SSL.

If you would like to request additional information on an SSL security product or application, please click on the button below.

Certified SonicWALL Sales Experts

 

Service Strategies Inc.

2392 Mount Vernon Rd

Dunwoody, GA 30338-3092

678-441-0020   800-662-1615

assist@ssimail.com

Copyright © 1998 - 2002 Service Strategies Inc. All rights reserved.
Revised: April 04, 2005.