IP Library › Granted Patent US 10,185,599
Granted Patent B2
US 10,185,599 · App. 15/178,171 · Granted Jan 22, 2019

Kernel mode accelerator

Inventors: Francis Dinha (Dublin, CA); James Yonan (Pleasanton, CA)
Assignee: OpenVPN Technologies, Inc.
G06F9/54H04L63/0272
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,185,599
App. No.
15/178,171
Granted
Jan 22, 2019
Kind
B2
Abstract

A system and method for disposing, in kernel space, a data plane having instructions operable to encrypt and transfer data over a network. The data plane is coupled to a control plane which resides in user space. The control plane has instructions operable to control the transfer of the encrypted data in kernel space. Certain embodiments include an application programming interface (API), which operates to expose a programming interface for encrypted communications which results in a more efficient data transfer because most of the data processing is done in kernel space.

Claims (26)

1. A method including the following:

disposing, in kernel space, a data plane, said data plane including processor-readable instructions directing the processor to encrypt and transfer data over a network;

disposing, in user space, a control plane, said control plane including processor-readable instructions directing the processor to encrypt and transfer data over the network;

disposing, in user space, an application programming interface (API), said API operable to expose a programming interface for encrypted communications,

receiving network condition information, wherein the network condition information comprises network throughput information, and

allocating encryption and data transfer operations between the data plane and the control plane in response to the network throughput information.

2. The method of claim 1 wherein said encryption and data transfer operations include at least one of authentication, VPN operations, or data compression.

3. The method of claim 1 wherein the data plane and the control plane include processor-readable instructions operable to effectuate data encapsulation.

4. The method of claim 1 wherein the control plane and the data plane include processor-readable instructions operable to effectuate secure sockets layer (SSL) security.

5. A processing device including:

a processor, said processor coupled to a memory and a network, said memory having a substantially smaller kernel space portion, and a relatively larger user space portion;

a control plane disposed in the user space and operable to effectuate encryption and transfer of data;

an application programming interface (API), said API disposed in the user space and operable to expose control of the control plane to users;

a data plane, said data plane disposed in the kernel space and operable to effectuate encryption and transfer of data;

wherein the processor receives network throughput information and

allocates encryption and data transfer operations between the data plane and the control plane in response to the network throughput information.

6. The device of claim 5 wherein either the data plane or the control plane is operable to interface with one or more VPN clients.

7. A non-transitory processor-readable storage device having processor readable code embodied on said storage device, said code for programming one or more processor to perform a method including:

disposing, in kernel space, a data plane, said data plane including processor-readable instructions operable to encrypt and transfer data over a network;

disposing, in user space, a control plane, said control plane including processor-readable instructions operable to encrypt and transfer data over the network;

disposing, in user space, an application programming interface (API), said API operable to expose a programming interface for encrypted communications,

receiving network throughput information, and

allocating encryption and transfer data operations between the data plane and the control plane in response to the network throughput information.

8. The storage device of claim 7 wherein the data plane and control plane include processor-readable instructions directing the processor to effectuate a virtual private network (VPN).

9. The storage device of claim 8 wherein the data plane and the control plane include processor-readable instructions directing the processor to effectuate data encapsulation.

10. The storage device of claim 7 wherein the control plane includes processor readable-instructions directing the processor to effectuate secure sockets layer (SSL) security.

Assignments (2)
CHANGE OF NAME Recorded Mar 2, 2022
From: OPENVPN TECHNOLOGIES INC
To: OPENVPN INC.
Reel/Frame 059781/0677 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 13, 2016
From: DINHA, FRANCIS; YONAN, JAMES
To: OPENVPN TECHNOLOGIES, INC.
Reel/Frame 038896/0634 →
Continuity (2)
Provisional Application 62189715 · Jul 7, 2015
Related Publication 20170013015A1 · Jan 12, 2017