• Skip to primary navigation
  • Skip to main content
  • Skip to footer

Cypherbridge Systems

IoT Security Solutions

MENUMENU
  • Company
    • About Cypherbridge
    • Company Blog
    • Industry Partners
    • Partner Programs
      • NXP
      • Renesas
      • ST
      • Synopsis
      • Texas Instruments
    • Media Kit
  • Verticals
  • Products
    • IoT Device Solutions
    • Chips & Platforms
    • Software Development Kits
      • uLoadXL SDK
      • uVPN SDK
      • uSSL TLS SDK
      • uSSH SDK
      • uCrypt SDK
      • uSMTP Toolkit
      • uMQTT Toolkit
      • uFile File Encryption
      • e802.1X SDK
      • uMODBUS Toolkit
      • EST SDK
      • NTP Client
      • uFTP Toolkit
      • Certstore Toolkit
  • Services
    • IoT Cybersecurity Trends
    • CDX Cloud Data Exchange
    • IoT Cybersecurity and the CRA
    • ESAS Embedded Software Assurance Service
    • Eclipse ThreadX Solution Center
    • Planning and Design
    • Solution Delivery
    • Product and System Integration
    • Product Life Cycle
  • Industry Partners
  • News
    • Upcoming Trade Shows
      • Past Trade Shows
    • Company Blog
    • News Releases
    • Product Announcements
    • Recent Newsletters
  • Support
    • Customer Area
    • Sitemap
    • Privacy Policy
    • Contact Us
You are here: Home / SDKPac Products / uVPN SDK

uVPN SDK

Overview

The Cypherbridge Systems VPN SDK implements IKEv1/IKEv2/IPsec for a cryptographically secure solution for IP packet networking. It provides authentication, data encryption and message integrity for embedded devices. VPN SDK is a standards based, full featured toolkit delivering system benefits including security and performance for embedded platforms, smartphones, tablets and more.

uVPN SDK Features

  • IPSec Tunnel and Transport Modes
  • IKEv1 and IKEv2 initiator and responder
  • uCrypt library HW Crypto engine integrated
  • TCP/IP stack L3 driver including LwIP support
  • Integrated SPD/SAD database
  • Rekey Operation
  • Dead Peer Detection
  • Post Quantum Ready RFC8784
  • Interoperates with Strongswan, Windows IPsec VPN, Cisco, Juniper

IPsec

IPsec adds peer authentication, encryption and message integrity to IP packet networks, protecting against loss of data privacy, integrity, identity spoofing, and replay attack. IPsec adds security at the network IP layer, with no changes needed to existing client/server or streaming applications. Widely adopted, standards based and interoperable with all network equipment, IPsec can be deployed in host-to-host security channels, remote access VPN to corporate network, or network-to-network.

The VPN SDK supports AH and ESP protocols, as illustrated in the following diagram showing ESP enscapulation over a network-to-network tunneled VPN:

The VPN SDK is designed for both IPv4 and IPv6 operation and is optimized for deployment in embedded systems.

IPsec Features

  • Supports AH and ESP connections
  • Integrated uCrypt cryptographic library includes DHM, AES, 3DES, RC4, SHA256, SHA384, MD5
  • TCP/IP interface integrates with RTOS, Kernel, User Mode TCP/IP stacks

IKE- Internet Key Exchange

VPN uIKE implements IKEv1 and IKEv2 standards based protocols to set up Security Associations (SA) for IPsec. Peer systems dynamically establish and synchronize the IKE SA through mutual authentication and secure exchange of session keys.
The SPD governs the policy and management of the security layers. The Security Policy Database (SPD) is used to define traffic flows, such that selected network traffic and direction can be configured on a granular basis. This allows all or selected network traffic to be protected with IPsec.
VPN uIKE stores the keys in the Security Association Database (SAD). IPsec fetches the cipher and authentication type and keys from the SAD, then applies security to an IP packet to encrypt outbound traffic, and decrypt inbound packets.

uVPN Integrated Solution

The following diagram shows the relationship between IKEv2 protocol, the SPD/SAD tables, IPsec, and the components of the embedded TCP/IP stack. The VPN SDK implements “bump-in-stack” security processing at the TCP/IP L3 datagram layer:

IKE Features

  • Supports embedded IKE initiator mode, Phase1 and Phase2 security association SA
  • Configurable session options for Security Association negotiation
  • Automatic negotiation of IKE connection
  • Authentication using shared secret and RSA key pairs

Contact Us

Cypherbridge Systems
7040 Avenida Encinas #104211
Carlsbad, CA 92011 USA

Phone: +1 760-814-1575
Email: info at cypherbridge.com

Follow Us

  • LinkedIn
  • Twitter
  • YouTube

About Us

Cypherbridge Systems is a security and communication protocol software firm based in Carlsbad, CA. Since inception in 2005, Cypherbridge has delivered a diverse range of solutions to real-world problems for vertical markets. Our customers range from venture funded startups to Fortune 10 global companies.

Learn More
Join the Cypherbridge Mailing List

We use MailChimp as our marketing automation platform. By clicking below to submit this form, you acknowledge that the information you provide will be transferred to MailChimp for processing in accordance with their privacy policy and terms.


Copyright © 2025 · Log in