IP Library Patent Application 16368396
Patent Application
App. No. 16/368,396

METHODS AND APPARATUS FOR SECURE OPERATION OF USER SPACE COMMUNICATION STACKS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
16/368,396
Abstract

Methods and apparatus for efficient data transfer within a user space network stack. Unlike prior art monolithic networking stacks, the exemplary networking stack architecture described hereinafter includes various components that span multiple domains (both in-kernel, and non-kernel). For example, unlike traditional “socket” based communication, disclosed embodiments can transfer data directly between the kernel and user space domains. Direct transfer reduces the per-byte and per-packet costs relative to socket based communication. A user space networking stack is disclosed that enables extensible, cross-platform-capable, user space control of the networking protocol stack functionality. The user space networking stack facilitates tighter integration between the protocol layers (including TLS) and the application or daemon. Exemplary systems can support multiple networking protocol stack instances (including an in-kernel traditional network stack).

Claims (34)

1 . A method for validating user space packet descriptors, comprising:

receiving a plurality of packets from a user space process;

for each packet of the plurality of packets:

extracting a data structure from the packet;

validating that the data structure conforms to a packet descriptor format; and

providing validated packets to a kernel space process.

2 . The method of claim 1 , wherein extracting the data structure from the each packet comprises extracting a pattern from a packet header associated with the each packet.

3 . The method of claim 2 , wherein validating that the data structure conforms to a packet descriptor format comprises checking the pattern based on a random number and an address associated with the each packet.

4 . The method of claim 1 , further comprising terminating the user space process when at least one packet is invalid.

5 . The method of claim 1 , wherein validating that the data structure conforms to a packet descriptor format comprises checking that the data structure comprises a valid checksum.

6 . The method of claim 1 , wherein validating that the data structure conforms to a packet descriptor format comprises checking that the data structure comprises a base offset from an address.

7 . The method of claim 6 , wherein providing validated packets to the kernel space process further comprises translating the base offset from the address to a pointer in kernel virtual address space.

8 . A method for tracking user space packet descriptors, comprising:

receiving a plurality of packets from a user space process;

determining a connection state based at least in part on a plurality of packet descriptors associated with a first set of the plurality of packets from the user space process; and

transmitting the first set of the plurality of packets from the user space process when the connection state is valid.

9 . The method of claim 8 , further comprising determining a second connection state associated with a second set of the plurality of packets from the user space process; and

rate limiting the second set of the plurality of packets from the user space process when the connection state is invalid.

10 . The method of claim 9 , wherein the second set of the plurality of packets from the user space process comprise synchronization packets (SYN) that are sent while one or more acknowledgement packets (ACK) packets have not been received.

11 . The method of claim 9 , wherein the second set of the plurality of packets from the user space process comprise reset packets (RST) that are sent without an outstanding socket connection.

12 . The method of claim 9 , wherein the second set of the plurality of packets from the user space process comprise reset packets (RST) that are sent without an outstanding synchronization packet (SYN).

13 . The method of claim 8 , further comprising generating one or more kernel space statistics based on the first set of the plurality of packets from the user space process when the connection state is valid.

14 . The method of claim 8 , further comprising determining a second connection state associated with a second set of the plurality of packets from the user space process; and

ignoring one or more user space statistics based on the second set of the plurality of packets from the user space process when the connection state is valid.

15 . A method for propagating sensitive network statistics, comprising:

receiving network statistics from a user space process;

validating the network statistics based at least in part on a plurality of packet descriptors associated with a first set of a plurality of packets from the user space process;

updating kernel space network statistics with the network statistics from the user space process based on the validation; and

generating an obfuscated set of network statistics for a second user space process based on the kernel space network statistics.

16 . The method of claim 15 , wherein receiving the network statistics from the user space process includes receiving round trip delay time (RTT) data.

17 . The method of claim 16 , wherein validating the network statistics based at least in part on the plurality of packet descriptors associated with the first set of the plurality of packets from the user space process comprises determining an upper and a lower RTT bound.

18 . The method of claim 15 , wherein the user space process comprises a user space library that is self-contained.

19 . The method of claim 18 , wherein the second user space process comprises a user space application that has entitlements to access the network statistics generated by the user space library.

20 . The method of claim 19 , wherein the user space library and the second user space process are operating from a common application space.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 12, 2019
From: MASPUTRA, CAHYA ADIANSYAH; NAIR, SANDEEP; PAULY, THOMAS FRANCIS; SIEGMUND, DIETER WILFRED; SHEN, WEI; MARDINIAN, OLIVIER; JEWELL, DARRIN
To: APPLE INC.
Reel/Frame 050986/0624 →