TRANSFERRING A PRIVATE SESSION KEY PROVIDED BY AN ENCRYPTION SERVICE TO A NETWORK TRANSMISSION UNIT FOR SECURE TRANSMISSIONS
By establishing a secure transmission tunnel and using a network transmission unit for encryption and decryption with a private session key, the method addresses the challenges of resource-intensive encryption and key exposure in existing data encryption technologies, enhancing both security and performance.
Patent Information
- Application Number
- DE112023003385
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-08-08
- Filing Date
- 2023-07-13
- Publication Date
- 2025-05-22
AI Technical Summary
Existing data encryption methods in transmission sessions require significant computational resources and risk exposing private session keys, which can lead to unauthorized access.
A method that establishes a secure transmission tunnel between user space software and a client device, accesses a private session key from an encryption service, and transmits this key to a network transmission unit for encryption and decryption operations, thereby reducing the computational burden on the host system and minimizing exposure of the private key.
This approach enhances data security in transmission sessions by reducing the computational resources needed for encryption and decryption, while also minimizing the risk of private session key exposure, thus improving overall security and performance.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
BACKGROUND
[0001] The present invention relates to data encryption and, in particular, to data encryption in a transmission session.
[0002] Data encryption is used to secure data by encoding it so that it is unintelligible until it is decoded. Data encryption is often applied to data transmitted over the Internet. Internet Key Exchange (IKE) is a security protocol generally implemented for secure Internet transmissions. IKE uses a session key to encrypt and decrypt data. A session key is a one-time, symmetric encryption key used to encrypt / decrypt messages in a transmission session. In this context, a session key is a temporary key that is typically used only for a specific transmission session. Other transmission sessions have their own session keys. SUMMARY
[0003] A method comprises establishing a secure transmission tunnel between user space software and a client device. The method may also include accessing a private session key from an encryption service. The method may also include transmitting the private session key from the user space software to a network transmission device. The method may also include transmitting outgoing session packets from the user space software to the network transmission device.The network transmission unit may be programmed to initiate operations including: generating, by the network transmission unit, encrypted outgoing session packets by encrypting the outgoing session packets using the private session key; transmitting, by the network transmission unit to the client unit via the secured transmission tunnel, the encrypted outgoing session packets; receiving, by the network transmission unit from the client unit via the secured transmission tunnel, incoming session packets; generating, by the network transmission unit, decrypted incoming session packets by decrypting the incoming session packets using the private session key; and transmitting, from the network transmission unit to the user space software, the decrypted incoming session packets.
[0004] A system includes a processor programmed to initiate executable operations. The executable operations include establishing a secure transmission tunnel between user-space software and a client device. The executable operations may also include accessing a private session key from an encryption service. The executable operations may also include transmitting the private session key from the user-space software to a network transmission device. The executable operations may also include transmitting outgoing session packets from the user-space software to the network transmission device.The network transmission unit may be programmed to initiate executable operations including: generating, by the network transmission unit, encrypted outgoing session packets by encrypting the outgoing session packets using the private session key; transmitting, by the network transmission unit to the client unit via the secured transmission tunnel, the encrypted outgoing session packets; receiving, by the network transmission unit from the client unit via the secured transmission tunnel, incoming session packets; generating, by the network transmission unit, decrypted incoming session packets by decrypting the incoming session packets using the private session key; and transmitting, from the network transmission unit to the user space software, the decrypted incoming session packets.
[0005] A computer program comprises a computer-readable storage medium having program code stored thereon. The program code is executable by a data processing system to perform operations. The operations include establishing a secure transmission tunnel between user-space software and a client device. The operations may also include accessing a private session key from an encryption service. The operations may also include transmitting the private session key from the user-space software to a network transmission device. The operations may also include transmitting outgoing session packets from the user-space software to the network transmission device.The network transmission unit may be programmed to initiate operations including: generating, by the network transmission unit, encrypted outgoing session packets by encrypting the outgoing session packets using the private session key; transmitting, by the network transmission unit to the client unit via the secured transmission tunnel, the encrypted outgoing session packets; receiving, by the network transmission unit from the client unit via the secured transmission tunnel, incoming session packets; generating, by the network transmission unit, decrypted incoming session packets by decrypting the incoming session packets using the private session key; and transmitting, from the network transmission unit to the user space software, the decrypted incoming session packets.
[0006] This "Summary" section is provided merely to introduce certain concepts and not to identify important or essential features of the claimed subject matter. Additional features of the inventive arrangements will become apparent from the accompanying drawings and the following detailed description. BRIEF DESCRIPTION OF THE DRAWINGS Fig. 1 illustrates a cloud computing environment according to an embodiment of the present invention. Fig. 2 illustrates abstraction model layers according to an embodiment of the present invention. Fig. Figure 3 is a block diagram illustrating an example architecture for a data processing system. Fig. 4 is a flowchart illustrating an example of performing encryption initialization in a user space transmission session. Fig. Figure 5 is a flowchart illustrating an example of accessing a private session key. Fig. 6 is a flowchart illustrating another example of performing encryption initialization in a user space transmission session. Fig. 7 is a flowchart illustrating a method for performing encryption initialization in a user space transmission session. DETAILED DESCRIPTION
[0007] This disclosure relates to data encryption and, more particularly, to data encryption in a transmission session.
[0008] The arrangements described herein are directed to and provide an enhancement of computer technology. In particular, the present arrangements improve data security in transmission sessions while reducing resource utilization to implement data security at the functional abstraction layers of management and virtualization provided by cloud computing environments.
[0009] According to the arrangements described herein, an application programming interface private session key for a secure data transfer session can be generated in user space of a host computing system. The private session key can then be stored on a network transfer device, and the network transfer device can implement data encryption and decryption for the transfer session. Consequently, the host hypervisor stack and the virtual machine operating system space do not need to generate or store the private session key, and they do not need to allocate valuable computing resources to implement data encryption / decryption for the transfer session.This allows processor and memory resources on the host computing system, which would otherwise be used to perform data encryption / decryption for the transfer session, to be freed for use for other tasks. Furthermore, because the private session key is stored on the network transfer unit rather than in the host hypervisor stack or the virtual machine's operating system space, the risk of the private session key being discovered by an unscrupulous party gaining unauthorized access to the host computing system is mitigated.
[0010] Several definitions that apply throughout this document are now presented.
[0011] As defined herein, the term "user space" means computing system main memory (e.g., local main memory and / or cache) that is separate from kernel space and allocated to running applications hosted for access by client devices. User space may, for example, be a portion of virtual memory that is separate from the virtual memory allocated as kernel space.
[0012] As defined herein, the term "kernel space" means computing system main memory (e.g., local memory and / or cache) associated with running kernel applications, and may also include computing system main memory associated with running hypervisor applications.
[0013] As defined herein, the term “public key” means an encryption key sent from a first system or entity to a second system or entity and used for secure data transmissions, where encrypted messages can only be decrypted by the second system or entity using the public key, for example, by using the public key to generate a private session key used to decrypt the encrypted messages.
[0014] As defined herein, the term “private session key” means an encryption key known only to a particular system or entity and used by that system or entity to decrypt encrypted messages transmitted to that system or entity.
[0015] As defined herein, the term “session packet” means a unit of data aggregated into a single packet traveling along a network path.
[0016] As defined herein, the term “encrypted session packet” means a session packet that is encrypted using an encryption key, for example, using a private session key.
[0017] As defined herein, the term “secure transmission tunnel” means an encrypted transmission connection between a first system or entity and a second system or entity.
[0018] As defined herein, the term “n-tuple” means a finite, ordered list of elements, where n is a non-negative integer.
[0019] As defined herein, the term “network transmission unit” means a network adapter or a switch.
[0020] As defined herein, the term "network adapter" means a hardware device that connects a data processing system to a data transmission network. Although data processing systems and network infrastructure may include one or more network adapters, data processing systems (e.g., servers and client devices) are not network adapters as defined herein, and network infrastructure (e.g., routers, firewalls, switches, access points, and the like) are not network adapters as defined herein.
[0021] As defined herein, the term “switch” means a hardware unit in a network infrastructure that connects units in a data transmission network, using packet switching to receive data and forward data to a destination unit.
[0022] As defined herein, the term "computer-readable storage medium" means a storage medium that contains or stores program code for use by or in connection with an instruction execution system, apparatus, or device. As defined herein, a "computer-readable storage medium" is not a transient, propagating signal per se.
[0023] As defined herein, the term "data processing system" means one or more hardware systems configured to process data, each hardware system including at least one processor programmed to initiate executable operations and main memory. A network adapter, by itself, is not a data processing system as defined herein. Network infrastructure such as routers, firewalls, switches, access points, and the like are not data processing systems as defined herein.
[0024] As defined herein, the term "processor" means at least one hardware circuit (e.g., an integrated circuit) configured to execute instructions contained in program code. Examples of a processor include, but are not limited to, a central processing unit (CPU), an array processor, a vector processor, a digital signal processor (DSP), a field programmable gate array (FPGA), a programmable logic array (PLA), an application-specific integrated circuit (ASIC), programmable logic circuits, and a controller.
[0025] As defined herein, the term “server” means a computing system configured to share services with one or more other computing systems.
[0026] As defined herein, the term "client device" means a computing system that requests shared services from a server and with which a user interacts. Examples of a client device include, but are not limited to, a workstation, desktop computer, computer terminal, mobile computer, laptop computer, netbook computer, tablet computer, smartphone, personal digital assistant, smartwatch, smart glasses, game console, set-top box, smart TV, and the like. A network adapter, by itself, is not a client device as defined herein. Network infrastructure such as routers, firewalls, switches, access points, and the like are not client devices as defined herein.
[0027] As defined herein, the term "real time" means a level of processing response that a user or system perceives as sufficiently fast for a particular process or determination to be made, or that enables the processor to keep pace with an external process.
[0028] As defined herein, the term "in response to" means promptly responding or reacting to an action or event. Thus, if a second action is performed "in response to" a first action, there is a causal relationship between an occurrence of the first action and an occurrence of the second action, and the term "in response to" indicates such a causal relationship.
[0029] As defined herein, the term “automatic” means without user intervention.
[0030] As defined herein, the term “User” means a person (i.e., a human being).
[0031] It should be understood at the outset that, although this disclosure includes a detailed description of cloud computing, the implementation of the teachings herein is not limited to a cloud computing environment. Rather, embodiments of the present invention may be implemented in conjunction with any other type of computing environment now known or later invented.
[0032] Cloud computing is a service delivery model for enabling seamless, on-demand network access to a shared pool of configurable computing resources (e.g., networks, network bandwidth, servers, processing, memory, storage, applications, virtual machines, and services) that can be rapidly provisioned and released with minimal management effort or interaction with a service provider. This cloud model can include at least five characteristics, at least three service models, and at least four implementation models.
[0033] The properties are as follows: On-demand self-service: A cloud user can unilaterally and automatically provide data processing functions such as server time and network storage as needed, without the need for human interaction with the service provider. Broad Network Access: Functions are available over a network and accessed through standard mechanisms that support use by heterogeneous thin or thick client platforms (e.g., mobile phones, laptops, and PDAs). Resource pooling: The provider's computing resources are pooled to serve multiple users using a multi-tenant model, with various physical and virtual resources dynamically allocated and reassigned as needed. There is a perceived location independence, as the user generally has no control or knowledge over the exact location of the provided resources, but may be able to specify a location at a higher level of abstraction (e.g., country, state, or data center). Rapid Elasticity: Features can be provisioned quickly and elastically for rapid scale-out, in some cases automatically, and released quickly for rapid scale-in. To the user, the features available for deployment often appear unlimited, and they can be purchased at any time in any quantity. Measured Service: Cloud systems automatically control and optimize resource usage by leveraging a measurement function at a certain level of abstraction appropriate for the type of service (e.g., storage, processing, bandwidth, and active user accounts). Resource usage can be monitored, controlled, and reported, providing transparency for both the provider and the user of the service.
[0034] The service models are as follows: Software as a Service (SaaS): The functionality provided to the user is to use the provider's applications running on a cloud infrastructure. The applications are accessible from various client devices via a thin client interface such as a web browser (e.g., web-based email). The user does not manage or control the underlying cloud infrastructure, including the network, servers, operating systems, storage, or even individual application features, with the possible exception of limited user-specific application configuration settings. Platform as a Service (PaaS): The functionality provided to the user is to deploy applications created or obtained by the user, using programming languages and tools supported by the provider, on the cloud infrastructure. The user does not manage or control the underlying cloud infrastructure, including networks, servers, operating systems, or storage, but has control over the deployed applications and possibly over configurations of the application hosting environment. Infrastructure as a Service (IaaS): The functionality provided to the user consists of providing processing, storage, networking, and other basic computing resources, allowing the user to deploy and run any software, including operating systems and applications. The user does not manage or control the underlying cloud infrastructure, but has control over operating systems, storage, deployed applications, and possibly limited control over selected network components (e.g., host firewalls).
[0035] The deployment models are as follows: Private Cloud: The cloud infrastructure is operated solely for an organization. It can be managed by the organization or a third party and can be located on its own premises or on third-party premises. Community Cloud: The cloud infrastructure is shared by multiple organizations and supports a specific user community with common concerns (e.g., mission, security requirements, policies, and compliance considerations). It can be managed by the organizations or a third party and can be located on-premises or on shared premises. Public Cloud: The cloud infrastructure is made available to the general public or a large industry group and is owned by an organization that sells cloud services. Hybrid Cloud: Cloud infrastructure is a composition of two or more clouds (private, community, or public) that remain separate entities but are interconnected by a standardized or proprietary technology that enables data and application portability (e.g., cloud target distribution for load balancing between clouds). A cloud computing environment is service-oriented with a focus on statelessness, low coupling, modularity, and semantic interoperability. At the heart of cloud computing lies an infrastructure comprising a network of interconnected nodes.
[0036] With reference to Fig. 1, an illustrative cloud computing environment 50 is shown. As shown, the cloud computing environment 50 includes one or more cloud computing nodes 10 with which local computing devices used by cloud users, such as a personal digital assistant (PDA) or mobile phone 54A, a desktop computer 54B, a laptop computer 54C, and / or an automotive computer system 54N, can communicate. The nodes 10 can communicate with each other. They can be physically or virtually grouped into one or more networks such as private, community, public, or hybrid clouds (not shown), as described above, or a combination thereof. This enables the cloud computing environment 50 to offer infrastructure, platforms, and / or software as services for which a cloud user does not need to maintain resources on a local computing device.It should be noted that the types of . Fig. 1 are intended to be illustrative only, and that the computing nodes 10 and the cloud computing environment 50 may communicate with any type of computerized device via any type of network and / or via any type of network-accessible connection (e.g., using a web browser).
[0037] With reference to Fig. 2 shows a set of functional abstraction layers implemented by the cloud computing environment 50 ( Fig. 1) are provided. It should be clear from the outset that the Fig. The components, layers, and functions shown in Figure 2 are intended to be illustrative only, and embodiments of the invention are not limited thereto. As shown, the following layers and corresponding functions are provided:
[0038] A hardware and software layer 60 includes hardware and software components. Examples of hardware components include: mainframe computers 61; Reduced Instruction Set Computer (RISC) architecture-based servers 62; servers 63; blade servers 64; storage devices 65; and networks and network components 66. The network components 66 may include, for example, network adapters, switches, routers, etc. In some embodiments, software components include network application server software 67 and database software 68.
[0039] A virtualization layer 70 provides an abstraction layer from which the following examples of virtual entities are provided in one or more embodiments: virtual servers 71; virtual storage 72; virtual networks 73, including virtual private networks; virtual applications and operating systems 74; and virtual clients 75.
[0040] In one example, a management layer 80 may provide the functions described below. Resource provisioning 81 provides for the dynamic procurement of computing resources and other resources used to perform tasks within the cloud computing environment. Metering and pricing 82 provides cost tracking of using resources within the cloud computing environment, as well as billing or invoicing for the consumption of those resources. In one example, these resources may include application software licenses. Security provides identity verification for cloud users and tasks, as well as protection for data and other resources. A user portal 83 provides users and system administrators with access to the cloud computing environment.Service level management 84 provides for the allocation and management of cloud computing resources so that the required service objectives are met. Service level agreement (SLA) planning and fulfillment 85 provides for the pre-arranging and procurement of cloud computing resources for which future requirements are anticipated, in accordance with an SLA.
[0041] A workload layer 90 provides examples of the functionality for which the cloud computing environment can be used. Examples of workloads and functions that can be provided by this layer include: mapping and navigation 91; software development and lifecycle management 92; virtual classroom education delivery 93; data analytics processing 94; transaction processing 95; and initialization 96 of encryption in a user-space broadcast session.
[0042] The initialization 96 of encryption in a user-space transmission session can be used to generate private session keys for data transmission sessions and store the private session keys on network adapters in the hardware and software layer 60. The network adapters can perform data encryption and decryption for transmission sessions using the private session keys. Consequently, computing resources provided by the virtualization layer 70 and the management layer 80 are relieved of the task of performing such encryption and decryption.
[0043] Fig. 3 depicts a block diagram illustrating an example architecture for a data processing system 300 that may be implemented in the hardware and software layer 60 of the cloud computing environment 50. The data processing system 300 may include at least one processor 305 (e.g., a central processing unit) connected to main memory elements 310 by a system bus 315 or other suitable circuitry. Thus, the data processing system 300 may store program code in the main memory elements 310. The processor 305 may execute the program code accessed by the memory elements 310 via the system bus 315. It should be understood that the data processing system 300 may be implemented as any system including a processor and main memory capable of performing the functions and / or operations disclosed in this description.For example, the data processing system 300 may be implemented as a server, a plurality of communicatively connected servers, a workstation, a desktop computer, a mobile computer, a tablet computer, a laptop computer, a netbook computer, a smartphone, a personal digital assistant, a set-top box, a game console, a network appliance, and so on.
[0044] The main memory elements 310 may include one or more physical main memory devices, such as a local main memory 320 and one or more mass storage devices 325. The local main memory 320 refers to random access memory (RAM) or other non-persistent main memory device(s) generally used during actual execution of the program code. The mass storage device(s) 325 may be implemented as a hard disk drive (HDD), solid state drive (SSD), or other persistent data storage device. The data processing system 300 may also include one or more caches (330) that provide temporary storage of at least a portion of program code to reduce the frequency with which program code must be retrieved from the local main memory 320 and / or the mass storage device 325 during execution.
[0045] Input / output (I / O) devices 340, such as a display, a pointing device, a keyboard, etc., may be connected to the data processing system 300. The I / O devices 340 may be connected to the data processing system 300 either directly or through intermediate I / O interfaces 345. One or more network adapters 350 may also be connected to the data processing system 300 to enable the data processing system 300 to be connected to other systems, computer systems, remote printers, and / or remote storage devices through intermediate private or public networks. Modems, cable modems, transceivers, and Ethernet cards are examples of various types of network adapters 350 that may be used with the data processing system 300.A network adapter 350 may be located within the data processing system 300 or external to the data processing system 300 and may be communicatively connected to the data processing system 300 via a suitable I / O device 340.
[0046] As in Fig. 3, the main memory elements 310 may store the components of the system, namely one or more programs / utilities 355, each of which may include one or more program modules 360. The program / utilities 355 may include, for example, an application that performs encryption initialization 96 in a user-space communication session. Implemented in the form of executable program code, the programs / utilities 355 may be executed by the data processing system 300 and thus considered part of the data processing system 300. Furthermore, the programs / utilities 355 include functional data structures that, when utilized as part of the data processing system 300, provide functionality.As defined in this disclosure, a "data structure" is a physical implementation of the organization of data of a data model within a physical main memory. Thus, a data structure is formed from specific electrical or magnetic structural elements in a main memory. A data structure imposes a physical organization on the data stored in main memory, as used by an application program executing using a processor.
[0047] Fig. 4 depicts a flowchart 400 illustrating an example of performing an initialization 96 of encryption in a user space transmission session. The initialization 96 of encryption in a user space transmission session may be performed by the data processing system 300 of Fig. 3, for example, may be implemented in accordance with Internet Protocol Security (IPSec). The data processing system 300 may be configured to provide Platform-as-a-Service (PaaS) and / or Software-as-a-Service (SaaS) user space software to client devices, including a client device 402. In this context, the data processing system 300 may allocate a portion of the main memory elements 310 for user space, for example, to store PaaS and / or SaaS user space software 404. The PaaS and / or SaaS user space software 404 may be assigned to the virtual machine (VM) hosted by the computing system 300, but stored and executed in user space main memory, which may be separated from main memory assigned to a host hypervisor stack 406, main memory assigned to an operating system space 408 of an Infrastructure-as-a-Service (IaaS) VM, and main memory assigned to the operating system space (e.g.,the kernel space) of the data processing system 300. The PaaS and / or SaaS user space software 404 may be managed, for example, using a container.
[0048] An application programming interface (API) 407 may also be provided by the computing system 300. In one illustration, when the PaaS and / or SaaS user-space software 404 is hosted in a VM, the API 407 may be a function provided by an I / O virtualization framework for use by the PaaS and / or SaaS user-space software 404 to access the network adapter 350. The hypervisor may emulate the network adapter 350 and provide the API 407 in the VM to be used for communication between the PaaS and / or SaaS user-space software 404 and the network adapter 350. By way of example, Virtio is an I / O virtualization framework provided for use with the Kernel-based Virtual Machine (KVM) virtualization module for the Linux operating system.Virtio may emulate the network adapter 350 and provide the API 407 for communication between the PaaS and / or SaaS user space software 404 and the network adapter 350.
[0049] As mentioned, the data processing system 300 may include a network adapter 350 ( Fig. 3). The network adapter 350 may be an intelligent network adapter and may include a network adapter software stack 410. In one illustration, the network adapter 350 may be an intelligent network interface card (SmartNIC) that supports software-defined networking (SDN). A SmartNIC is a network adapter that offloads processing tasks that the processor 305 of the data processing system 300 would normally perform, such as performing encryption / decryption, performing firewall operations, and implementing transmission processing.The transmission processing may be Transmission Control Protocol / Internet Protocol (TCP / IP) transmission processing, Hypertext Transfer Protocol (HTTP) transmission processing, Datagram Transport Layer Security (DTLS) transmission processing, and / or Quick UDP Internet Connection Protocol (QUIC) transmission processing. A network adapter 350 may be located within the data processing system 300 or external to the data processing system 300 and communicatively coupled to the data processing system 300 via a suitable I / O device 340.
[0050] The network adapter 350 may also include an encryption engine 412 configured to encrypt and decrypt data packets, as will be described. The network adapter 350 may also include a transmission interface (not shown), for example, a PCI Express interface or other suitable interface, configured to communicate with the data processing system 300. The network adapter 350 may also include a transmission interface (not shown) configured to communicate over one or more transmission networks. For example, the network adapter 350 may include an Ethernet port or a wireless port (e.g., Wi-Fi).
[0051] In operation, the data processing system 300 may execute a program / utility 355 ( Fig. 3) hosted in the PaaS and / or SaaS user space software 404 and performing encryption initialization 96 in a user space transmission session in the user space. The data processing system 300 may receive a session request 420 from the client device 402 via one or more transmission networks 422 (e.g., via the Internet), requesting access to the PaaS and / or SaaS user space software 404, for example, to access one or more applications / services, via a transmission session. In response to the session request 420, the program / utility 355 may determine in real time one or more port identifiers (port IDs) 424 for one or more ports 426 provided by the IaaS VM operating system space 408 to be used by the PaaS and / or SaaS user space software 404 for the broadcast session.For example, one or more of the ports 426 may be User Datagram Protocol / Internet Protocol (UDP / IP) ports. In one or more arrangements, the program / utility 355 may request the port IDs 424 from the PaaS VM operating system space 408, which may assign these port IDs 424 to the transmission session, but the present arrangements are not limited in this regard. For example, the port IDs 424 may be preassigned to the PaaS and / or SaaS user space software 404 and known to the program / utility 355. In one illustration, a first port ID 424 may indicate a first port 426 (e.g., outgoing port) to which the PaaS and / or SaaS user space software 404 is to transmit UDP datagrams to the network adapter 350, and a second port ID 424 may indicate a second port 426 (e.g.,incoming port) on which the PaaS and / or SaaS user space software 404 listens for UDP datagrams generated by the network adapter 350. In another example, a first port ID 424 may indicate a first port 426 (e.g., outgoing port) to which the PaaS and / or SaaS user space software 404 is to communicate with the network adapter 350 via an API 407, and a second port ID 424 may indicate a second port 426 (e.g., incoming port) on which the PaaS and / or SaaS user space software 404 listens for data transmitted from the network adapter 350 to the PaaS and / or SaaS user space software 404 via the API 407.
[0052] In response to establishing the port ID 424, the program / utility 355 operating within the PaaS and / or SaaS user space software 404 may generate a public key in real time at step 428 and perform a real-time public key exchange 430 with the client device 402. In one or more arrangements, the public key exchange 430 may be performed in accordance with Phase 1 of the Internet Key Exchange (IKE) protocol, for example, IKE or IKE2.
[0053] In one illustration, the public key exchange 430 may be performed using the main mode of IKE Phase 1 using a plurality of exchange operations between the PaaS and / or SaaS user space software 404 (e.g., the program / utility 355) and the client device 402 to agree on a secured association (SA). In particular, Phase 1 may include an agreement of an SA. The main mode of IKE Phase 1 may include: an initial exchange between the PaaS and / or SaaS user space software 404 (e.g., the program / utility 355) and the client device 402 of at least one algorithm and at least one hash to be used to secure transmissions; a Diffie-Hellman public key exchange between the PaaS and / or SaaS user space software 404 (e.g.,the program / utility 355) and the client device 402 to generate shared secret key material used to generate at least one shared secret key, and passing nonces (e.g., random numbers) from the PaaS and / or SaaS user space software 404 to the client device 402, which are signed and returned by the client device 402 to verify user identity; and device identity authentication, for example, by the PaaS and / or SaaS user space software 404 and the client device 402 exchanging IP addresses to be used for the transmission session in encrypted form (e.g., by encrypting the IP addresses using the generated shared secret keys).The PaaS and / or SaaS user space software 404 and the client device 402 may each generate respective public keys to be exchanged during the Diffie-Hellman public key exchange using their respective private keys, the algorithm, and the hash determined during the initial exchange.
[0054] The public key exchange 430 may also be performed using the aggressive mode of IKE Phase 1. The aggressive mode of IKE Phase 1 may include the exchange of information explained above for the main mode, but the information may be exchanged using fewer exchange operations. For example, the PaaS and / or SaaS user-space software 404 (e.g., the program / utility 355) may transmit a message including the algorithm, the hash, a Diffie-Hellman public key, a nonce, and an identity packet to the client device 402. The client device 402 may respond with a message completing the exchange, and the PaaS and / or SaaS user-space software 404 (e.g., the program / utility 355) may confirm the exchange.
[0055] Regardless of whether the main mode or the aggressive mode of IKE Phase 1 is used for the public key exchange, the public keys are neither known to nor discovered by the host hypervisor stack 406, the IaaS VM operating system space 408, nor the operating system of the computing system 300. This improves security by reducing the risk of an unscrupulous party obtaining the public keys from the host hypervisor stack 406 or the IaaS VM operating system space 408, which could otherwise be used to decrypt data exchanged during the secure transmission tunnel configuration. Completion of the public key exchange 430 may result in the establishment of a secure transmission tunnel (e.g., an IPSec tunnel) between the PaaS and / or SaaS user space software 404 and the client device 402.
[0056] In the above examples, the program / utility 355 may be operated within the PaaS and / or SaaS user space software 404 to initiate the setup and configuration of a secure tunnel according to IKE. At the same time, the program / utility 355 may implement any other suitable key exchange protocol, and the present arrangements are not limited in this regard.
[0057] In step 432, the program / utility 355 may access a private session key from an encryption service in real time. The encryption service may also provide a hardware security module (HSM) that provides the ability to use a private session key for cloud data encryption. An example of a suitable encryption service is IBM ® Cloud ®Hyper Protect Crypto Services (HPCS), available from International Business Machines of Armonk, NY. In one or more arrangements, the program / utility 355 may use an API other than API 407 to initiate the encryption service, to generate and / or otherwise provide the private session key, for example, using the PKCS #11 API or the GREP11 API, both of which are available from the GitHub repository.
[0058] Fig. 5 depicts a flowchart 500 illustrating an example of accessing a private session key, for example, from an encryption service. The flowchart may be implemented at step 432. At step 502, an API 510 (e.g., the PKCS #11 API or the GREP11 API) may generate an API key to be used to access an encryption service instance from the encryption service 512. At step 520, the PaaS and / or SaaS user space software 404 (e.g., the program / utility 355) may access the API key from the API 510.
[0059] In step 522, the PaaS and / or SaaS user space software 404 (e.g., the program / utility 355) may generate a configuration file that provides a virtual private cloud (VPC) instance with the encryption service 512, enables a private endpoint for the VPC instance, and creates an encryption service endpoint gateway. The configuration file may include the API key, an instance identifier for an encryption service instance, a uniform resource locator (URL) of the VPC instance's endpoint address, and a port number of the VPC instance's endpoint address.
[0060] In step 524, the PaaS and / or SaaS user space software 404 (e.g., the program / utility 355) may initiate a request for a private session key, for example, by passing the configuration file to the API 510. In response, the API 510 may set up a secure VPC instance with the encryption service 512 and request a private session key in step 526. In response to the request, the encryption service 512 may transmit the private session key to the API 510 in the VPC instance in step 528. In response to receiving the private session key, the API 510 may pass the private session key to the PaaS and / or SaaS user space software 404 in step 530.
[0061] Again with reference to Fig. 4, the program / utility 355 may initiate operations in real time to implement a tunnel configuration 434 using the private session key accessed by the encryption service 512. In this context, it should be noted that step 432 may be performed at any time before step 434, for example, before or in parallel with receiving the port identifier 424, before or in parallel with exchanging the public key 430, etc.
[0062] In one or more arrangements, tunnel configuration 434 may be performed according to Phase 2 of the IKE protocol. In one illustration, PaaS and / or SaaS user space software 404 (e.g., program / utility 355) and client device 402 may exchange data over the tunnel using the agreed-upon SA to agree on a shared IPSec policy, shared secret key material used for an IPSec security algorithm, and to establish IPSec SAs. Further, program / utility 355 and client device 402 may exchange nonces that provide replay protection, which are used to generate new secret key material and prevent replay attacks by generating rogue SAs. In response to establishing the secure tunnel, program / utility 355 may halt the transmission session in step 436.
[0063] In response to the transmission session being halted at step 436, the program / utility 355 may transmit an n-tuple (e.g., a TCP / IP twin-tuple or a TCP / IP quintuple) and the private session key to the network adapter 350 in real time at step 438. In one illustration, the program / utility 355 may transmit the configuration file including the private session key to the network adapter 350. In one or more arrangements, the program / utility 355 may transmit the n-tuple and the private session key to the network adapter 350 over the port 426 (e.g., the first port) indicated by the port ID 424 in at least one User Datagram Protocol (UDP) datagram.In one or more arrangements, when the PaaS and / or SaaS user space software 404 is hosted in a VM, the program / utility 355 may transmit the n-tuple and the private session key to the network adapter 350 via the API 407.
[0064] The n-tuple may include data indicating a source IP address and a destination IP address. Optionally, the n-tuple may further include data indicating a source port, a destination port, and / or a transmission protocol. The source IP address may be the IP address assigned to the PaaS and / or SaaS user space software 404. The destination IP address may be an IP address assigned to the client device 402. The source port may be an outgoing port 426 (e.g., the first port 426), indicated by the port ID 424, to be used by the PaaS and / or SaaS user space software 404 (e.g., via the API 407 in one or more arrangements) for exchanging session packets 446 with the client device 402. The target port may be a port of the client device 402 through which the PaaS and / or SaaS user space software 404 may communicate with the client device 402 using the secure tunnel.The transfer protocol may be the transfer protocol (e.g., TCP / IP, DTLS, and / or QUIC) used for transfers between the PaaS and / or SaaS user space software 404 and the client device 402. Optionally, the n-tuple may also include a unidirectional session identifier (ID) (e.g., a Security Parameter Index for IPsec) for the transfer session. The PaaS and / or SaaS user space software 404 (e.g., the program / utility 355) may transmit another UDP datagram specifying the session ID to the network adapter 350 in real time. The PaaS and / or SaaS user space software 404 (e.g., the program / utility 355) may transmit the session ID to the network adapter 350 in real time via the API 407.
[0065] In step 440, the network adapter 350 may store the n-tuple associated with the private session key in real time in the network adapter software stack 410. For example, the network adapter 350 may generate and store data associating the n-tuple with the private session key. In response to storing the n-tuple and the private session key, the network adapter 350 may transmit a completion status message 442 to the PaaS and / or SaaS user space software 404 (e.g., the program / utility 355) in real time, indicating that the network adapter 350 has completed receiving and storing the n-tuple and the private session key. In one or more arrangements, the completion status message may be transmitted as a UDP datagram over a port 426 (e.g., the second port 426) on which the PaaS and / or SaaS user space software 404 is listening.In one or more further arrangements, the completion status message may be transmitted to the PaaS and / or SaaS user space software 404 via the network adapter 350 and the API 407.
[0066] Because the n-tuple and private session key are transmitted in one or more UDP datagrams or via the API from the PaaS and / or SaaS user-space software 404 to the network adapter 350 and are stored by the network adapter 350 rather than the processor 305, the n-tuple and private session key are neither known nor discovered by the host hypervisor stack 406, the IaaS VM operating system space 408, nor the operating system of the computing system 300. Again, this improves security by reducing the risk of an unscrupulous party obtaining the n-tuple and private session key from the host hypervisor stack 406 or the IaaS VM operating system space 408, which could otherwise be used to decrypt session packets exchanged during the transmission session.
[0067] In response to receiving the completion status message 442, the PaaS and / or SaaS user space software 404 (e.g., the program / utility 355 hosted in the PaaS and / or SaaS user space software 404) may, in step 444, restart the communication session with the client device 402, including the exchange of session packets 446, in real time.
[0068] For outgoing session packets, the PaaS and / or SaaS user space software 404 may transmit the session packets 446 to the network adapter 350 via a port 426 (e.g., the first port 426). In one or more arrangements, the PaaS and / or SaaS user space software 404 may transmit the session packets 446 to the API 407, and the API may transmit the session packets 446 to the network adapter 350 via the port 426. The network adapter 350 may invoke the network adapter encryption engine 412 to encrypt the outgoing session packets 446 as encrypted session packets 448 using the private session key, and transmit encrypted session packets 448 to the client device 402, for example, using TCP / IP, DTLS, and / or QUIC.In one illustration, the network adapter 350 may encrypt the session packets 448 using the private session key according to the Advanced Encryption Standard (AES) and transmit encrypted session packets 448 in real time using the transmission protocol specified by the n-tuple via the secure transmission tunnel to the destination IP address specified by the n-tuple.
[0069] The network adapter 350 may also receive incoming encrypted session packets 448 from the client device 402 via the secure transmission tunnel, for example, via TCP / IP, DTLS, and / or QUIC. The network adapter 350 may invoke the network adapter encryption engine 412 in real time to decrypt the incoming session packets 448 using the private session key, for example, according to AES. The network adapter 350 may specify the private session key by specifying the IP address from which the incoming encrypted session packets 448 are received, specifying the n-tuple comprising that IP address, and specifying the private session key associated with that n-tuple. The network adapter 350 may transmit the decrypted session packets 446 via the port 426 as session packets 446 in real time to the PaaS and / or SaaS user space software 404. In one or more arrangements, the API 407 may be connected to the port 426 (e.g.,the second port 426) listen for the session packets 446 and transmit the session packets 446 to the PaaS and / or SaaS user room software 404.
[0070] It should be noted that by performing encryption / decryption by the network adapter encryption engine 412, the amount of operations performed by the processor 305 is reduced compared to performing encryption / decryption by the processor 305 (e.g., using the host hypervisor stack and / or the IaaS VM operating system space 408). This improves the performance of the processor as well as the performance of the computing system 300.
[0071] From time to time, the PaaS and / or SaaS user space software 404 (e.g., the program / utility 355) may determine that the private session key should be changed. To do so, the PaaS and / or SaaS user space software 404 may return to step 428 and generate a new public key and repeat the operations described in steps 430 through 444. The PaaS and / or SaaS user space software 404 may determine that the private session key be changed at regular intervals (e.g., every hour, every six hours, every day, etc.) or in response to detecting an event, such as the transmission session resuming after a period of inactivity in the transmission session that exceeds a threshold.
[0072] Fig. 6 depicts a flowchart 600 illustrating another example of performing encryption initialization 96 in a user-space transmission session. In this example, a switch 610 may be used to perform encryption / decryption of the session packets 446. The switch 610 may be a component of the transmission network(s) 422 to which the computing system 300 communicates via the network adapter 350. For example, the switch 610 may be a component of a local area network (LAN) or a wide area network (WAN) to which the computing system 300 communicates via the network adapter 350. In this example, the network adapter 350 need not include the encryption engine 412 and the software stack 410, although the present example is not limited in this regard.
[0073] In one illustration, switch 610 may be a software-defined networking (SDN) switch or an intelligent switch supporting SDN, and may include a switch software stack 612. In one illustration, switch 610 may offload processing tasks that would normally be performed by processor 305 of data processing system 300, such as performing encryption / decryption, performing firewall operations, and implementing transport processing. Transport processing may include TCP / IP transport processing, HTTP transport processing, DTLS transport processing, and / or QUIC transport processing.
[0074] The switch 610 may include a switch encryption engine 614 configured to encrypt and decrypt data packets, as will be described. The switch 610 may also include transmission ports (not shown) configured to exchange data over one or more transmission networks. For example, the switch 610 may include one or more Ethernet ports and / or one or more wireless transmission ports (e.g., Wi-Fi ports).
[0075] In operation, the data processing system 300 may execute a program / utility 355 ( Fig. 3) hosted in the PaaS and / or SaaS user space software 404 and performing encryption initialization 96 in a user space transmission session in the user space. The data processing system 300 may receive a session request 420 from the client device 402 via one or more transmission networks 422 (e.g., via the Internet), requesting access to the PaaS and / or SaaS user space software 404, for example, to access one or more applications / services, via a transmission session. In response to the session request 420, the program / utility 355 may determine in real time one or more port identifiers (port IDs) 424 for one or more ports 426 provided by the PaaS VM operating system space 408 to be used by the PaaS and / or SaaS user space software 404 for the broadcast session.
[0076] For example, one or more of the ports 426 may be User Datagram Protocol / Internet Protocol (UDP / IP) ports. In one or more arrangements, the program / utility 355 may request the port IDs 424 from the PaaS VM operating system space 408, which may assign these port IDs 424 to the transmission session, but the present arrangements are not limited in this regard. For example, the port IDs 424 may be preassigned to the PaaS and / or SaaS user space software 404 and known to the program / utility 355. In one illustration, a first port ID 424 may indicate a first port 426 (e.g., outgoing port) to which the PaaS and / or SaaS user space software 404 is to transmit UDP datagrams to the switch 610, and a second port ID 424 may indicate a second port 426 (e.g.,inbound port) on which the PaaS and / or SaaS user space software 404 listens for UDP datagrams generated by the switch 610. In another example, a first port ID 424 may indicate a first port 426 (e.g., outbound port) to which the PaaS and / or SaaS user space software 404 is to communicate with the switch 610 via an API 407, and a second port ID 424 may indicate a second port 426 (e.g., inbound port) on which the PaaS and / or SaaS user space software 404 listens for data transmitted from the switch 610 to the PaaS and / or SaaS user space software 404 via the API 407.
[0077] In response to establishing the port ID 424, the program / utility 355 operating within the PaaS and / or SaaS user space software 404 may generate a public key in real time at step 428 and perform a real-time public key exchange 430 with the client device 402. In one or more arrangements, the public key exchange 430 may be performed in accordance with Phase 1 of the Internet Key Exchange (IKE) protocol, for example, IKE or IKE2.
[0078] In one illustration, the public key exchange 430 may be performed using the main mode of IKE Phase 1 using a plurality of exchange operations between the PaaS and / or SaaS user space software 404 (e.g., the program / utility 355) and the client device 402 to agree on a secured association (SA). In particular, Phase 1 may include an agreement of an SA. The main mode of IKE Phase 1 may include: an initial exchange between the PaaS and / or SaaS user space software 404 (e.g., the program / utility 355) and the client device 402 of at least one algorithm and at least one hash to be used to secure transmissions; a Diffie-Hellman public key exchange between the PaaS and / or SaaS user space software 404 (e.g.,the program / utility 355) and the client device 402 to generate shared secret key material used to generate at least one shared secret key, and passing nonces (e.g., random numbers) from the PaaS and / or SaaS user space software 404 to the client device 402, which are signed and returned by the client device 402 to verify user identity; and device identity authentication, for example, by the PaaS and / or SaaS user space software 404 and the client device 402 exchanging IP addresses to be used for the transmission session in encrypted form (e.g., by encrypting the IP addresses using the generated shared secret keys).The PaaS and / or SaaS user space software 404 and the client device 402 may each generate respective public keys to be exchanged during the Diffie-Hellman public key exchange using their respective private keys, the algorithm, and the hash determined during the initial exchange.
[0079] The public key exchange 430 may also be performed using the aggressive mode of IKE Phase 1. The aggressive mode of IKE Phase 1 may include the exchange of information explained above for the main mode, but the information may be exchanged using fewer exchange operations. For example, the PaaS and / or SaaS user-space software 404 (e.g., the program / utility 355) may transmit a message including the algorithm, the hash, a Diffie-Hellman public key, a nonce, and an identity packet to the client device 402. The client device 402 may respond with a message completing the exchange, and the PaaS and / or SaaS user-space software 404 (e.g., the program / utility 355) may confirm the exchange.
[0080] Regardless of whether the main mode or the aggressive mode of IKE Phase 1 is used for the public key exchange, the public keys are neither known to nor discovered by the host hypervisor stack 406, the IaaS VM operating system space 408, nor the operating system of the computing system 300. This improves security by reducing the risk of an unscrupulous party obtaining the public keys from the host hypervisor stack 406 or the IaaS VM operating system space 408, which could otherwise be used to decrypt data exchanged during the secure transmission tunnel configuration. Completion of the public key exchange 430 may result in the establishment of a secure transmission tunnel (e.g., an IPSec tunnel) between the PaaS and / or SaaS user space software 404 and the client device 402.
[0081] In the above examples, the program / utility 355 may be operated within the PaaS and / or SaaS user space software 404 to initiate the setup and configuration of a secure tunnel according to IKE. At the same time, the program / utility 355 may implement any other suitable key exchange protocol, and the present arrangements are not limited in this regard.
[0082] In step 432, the program / utility 355 may access a private session key from an encryption service in real time. The encryption service may also provide a hardware security module (HSM) that provides the ability to use a private session key for cloud data encryption. An example of a suitable encryption service is IBM ® Cloud ®Hyper Protect Crypto Services (HPCS), available from International Business Machines of Armonk, NY. In one or more arrangements, the program / utility 355 may use an API other than API 407 to initiate the encryption service to generate and / or otherwise provide the private session key, for example, using the PKCS #11 API or the GREP11 API, both available from the GitHub repository. In one or more arrangements, step 432 may be performed according to the flowchart 500 of Fig. 5 should be implemented.
[0083] The program / utility 355 may initiate operations in real time to implement the tunnel configuration 434 using the private session key accessed by the encryption service 512. In this context, it should be noted that step 432 may be performed at any time before step 434, for example, before or in parallel with the receipt of the port identifier 424, before or in parallel with the exchange 430 of the public key, etc.
[0084] In one or more arrangements, tunnel configuration 434 may be performed according to Phase 2 of the IKE protocol. In one illustration, PaaS and / or SaaS user space software 404 (e.g., program / utility 355) and client device 402 may exchange data over the tunnel using the agreed-upon SA to agree on a shared IPSec policy, shared secret key material used for an IPSec security algorithm, and to establish IPSec SAs. Further, program / utility 355 and client device 402 may exchange nonces that provide replay protection, which are used to generate new secret key material and prevent replay attacks by generating rogue SAs. In response to establishing the secure tunnel, program / utility 355 may halt the transmission session in step 436.
[0085] In response to the transmission session being halted in step 436, the program / utility 355 may transmit a Transmission Control Protocol / Internet Protocol n-tuple (e.g., a TCP / IP twin-tuple or a TCP / IP quintuple) and the private session key to the switch 610 in real time in step 638. In one illustration, the program / utility 355 may transmit the configuration file comprising the private session key to the switch 610. In one or more arrangements, the program / utility 355 may transmit the n-tuple and the private session key to the switch 610 over the port 426 (e.g., the first port) indicated by the port ID 424 and the network adapter 350 in at least one User Datagram Protocol (UDP) datagram.In one or more arrangements, when the PaaS and / or SaaS user space software 404 is hosted in a VM, the program / utility 355 may transmit the n-tuple and the private session key to the switch 610 via the API 407, which may transmit the n-tuple to the switch 610 via the network adapter 350.
[0086] The n-tuple may include data indicating a source IP address and a destination IP address. Optionally, the n-tuple may further include data indicating a source port, a destination port, and / or a transmission protocol. The source IP address may be the IP address assigned to the PaaS and / or SaaS user space software 404. The destination IP address may be an IP address assigned to the client device 402. The source port may be an outgoing port 426 (e.g., the first port 426), indicated by the port ID 424, to be used by the PaaS and / or SaaS user space software 404 (e.g., via the API 407 in one or more arrangements) for exchanging session packets 446 with the client device 402. The target port may be a port of the client device 402 through which the PaaS and / or SaaS user space software 404 may communicate with the client device 402 using the secure tunnel.The transmission protocol may be the transmission protocol (e.g., TCP / IP, DTLS, and / or QUIC) used for transmissions between the PaaS and / or SaaS user space software 404 and the client device 402. Optionally, the n-tuple may also include a unidirectional session identifier (ID) (e.g., a Security Parameter Index for IPsec) for the transmission session; the PaaS and / or SaaS user space software 404 (e.g., the program / utility 355) may transmit another UDP datagram specifying the session ID to the switch 610 in real time; or the PaaS and / or SaaS user space software 404 (e.g., the program / utility 355) may transmit the session ID to the switch 610 in real time via the API 407.
[0087] In step 640, the switch 610 may store the n-tuple associated with the private session key in real time in the switch software stack 612. For example, the switch 610 may generate and store data associating the n-tuple with the private session key. In response to storing the n-tuple and the private session key, the switch 610 may transmit a completion status message 642 to the PaaS and / or SaaS user space software 404 (e.g., the program / utility 355) in real time, indicating that the switch 610 has completed receiving and storing the n-tuple and the private session key. In one or more arrangements, the completion status message may be transmitted as a UDP datagram over a port 426 (e.g., the second port 426) on which the PaaS and / or SaaS user space software 404 is listening.In one or more further arrangements, the completion status message may be transmitted to the PaaS and / or SaaS user space software 404 via the network adapter 350 and the API 407.
[0088] Because the n-tuple and private session key are transmitted in one or more UDP datagrams or via the API from the PaaS and / or SaaS user space software 404 to the switch 610 and are stored by the switch 610 rather than the processor 305, the n-tuple and private session key are neither known nor discovered by the host hypervisor stack 406, the IaaS VM operating system space 408, nor the operating system of the computing system 300. Again, this improves security by reducing the risk of an unscrupulous party obtaining the n-tuple and private session key from the host hypervisor stack 406 or the IaaS VM operating system space 408, which could otherwise be used to decrypt session packets exchanged during the transmission session.
[0089] In response to receiving the completion status message 642, the PaaS and / or SaaS user space software 404 (e.g., the program / utility 355 hosted in the PaaS and / or SaaS user space software 404) may, in step 444, restart the communication session with the client device 402, including the exchange of session packets 446, in real time.
[0090] For outgoing session packets, the PaaS and / or SaaS user space software 404 may transmit the session packets 446 to the switch 610 via a port 426 (e.g., the first port). In one or more arrangements, the PaaS and / or SaaS user space software 404 may transmit the session packets 446 to the API 407, and the API may transmit the session packets 446 to the switch 610 via the port 426. The switch 610 may invoke the switch encryption engine 614 to encrypt the outgoing session packets 446 as encrypted session packets 448 using the private session key and transmit encrypted session packets 448 to the client device 402.In one illustration, the switch 610 may encrypt the session packets 448 using the private session key according to the Advanced Encryption Standard (AES) and transmit encrypted session packets 448 in real time using the transmission protocol specified by the n-tuple via the secure transmission tunnel to the destination IP address specified by the n-tuple.
[0091] The switch 610 may also receive incoming encrypted session packets 448 from the client device 402 via the secure transmission tunnel, for example, via TCP / IP, DTLS, and / or QUIC. The switch 610 may invoke the encryption engine 614 in real time to decrypt the incoming session packets 448 using the private session key, for example, according to AES. The switch 610 may specify the private session key by specifying the IP address from which the incoming encrypted session packets 448 are received, specifying the n-tuple comprising that IP address, and specifying the private session key associated with that n-tuple. The switch 610 may transmit the decrypted session packets 446 to the PaaS and / or SaaS user space software 404 as session packets 446 in real time via the network adapter 350 and the port 426 (e.g., the second port 426).In one or more arrangements, the API 407 may listen for the session packets 446 on the port 426 and transmit the session packets 446 to the PaaS and / or SaaS user space software 404.
[0092] It should be noted that by performing encryption / decryption by the switch encryption engine 614, the amount of operations performed by the processor 305 is reduced compared to performing encryption / decryption by the processor 305 (e.g., using the host hypervisor stack and / or the IaaS VM operating system space 408). This improves the performance of the processor as well as the performance of the data processing system 300.
[0093] From time to time, the PaaS and / or SaaS user space software 404 (e.g., the program / utility 355) may determine that the private session key should be changed. To do so, the PaaS and / or SaaS user space software 404 may return to step 428 and generate a new public key and repeat the operations described in steps 430 through 444. The PaaS and / or SaaS user space software 404 may determine that the private session key be changed at regular intervals (e.g., every hour, every six hours, every day, etc.) or in response to detecting an event, such as the transmission session resuming after a period of inactivity in the transmission session that exceeds a threshold.
[0094] Fig.7 depicts a flowchart illustrating a method 700 for performing encryption initialization in a user-space transmission session. In the following description, the program / utility 355 may be executed by the processor 305 of the data processing system and hosted in the PaaS and / or SaaS user-space software 404. Data storage, encryption, and decryption operations performed by the network transmission device (e.g., the network adapter 350 or the switch 610) may be performed independently of the processor 305.
[0095] In step 702, the program / utility 355 may establish a secure transmission tunnel between user space software and a client device.
[0096] In step 704, the program / utility 355 may access a private session key from an encryption service.
[0097] In step 706, the program / utility 355 may transmit the private session key from the user space software to a network transmission device.
[0098] In step 708, the program / utility 355 may transmit outgoing session packets from the user space software to the network transmission unit.
[0099] In step 710, the network transmission unit may generate encrypted outgoing session packets by encrypting the outgoing session packets using the private session key.
[0100] In step 712, the network transmission device may transmit the encrypted outgoing session packets to the client device via the secured transmission tunnel.
[0101] In step 714, the network transmission device may receive incoming session packets from the client device via the secure transmission tunnel.
[0102] In step 716, the network transmission unit may generate decrypted incoming session packets by decrypting the incoming session packets using the private session key.
[0103] In step 718, the network transmission unit may transmit the decrypted incoming session packets to the user space software.
[0104] The foregoing description is merely exemplary of embodiments of the invention, as well as variations and substitutions. While the disclosure concludes with claims defining novel features, it is believed that the various features described herein will be better understood when the description is considered in conjunction with the drawings. The process(es), machine(s), manufacture(s), and any variations thereof described in this disclosure are provided for purposes of illustration. Any specific structural and functional details described are not to be construed as limiting, but merely as a basis for the claims and as a representative basis for teaching one skilled in the art to variously utilize the features described in virtually any appropriately detailed structure.Furthermore, the terms and phrases used in this disclosure are not intended to be limiting, but rather to enable an understandable description of the features presented.
[0105] The present invention may be a system, a method, and / or a computer program product at any possible level of integration of technical details. The computer program product may comprise a computer-readable storage medium (or media) having computer-readable program instructions embodied thereon for causing a processor to carry out aspects of the present invention.
[0106] The computer-readable storage medium may be any physical device capable of retaining and storing instructions for use by an instruction-executing system. The computer-readable storage medium may be, for example, but not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination thereof. A non-exhaustive list of more specific examples of the computer-readable storage medium includes the following: a removable computer diskette, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM).Flash memory), static random access memory (SRAM), removable compact disc read-only memory (CD-ROM), digital versatile disc (DVD), memory stick, floppy disk, mechanically encoded device such as punched cards or raised structures in a groove on which instructions are stored, and any suitable combination thereof. A computer-readable storage medium, as used herein, shall not be construed as carrying transient signals per se, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide or other transmission medium (e.g., pulses of light traveling through fiber optic cables), or electrical signals carried through a wire.
[0107] Computer-readable program instructions described herein may be downloaded from a computer-readable storage medium to respective computing / processing units or to an external computer or storage device via a network such as the Internet, a local area network, a wide area network, and / or a wireless network. The network may include copper transmission cables, fiber optic transmission lines, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing unit receives computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in a computer-readable storage medium within the respective computing / processing unit.
[0108] Computer-readable program instructions for performing operations of the present invention may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state-setting data, integrated circuit configuration data, or either source code or object code written in any combination of one or more programming languages, including object-oriented programming languages such as Smalltalk, C++, or the like, and procedural programming languages such as the C programming language or similar programming languages.The computer-readable program instructions may execute entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on the remote computer or server. In the latter case, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection may be made to an external computer (for example, through the Internet using an Internet service provider).In some embodiments, electronic circuits, including, for example, programmable logic circuits, field-programmable gate arrays (FPGAs), or programmable logic arrays (PLAs), may execute the computer-readable program instructions by utilizing state information of the computer-readable program instructions to personalize the electronic circuits to perform aspects of the present invention.
[0109] Aspects of the present invention are described herein with reference to flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It should be understood that each block of the flowcharts and / or block diagrams, as well as combinations of blocks in the flowcharts and / or block diagrams, may be implemented by computer-readable program instructions.
[0110] These computer-readable program instructions may be provided to a processor of a computer or other programmable data processing device to produce a machine such that the instructions executed via the processor of the computer or other programmable data processing device produce a means for implementing the functions / steps defined in the block(s) of flowchart and / or block diagrams.These computer-readable program instructions may also be stored on a computer-readable storage medium that can direct a computer, a programmable data processing apparatus, and / or other devices to function in a particular manner, such that the computer-readable storage medium having instructions stored thereon comprises an article of manufacture, including instructions that implement aspects of the function / step specified in the block(s) of the flowchart and / or block diagrams.
[0111] The computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of process steps to be performed on the computer, other programmable device, or other device to produce a computer-executable process such that the instructions executing on the computer, other programmable device, or other device implement the functions / steps specified in the block(s) of flowchart and / or block diagrams.
[0112] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagrams may represent a module, segment, or portion of instructions comprising one or more executable instructions for performing the specified logical function(s). In some alternative implementations, the functions specified in the blocks may occur in a different order than shown in the figures.For example, two blocks shown in sequence may actually be performed as one step, executed concurrently, executed substantially concurrently, executed in a partially or entirely temporally overlapping manner, or the blocks may sometimes be executed in reverse order depending on the corresponding functionality. It is further to be understood that each block of the block diagrams and / or flowcharts, as well as combinations of blocks in the block diagrams and / or flowcharts, may be implemented by special purpose hardware-based systems that perform the specified functions or steps, or executing combinations of special purpose hardware and computer instructions. The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the invention.As used herein, the singular forms "a," "an," and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It is further understood that the terms "includes," "including," "comprises," and / or "having," when used in this disclosure, denote the presence of specified features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.
[0113] The terminology used herein is for the purpose of describing particular embodiments only and is not limiting of the invention. As used herein, the singular forms "a," "an," and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It is further understood that the terms "including," "including," "comprises," and / or "having," when used in this disclosure, refer to the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.
[0114] Reference throughout this disclosure to "a single embodiment," "an embodiment," "a single arrangement," "an arrangement," "a single aspect," "an aspect," or similar language means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment described in this disclosure. Accordingly, one occurrence of the phrases "a single embodiment," "an embodiment," "a single arrangement," "an arrangement," "a single aspect," "an aspect," and similar language throughout this disclosure may, but need not, refer to the same embodiment.
[0115] The term "plurality" as used herein is defined as two or more than two. The term "another" as used herein is defined as at least one second or more. The term "connected" as used herein is defined as connected, whether directly without any intervening elements or indirectly with one or more intervening elements, unless otherwise specified. Two elements may also be connected mechanically, electrically, or by data exchange through a transmission channel, path, network, or system. The term "and / or" as used herein refers to and includes any and all possible combinations of one or more of the related listed elements. Although the terms first, second, etc.may be used herein to describe various elements, it is also understood that these elements should not be limited by these terms, as these terms are used only to distinguish one element from another unless otherwise stated or unless the context indicates otherwise.
[0116] The term "if" may, depending on the context, be interpreted to mean "when" or "after" or "in response to the determination" or "in response to the detection." Similarly, the phrase "if it is determined" or "if [a specified condition or event] is detected" may, depending on the context, be interpreted to mean "after the determination" or "in response to the determination" or "after [the specified condition or event] has been detected," or "in response to [the specified condition or event] having been detected."
[0117] The descriptions of the various embodiments of the present invention have been presented for purposes of illustration, but are not intended to be exhaustive or limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described embodiments. The terminology used herein has been chosen to best explain the principles of the embodiments, practical application, or technical improvement over existing technology, or to enable others skilled in the art to understand the embodiments disclosed herein.
Claims
[1] Procedure which includes: Establishing a secure transmission tunnel between user space software and a client device; Accessing a private session key from an encryption service; Transmitting, from the user space software to a network transmission unit, the private session key; and Transmitting, from the user space software to the network transmission unit, outgoing session packets; wherein the network transmission unit is programmed to initiate operations comprising: generating, by the network transmission unit, encrypted outgoing session packets by encrypting the outgoing session packets using the private session key; Transmitting, by the network transmission unit to the client unit via the secure transmission tunnel, the encrypted outgoing session packets; Receiving, by the network transmission unit from the client unit, via the secured transmission tunnel, incoming session packets; generating, by the network transmission unit, decrypted incoming session packets by decrypting the incoming session packets using the private session key; and Transmitting, from the network transmission unit to the user space software, the decrypted incoming session packets. [2] The method of claim 1, further comprising: Receiving from an operating system space a port identifier for a port provided by the operating system space to be used by the user space software for a communication session; wherein transmitting, from the user space software to the network transmission unit, the private session key comprises transmitting the private session key to the network transmission unit over the port specified by the port identifier in at least one User Datagram Protocol (UDP) datagram. [3] The method of claim 1, wherein transmitting the private session key from the user space software to the network transmission unit comprises transmitting the private session key from the user space software to the network transmission unit via an application programming interface. [4] The method of claim 1, further comprising: Transmitting, from the user space software to the network transmission unit, an n-tuple, the n-tuple comprising data indicating a source IP address and a destination IP address, the network transmission unit storing the n-tuple in association with the private session key in a software stack of the network transmission unit. [5] The method of claim 4, further comprising: Receiving, by the user space software from the network transmission unit, a UDP datagram indicating a completion status indicating that the reception and storage of the n-tuple and the private session key by the network transmission unit have been completed; wherein the transmission, from the user space software to the network transmission unit, of the outgoing session packets occurs in response to the receipt from the network transmission unit of the UDP datagram indicating the completion status indicating that the receipt and storage of the n-tuple and the private session key by the network transmission unit have been completed. [6] The method of claim 4, further comprising: Receiving, by the user space software from the network transmission unit, via an application programming interface, a completion status indicating that the reception and storage of the n-tuple and the private session key by the network transmission unit have been completed; wherein the transmission, from the user space software to the network transmission unit, of the outgoing session packets occurs in response to the receipt, by the user space software from the network transmission unit, via the application programming interface, of the completion status indicating that the reception and storage of the n-tuple and the private session key by the network transmission unit have been completed. [7] The method of claim 1, wherein the private session key is neither known to nor discovered by a host hypervisor stack nor an operating system space of a data processing system hosting the user space software. [8] System that has: a processor programmed to start executable operations that have: Establishing a secure transmission tunnel between user space software and a client device; Accessing a private session key from an encryption service; Transmitting, from the user space software to a network transmission unit, the private session key; and Transmitting, from the user space software to the network transmission unit, outgoing session packets; wherein the network transmission unit is programmed to initiate executable operations comprising: generating, by the network transmission unit, encrypted outgoing session packets by encrypting the outgoing session packets using the private session key; Transmitting, by the network transmission unit to the client unit via the secure transmission tunnel, the encrypted outgoing session packets; Receiving, by the network transmission unit from the client unit, via the secured transmission tunnel, incoming session packets; generating, by the network transmission unit, decrypted incoming session packets by decrypting the incoming session packets using the private session key; and Transmitting, from the network transmission unit to the user space software, the decrypted incoming session packets. [9] The system of claim 8, wherein the executable operations further comprise: Receiving from an operating system space a port identifier for a port provided by the operating system space to be used by the user space software for a communication session; wherein transmitting, from the user space software to the network transmission unit, the private session key comprises transmitting the private session key to the network transmission unit over the port specified by the port identifier in at least one User Datagram Protocol (UDP) datagram. [10] The system of claim 8, wherein transmitting the private session key from the user space software to the network transmission unit comprises transmitting the private session key from the user space software to the network transmission unit via an application programming interface. [11] The system of claim 8, wherein the executable operations further comprise: Transmitting, from the user space software to the network transmission unit, an n-tuple, the n-tuple comprising data indicating a source IP address and a destination IP address, the network transmission unit storing the n-tuple in association with the private session key in a software stack of the network transmission unit. [12] The system of claim 11, wherein the executable operations further comprise: Receiving, by the user space software from the network transmission unit, a UDP datagram indicating a completion status indicating that the reception and storage of the n-tuple and the private session key by the network transmission unit have been completed; wherein the transmission, from the user space software to the network transmission unit, of the outgoing session packets occurs in response to the receipt from the network transmission unit of the UDP datagram indicating the completion status indicating that the receipt and storage of the n-tuple and the private session key by the network transmission unit have been completed. [13] The system of claim 11, wherein the executable operations further comprise: Receiving, by the user space software from the network transmission unit, via an application programming interface, a completion status indicating that the reception and storage of the n-tuple and the private session key by the network transmission unit have been completed; wherein the transmission, from the user space software to the network transmission unit, of the outgoing session packets occurs in response to the receipt, by the user space software from the network transmission unit, via the application programming interface, of the completion status indicating that the reception and storage of the n-tuple and the private session key by the network transmission unit have been completed. [14] The system of claim 8, wherein the private session key is neither known to nor discovered by a host hypervisor stack nor an operating system space of a data processing system hosting the user space software. [15] Computer program product comprising: one or more computer-readable storage media having program code stored thereon, wherein the program code stored on the one or more computer-readable storage media is executable as a whole by a data processing system to perform operations including: Establishing a secure transmission tunnel between user space software and a client device; Accessing a private session key from an encryption service; Transmitting, from the user space software to a network transmission unit, the private session key; and Transmitting, from the user space software to the network transmission unit, outgoing session packets; wherein the network transmission unit is programmed to initiate executable operations comprising: generating, by the network transmission unit, encrypted outgoing session packets by encrypting the outgoing session packets using the private session key; Transmitting, by the network transmission unit to the client unit via the secure transmission tunnel, the encrypted outgoing session packets; Receiving, by the network transmission unit from the client unit, via the secured transmission tunnel, incoming session packets; generating, by the network transmission unit, decrypted incoming session packets by decrypting the incoming session packets using the private session key; and Transmitting, from the network transmission unit to the user space software, the decrypted incoming session packets. [16] The computer program product of claim 15, wherein the program code is executable by the data processing system to initiate operations further comprising: Receiving from an operating system space a port identifier for a port provided by the operating system space to be used by the user space software for a communication session; wherein transmitting, from the user space software to the network transmission unit, the private session key comprises transmitting the private session key to the network transmission unit over the port specified by the port identifier in at least one User Datagram Protocol (UDP) datagram. [17] The computer program product of claim 15, wherein transmitting the private session key from the user space software to the network transmission device comprises transmitting the private session key from the user space software to the network transmission device via an application programming interface. [18] The computer program product of claim 15, wherein the program code is executable by the data processing system to initiate operations further comprising: Transmitting, from the user space software to the network transmission unit, an n-tuple, the n-tuple comprising data indicating a source IP address and a destination IP address, the network transmission unit storing the n-tuple in association with the private session key in a software stack of the network transmission unit. [19] The computer program product of claim 18, wherein the program code is executable by the data processing system to initiate operations further comprising: Receiving, by the user space software from the network transmission unit, a UDP datagram indicating a completion status indicating that the reception and storage of the n-tuple and the private session key by the network transmission unit have been completed; wherein the transmission, from the user space software to the network transmission unit, of the outgoing session packets occurs in response to the receipt from the network transmission unit of the UDP datagram indicating the completion status indicating that the receipt and storage of the n-tuple and the private session key by the network transmission unit have been completed. [20] The computer program product of claim 18, wherein the program code is executable by the data processing system to initiate operations further comprising: Receiving, by the user space software from the network transmission unit, via an application programming interface, a completion status indicating that the reception and storage of the n-tuple and the private session key by the network transmission unit have been completed; wherein the transmission, from the user space software to the network transmission unit, of the outgoing session packets occurs in response to the receipt, by the user space software from the network transmission unit, via the application programming interface, of the completion status indicating that the reception and storage of the n-tuple and the private session key by the network transmission unit have been completed.
Citation Information
Cited By
Distribution of private session key to a network communication device for secured RDMA communications
US12732360B2