发明公开
- 专利标题: End-to-end network security with traffic visibility
- 专利标题(中): 与流量可视性终端到端到端的网络安全
-
申请号: EP08253608.7申请日: 2008-11-05
-
公开(公告)号: EP2068526A3公开(公告)日: 2012-07-11
- 发明人: Long, Men , Walker, Jesse , Durham, David , Millier, Marc , Grewal, Karanvir
- 申请人: Intel Corporation
- 申请人地址: 2200 Mission College Boulevard Santa Clara, CA 95054 US
- 专利权人: Intel Corporation
- 当前专利权人: Intel Corporation
- 当前专利权人地址: 2200 Mission College Boulevard Santa Clara, CA 95054 US
- 代理机构: Beresford, Keith Denis Lewis
- 优先权: US935783 20071106
- 主分类号: H04L29/06
- IPC分类号: H04L29/06
摘要:
End-to-end security between clients and a server, and traffic visibility to intermediate network devices, achieved through combined mode, single pass encryption and authentication using two keys is disclosed. In various embodiments, a combined encryption-authentication unit includes a cipher unit and an authentication unit coupled in parallel to the cipher unit, and generates an authentication tag using an authentication key in parallel with the generation of the cipher text using an encryption key, where the authentication and encryption key have different key values. In various embodiments, the cipher unit operates in AES counter mode, and the authentication unit operates in parallel, in AES-GMAC mode Using a two key, single pass combined mode algorithm preserves network performance using a limited number of HW gates, while allowing an intermediate device access to the encryption key for deciphering the data, without providing that device the ability to compromise data integrity, which is preserved between the end to end devices.
公开/授权文献
- EP2068526B1 End-to-end network security with traffic visibility 公开/授权日:2014-04-30
信息查询