Nubeva licenses a modular family of software components to implement SKI (Session Key Intercept) based
TLS Decryption. Nubeva SKI delivers the modern solution for inline and passive systems decryption and inspection.
Offered as source and object code, Nubeva provides endpoint key extraction software (SKI Sensors) and both a turnkey and a library decryption option that utilizes symmetric keys.
The SKI Sensor and SKI Decryption solutions can be used in your solution independently or work together to form a complete solution. All elements support Nubeva’s innovative FastSKI™ protocol, which provides a highly reliable, secure, low-latency key delivery from source to destination.
SKI Sensors
Lightweight, read-only, nextgen endpoint software uses highly optimized TLS signatures to detect and decode TLS processes in memory and extract keys before handshakes complete. They work across today’s myriad of TLS implementations and a growing list of host platforms to extract keys for any session seamlessly from the client or server-side of a connection, intra-, and inter-machine. Sensors are easy to implement, easily managed, and work independent of authentication, PKI, without certs and server private keys. With no application or library changes, Nubeva’s discrete sensor is the answer to simplifying TLS decryption - once you have the session secrets, decryption is simple and efficient. Technical Details:
SKI Decryption Library
Nubeva’s Decryption Library is an advanced C-Library that supports high-speed TLS 1.3 and TLS 1.2 PFS decryption, delivering more than 12Gb/sec per core. Matching streamed traffic with the discovered session secrets (or keys from any other source), Nubeva’s secure Decryption Library enables pure, symmetric decryption embedded directly in existing or new inline and passive DPI systems.
SKI Decryptor
A complete symmetric key decryption solution delivered as a container. Using session keys discovered by Nubeva’s SKI sensors, the decryptor reads packets from an interface and matches the keys with streamed traffic. Packets are decrypted and delivered out of the virtual interface to inspect, monitor, or forward.
Maintenance and Support
Nubeva complements its software products with white-glove support and maintenance. As Nubeva continues to innovate and ciphers suites evolve, those implementing Nubeva’s SKI architecture, or components thereof, will receive ongoing support. Our support package will include Key Extraction Signature updates, software updates, bug fixes, documentation, and consultative support focused on rapid implementation, innovation, knowledge transfer, and continuous delivery of solutions utilizing Nubeva technology.