Invention Application
- Patent Title: SECURED NETWORK ARCHITECTURE
- Patent Title (中): 安全网络架构
-
Application No.: US14780785Application Date: 2013-03-27
-
Publication No.: US20160057121A1Publication Date: 2016-02-25
- Inventor: Esa Markus METSALA , Heikki-Stefan ALMAY
- Applicant: NOKIA SOLUTIONS AND NETWORKS OY
- International Application: PCT/EP2013/056541 WO 20130327
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L9/32

Abstract:
A secure storage for an X.509v3 digital certificate is provided (301, 302). Ports of a first and second apparatus (101, 102) are mutually authenticated (303) by using 802.1X based authentication and 802.1AR certificates. Traffic types are divided (304, 305) by an operator-configurable selector function into user plane, control plane, synchronization plane, and management plane traffic types. For Ethernet transport a virtual port is created for each traffic type, and a different MACsec secure connectivity association is created for each virtual port. For Ethernet transport an operator-programmable security policy is maintained for each traffic type. For IP transport an IPsec security association is created for each traffic type, and an operator-programmable security policy is maintained for each security association. For IP transport, TLS support may be enabled for compatibility with network management traffic. A port is repeatedly re-authenticated by an operator-definable timer value.
Public/Granted literature
- US10924470B2 Secured network architecture Public/Granted day:2021-02-16
Information query