IP Library › Granted Patent US 7,870,384
Granted Patent B2
US 7,870,384 · App. 12/121,844 · Granted Jan 11, 2011

Offload processing for secure data transfer

Assignee: International Business Machines Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,870,384
App. No.
12/121,844
Granted
Jan 11, 2011
Kind
B2
Abstract

Improvements in security processing are disclosed which enable security processing to be transparent to the application. Security processing (such as Secure Sockets Layer, or “SSL”, or Transport Layer Security, or “TLS”) is performed in (or controlled by) the stack. A decision to enable security processing on a connection can be based on configuration data or security policy, and can also be controlled using explicit enablement directives. Directives may also be provided for allowing applications to communicate with the security processing in the stack for other purposes. Functions within the protocol stack that need access to clear text can now be supported without loss of security processing capability. No modifications to application code, or in some cases only minor modifications (such as inclusion of code to invoke directives), are required to provide this security processing. Improved offloading of security processing is also disclosed, which provides processing efficiencies over prior art offloading techniques. Offload components can be controlled from the kernel, an SSL layer or an application.

Claims (6)

1. A system for improving security processing in a computing network, comprising:

a security offload component in an operating system kernel which performs security processing;

at least one control function in an SSL layer or application layer for directing operation of the security offload component;

means for executing the at least one provided control function; and

means, responsive to operation of the means for executing, for directing the security offload component to secure at least one communication of an application program;

wherein the application program executes under the control of the operating system kernel.

Continuity (2)
Continuation 1028910700 · Nov 6, 2002
Related Publication 20080216150A1 · Sep 4, 2008