Invention Grant
- Patent Title: Secured network architecture
-
Application No.: US14780785Application Date: 2013-03-27
-
Publication No.: US10924470B2Publication Date: 2021-02-16
- Inventor: Esa Markus Metsala , Heikki-Stefan Almay
- Applicant: NOKIA SOLUTIONS AND NETWORKS OY
- Applicant Address: FI Espoo
- Assignee: NOKIA SOLUTIONS AND NETWORKS OY
- Current Assignee: NOKIA SOLUTIONS AND NETWORKS OY
- Current Assignee Address: FI Espoo
- Agency: Squire Patton Boggs (US) LLP
- International Application: PCT/EP2013/056541 WO 20130327
- International Announcement: WO2014/154264 WO 20141002
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04W12/06 ; H04L9/32

Abstract:
A secure storage for an X.509v3 digital certificate is provided (301, 302). Ports of a first and second apparatus (101, 102) are mutually authenticated (303) by using 802.1X based authentication and 802.1AR certificates. Traffic types are divided (304, 305) by an operator-configurable selector function into user plane, control plane, synchronization plane, and management plane traffic types. For Ethernet transport a virtual port is created for each traffic type, and a different MACsec secure connectivity association is created for each virtual port. For Ethernet transport an operator-programmable security policy is maintained for each traffic type. For IP transport an IPsec security association is created for each traffic type, and an operator-programmable security policy is maintained for each security association. For IP transport, TLS support may be enabled for compatibility with network management traffic. A port is repeatedly re-authenticated by an operator-definable timer value.
Public/Granted literature
- US20160057121A1 SECURED NETWORK ARCHITECTURE Public/Granted day:2016-02-25
Information query