IP Library Granted Patent US 12,255,921
Granted Patent B2
US 12,255,921 · App. 17/349,247 · Granted Mar 18, 2025

Efficient encryption in VPN sessions

Inventors: Akhilesh S. Thyagaturu (Tempe, AZ); Vinodh Gopal (Westborough, MA)
Assignee: Intel Corporation
H04L63/18H04L63/0272H04L63/029H04L63/0428H04L63/164H04L63/166H04L63/168
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,255,921
App. No.
17/349,247
Granted
Mar 18, 2025
Kind
B2
Abstract

Methods, apparatus, and software for efficient encryption in virtual private network (VPN) sessions. A VPN link and an auxiliary link (and associated sessions) are established between computing platforms to support end-to-end communication between respective application running on the platforms. The VPN link may employ a conventional VPN protocol such as TLS or IPsec, while the auxiliary link comprises a NULL encryption VPN tunnel. To transfer data, a determination is made to whether the data are encrypted or non-encrypted. Encrypted data are transferred over the auxiliary link to avoid re-encryption of the data. Non-encrypted are transferred over the VPN link. TLS and IPsec VPN agents may be used to assist in setting up the VPN and auxiliary sessions. The techniques avoid double encryption of VPN traffic, while ensuring that various types of traffic transferred between platforms is encrypted.

Claims (40)

1. A method for securely transferring data, comprising:

establishing a virtual private network (VPN) link between a first platform running a first application and a second platform communicatively coupled to the first platform via one or more networks and running a second application;

establishing an auxiliary link comprising a NULL encryption VPN tunnel between the first platform and the second platform;

establishing a Transport Layer Security (TLS) VPN session to be used for forwarding traffic over the VPN link;

establishing an auxiliary TLS session to transfer data over the auxiliary link,

wherein each of the TLS VPN session and the auxiliary TLS session has a TLS session identifier (ID);

maintaining a data structure mapping TLS session IDs to cipher information indicating whether a TLS session ID is associated with a TLS VPN cipher or a NULL encryption;

determining whether data to be transferred between the first application and second application are encrypted data or non-encrypted data; and

when the data are encrypted, transferring the data between the first platform and the second platform over the auxiliary link; otherwise,

when the data are non-encrypted, transferring the data between the first platform and the second platform over the VPN link, wherein the non-encrypted data are encrypted using a VPN protocol comprising a TLS protocol in connection with transferring the data over the VPN link.

2. The method of claim 1 , wherein the VPN protocol is implemented via VPN agents comprising software running on the first and second platforms.

3. The method of claim 1 , wherein the encrypted data comprise Hypertext Transport Protocol Secure (HTTPS) traffic.

4. A computing platform, comprising a first computing platform and including:

a processor;

memory, operatively coupled to the processor;

a network interface, operatively coupled to the processor; and

software instructions, configured to be executed on the processor to enable the computing platform to:

establish a virtual private network (VPN) link between the first computing platform and a second computing platform communicatively coupled to the first computing platform via one or more networks;

establish an auxiliary link comprising a NULL encryption VPN tunnel between the first computing platform and the second computing platform;

establish a Transport Layer Security (TLS) VPN session to be used for forwarding traffic over the VPN link;

establish an auxiliary TLS session to transfer data over the auxiliary link,

wherein each of the TLS VPN session and the auxiliary TLS session has a TLS session identifier (ID);

maintain a data structure mapping TLS session IDs to cipher information indicating whether a TLS session ID is associated with a TLS VPN cipher or a NULL encryption;

determine whether data to be transferred between the first computing platform and the second computing platform are encrypted data or non-encrypted data; and

when the data are encrypted, transferring the data between the first computing platform and the second computing platform over the auxiliary link; otherwise,

when the data are non-encrypted, encrypting the data using a TLS protocol and transferring the data encrypted using the TLS protocol between the first computing platform and the second computing platform over the VPN link.

5. The computing platform of claim 4 , wherein the software instructions include instructions comprising a VPN agent, and wherein the TLS protocol is implemented via the VPN agent.

6. The computing platform of claim 4 , wherein the encrypted data comprise Hypertext Transport Protocol Secure (HTTPS) traffic.

7. A non-transitory machine-readable storage medium having instructions stored there thereon configured to executed on a processor of a first computing platform including a first network interface communicatively coupled to a second network interface of a second computing platform, wherein execution of the instructions enables the first computing platform to:

establish a virtual private network (VPN) link between the first computing platform and a second computing platform communicatively coupled to the first computing platform via one or more networks;

establish an auxiliary link comprising a NULL encryption VPN tunnel between the first computing platform and the second computing platform;

establish a Transport Layer Security (TLS) VPN session to be used for forwarding traffic over the VPN link;

establish an auxiliary TLS session to transfer data over the auxiliary link,

wherein each of the TLS VPN session and the auxiliary TLS session has a TLS session identifier (ID);

maintain a data structure mapping TLS session IDs to cipher information indicating whether a TLS session ID is associated with a TLS VPN cipher or a NULL encryption;

determine whether data to be transferred between the first computing platform and the second computing platform are encrypted data or non-encrypted data; and

when the data are encrypted, transferring the data between the first computing platform and the second computing platform over the auxiliary link; otherwise,

when the data are non-encrypted, encrypting the data using a TLS protocol and transferring the data encrypted using the TLS protocol between the first computing platform and the second computing platform over the VPN link.

8. The non-transitory machine-readable storage medium of claim 7 , wherein the encrypted data comprise Hypertext Transport Protocol Secure (HTTPS) traffic.

9. The non-transitory machine-readable storage medium of claim 7 , wherein the software instructions include instructions comprising a VPN agent, and wherein the TLS protocol is implemented via the VPN agent.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 28, 2021
From: THYAGATURU, AKHILESH S.; GOPAL, VINODH
To: INTEL CORPORATION
Reel/Frame 056688/0280 →
Continuity (1)
Related Publication 20210314359A1 · Oct 7, 2021
References Cited (10)
US 9571457B1 · Hoy · 2017 [cited by examiner]
US 20070218912A1 · Song · 2007 [cited by examiner]
US 20160315920A1 · Kurmala · 2016 [cited by examiner]
US 20200162382A1 · Mendoza · 2020 [cited by examiner]
CN 103188351A · 2013 [cited by examiner]
“Fortigate SSL VPN”, Fortigate Guide, downloaded from https://tekguru4u.com/fortigate-ssl-vpn/, Jun. 14, 2021, 5 pages. [cited by applicant]
Lacković et al, “Performance Analysis of Virtualized VPN Endpoints,” 2017 40th International Convention on Information and Communication Technology, Electronics and Microelectronics (MIPRO), May 2017, 6 pages. [cited by applicant]
Shantharama et al, “Hardware Acceleration for Container Migration on Resource-Constrained Platforms”, IEEE Access, received Aug. 6, 2020, accepted Sep. 11, 2020, date of publication Sep. 18, 2020, date of current versio… [cited by applicant]
Shantharama, “Hardware-Accelerated Platforms and Infrastructures for Network Functions: A Survey of Enabling Technologies and Research Studies”, in IEEE Access, vol. 8, 2020, 65 pages. [cited by applicant]
Talkington et al., “Detecting Devices and Protocols on VPN-Encrypted Networks”, 2020 Sixth International Conference on Mobile And Secure Services (MobiSecServ), Feb. 2020, 8 pages. [cited by applicant]