Method and system for establishing secure connection between stations

    公开(公告)号:US08755528B2

    公开(公告)日:2014-06-17

    申请号:US13516257

    申请日:2010-05-21

    IPC分类号: G06F21/00

    摘要: A method and system for establishing a secure connection between stations are disclosed. The method includes that: 1) a switch device receives an inter-station key request packet sent by a first user terminal; 2) the switch device generates an inter-station key, constructs an inter-station key announcement packet and sends it to a second user terminal; 3) the switch device receives an inter-station key announcement response packet sent by the second user terminal; 4) the switch device constructs an inter-station key announcement response packet and sends it to the first user terminal; 5) the switch device receives an inter-station key announcement response packet sent by the first user terminal. The switch device establishes an inter-station key for the two stations which are connected to the switch device directly, by which the embodiments of the present invention ensure the confidentiality and integrality of user data between the stations.

    METHOD AND SYSTEM FOR ESTABLISHING SECURE CONNECTION BETWEEN STATIONS
    12.
    发明申请
    METHOD AND SYSTEM FOR ESTABLISHING SECURE CONNECTION BETWEEN STATIONS 有权
    建立安全连接的方法和系统

    公开(公告)号:US20120257755A1

    公开(公告)日:2012-10-11

    申请号:US13516257

    申请日:2010-05-21

    IPC分类号: H04L9/08

    CPC分类号: H04L9/083 H04L63/061

    摘要: A method and system for establishing a secure connection between stations are disclosed. The method includes that: 1) a switch device receives an inter-station key request packet sent by a first user terminal; 2) the switch device generates an inter-station key, constructs an inter-station key announcement packet and sends it to a second user terminal; 3) the switch device receives an inter-station key announcement response packet sent by the second user terminal; 4) the switch device constructs an inter-station key announcement response packet and sends it to the first user terminal; 5) the switch device receives an inter-station key announcement response packet sent by the first user terminal. The switch device establishes an inter-station key for the two stations which are connected to the switch device directly, by which the embodiments of the present invention ensure the confidentiality and integrality of user data between the stations.

    摘要翻译: 公开了一种在站间建立安全连接的方法和系统。 该方法包括:1)交换设备接收由第一用户终端发送的站间密钥请求分组; 2)交换设备生成站间密钥,构建站间密钥通告报文,并发送给第二用户终端; 3)交换设备接收由第二用户终端发送的站间密钥通告响应报文; 4)交换机构建一个站间密钥通知应答报文,并发送给第一用户终端; 5)交换机接收第一用户终端发送的站间密钥通告响应报文。 交换设备为直接连接到交换机设备的两个站建立站间密钥,本发明的实施例通过该站点密钥确保站点之间的用户数据的机密性和完整性。

    Method for establishing secure network architecture, method and system for secure communication
    13.
    发明授权
    Method for establishing secure network architecture, method and system for secure communication 有权
    建立安全网络架构,安全通信方法和系统的方法

    公开(公告)号:US08843748B2

    公开(公告)日:2014-09-23

    申请号:US13702217

    申请日:2011-01-10

    IPC分类号: H04L29/06 H04L9/08 H04L12/18

    摘要: A method for establishing a secure network architecture, a method and system for secure communication are provided. The method for establishing a secure network architecture includes: 1) constructing the network architecture where the identities of nodes are legal, including: neighboring node discovery; performing identities certification and shared key negotiation between a node and the neighbor node; 2) constructing a secure switching device architecture, including: establishing a shared key between every two of the switch devices.

    摘要翻译: 提供了一种用于建立安全网络架构的方法,一种用于安全通信的方法和系统。 建立安全网络架构的方法包括:1)构建节点身份合法的网络架构,包括:邻居节点发现; 执行节点与邻居节点之间的身份认证和共享密钥协商; 2)构建安全交换设备架构,包括:在每两个交换设备之间建立共享密钥。

    Method and system for establishing secure connection between stations
    14.
    发明授权
    Method and system for establishing secure connection between stations 有权
    站之间建立安全连接的方法和系统

    公开(公告)号:US08831227B2

    公开(公告)日:2014-09-09

    申请号:US13516257

    申请日:2010-05-21

    IPC分类号: G06F21/00 H04L9/08 H04L29/06

    CPC分类号: H04L9/083 H04L63/061

    摘要: A method and system for establishing a secure connection between stations are disclosed. The method includes that: 1) a switch device receives an inter-station key request packet sent by a first user terminal; 2) the switch device generates an inter-station key, constructs an inter-station key announcement packet and sends it to a second user terminal; 3) the switch device receives an inter-station key announcement response packet sent by the second user terminal; 4) the switch device constructs an inter-station key announcement response packet and sends it to the first user terminal; 5) the switch device receives an inter-station key announcement response packet sent by the first user terminal. The switch device establishes an inter-station key for the two stations which are connected to the switch device directly, by which the embodiments of the present invention ensure the confidentiality and integrality of user data between the stations.

    摘要翻译: 公开了一种在站间建立安全连接的方法和系统。 该方法包括:1)交换设备接收由第一用户终端发送的站间密钥请求分组; 2)交换设备生成站间密钥,构建站间密钥通告报文,并发送给第二用户终端; 3)交换设备接收由第二用户终端发送的站间密钥通告响应报文; 4)交换机构建一个站间密钥通知应答报文,并发送给第一用户终端; 5)交换机接收第一用户终端发送的站间密钥通告响应报文。 交换设备为直接连接到交换机设备的两个站建立站间密钥,本发明的实施例通过该站点密钥确保站点之间的用户数据的机密性和完整性。

    METHOD FOR ESTABLISHING SECURE NETWORK ARCHITECTURE, METHOD AND SYSTEM FOR SECURE COMMUNICATION
    15.
    发明申请
    METHOD FOR ESTABLISHING SECURE NETWORK ARCHITECTURE, METHOD AND SYSTEM FOR SECURE COMMUNICATION 有权
    建立安全网络架构的方法,安全通信的方法和系统

    公开(公告)号:US20130080783A1

    公开(公告)日:2013-03-28

    申请号:US13702217

    申请日:2011-01-10

    IPC分类号: H04L9/08

    摘要: A method for establishing a secure network architecture, a method and system for secure communication are provided. Said method for establishing a secure network architecture includes: 1) constructing the network architecture where the identities of nodes are legal, including: neighboring node discovery; performing identities certification and shared key negotiation between a node and the neighbor node; 2) constructing a secure switching device architecture, including: establishing a shared key between every two of the switch devices.

    摘要翻译: 提供了一种用于建立安全网络架构的方法,一种用于安全通信的方法和系统。 所述建立安全网络架构的方法包括:1)构建节点身份合法的网络架构,包括:邻居节点发现; 执行节点与邻居节点之间的身份认证和共享密钥协商; 2)构建安全交换设备架构,包括:在每两个交换设备之间建立共享密钥。

    Terminal device capable of link layer encryption and decryption and data processing method thereof
    16.
    发明授权
    Terminal device capable of link layer encryption and decryption and data processing method thereof 有权
    能够进行链路层加密和解密的终端设备及其数据处理方法

    公开(公告)号:US09009466B2

    公开(公告)日:2015-04-14

    申请号:US13995641

    申请日:2011-06-17

    IPC分类号: H04L29/06 H04L9/08

    摘要: There are a terminal device capable of link layer encryption and decryption and a data process method thereof, and the terminal device includes a link layer processing module including a control module, a data frame encryption module, a data frame decryption module, a key management module, an algorithm module, a transmission port and a reception port; and the control module is connected with the transmission port through the data frame encryption module, the reception port is connected with the control module through the data frame decryption module, the control module is connected with the key management module, the data frame encryption module is connected with the data frame decryption module through the key management module, and the data frame encryption module is connected with the data frame decryption module through the algorithm module.

    摘要翻译: 存在能够进行链路层加密和解密的终端设备及其数据处理方法,并且终端设备包括链路层处理模块,该链路层处理模块包括控制模块,数据帧加密模块,数据帧解密模块,密钥管理模块 算法模块,传输端口和接收端口; 控制模块通过数据帧加密模块与传输端口连接,接收端口通过数据帧解密模块与控制模块连接,控制模块与密钥管理模块连接,数据帧加密模块为 通过密钥管理模块与数据帧解密模块相连,数据帧加密模块通过算法模块与数据帧解密模块连接。

    TERMINAL DEVICE CAPABLE OF LINK LAYER ENCRYPTION AND DECRYPTION AND DATA PROCESSING METHOD THEREOF
    17.
    发明申请
    TERMINAL DEVICE CAPABLE OF LINK LAYER ENCRYPTION AND DECRYPTION AND DATA PROCESSING METHOD THEREOF 有权
    能够连接层加密和解码的终端设备及其数据处理方法

    公开(公告)号:US20130283045A1

    公开(公告)日:2013-10-24

    申请号:US13995641

    申请日:2011-06-17

    IPC分类号: H04L29/06 H04L9/08

    摘要: There are a terminal device capable of link layer encryption and decryption and a data process method thereof, and the terminal device includes a link layer processing module including a control module, a data frame encryption module, a data frame decryption module, a key management module, an algorithm module, a transmission port and a reception port; and the control module is connected with the transmission port through the data frame encryption module, the reception port is connected with the control module through the data frame decryption module, the control module is connected with the key management module, the data frame encryption module is connected with the data frame decryption module through the key management module, and the data frame encryption module is connected with the data frame decryption module through the algorithm module.

    摘要翻译: 存在能够进行链路层加密和解密的终端设备及其数据处理方法,并且终端设备包括链路层处理模块,该链路层处理模块包括控制模块,数据帧加密模块,数据帧解密模块,密钥管理模块 算法模块,传输端口和接收端口; 控制模块通过数据帧加密模块与传输端口连接,接收端口通过数据帧解密模块与控制模块连接,控制模块与密钥管理模块连接,数据帧加密模块为 通过密钥管理模块与数据帧解密模块相连,数据帧加密模块通过算法模块与数据帧解密模块连接。

    SWITCH EQUIPMENT AND DATA PROCESSING METHOD FOR SUPPORTING LINK LAYER SECURITY TRANSMISSION
    18.
    发明申请
    SWITCH EQUIPMENT AND DATA PROCESSING METHOD FOR SUPPORTING LINK LAYER SECURITY TRANSMISSION 有权
    用于支持链路层安全传输的交换机设备和数据处理方法

    公开(公告)号:US20130283044A1

    公开(公告)日:2013-10-24

    申请号:US13995593

    申请日:2011-06-17

    IPC分类号: H04L29/06 H04L9/08

    摘要: A switch equipment and data processing method for supporting link layer security transmission are provided. The switch equipment for supporting link layer security transmission comprises a switch module and multiple port modules, each port module is electrically connected with the switch module respectively; the port module supports a link layer key management capability, and is used for establishing a share key for encrypting and decrypting data frames between the switch equipment and other network nodes.

    摘要翻译: 提供了用于支持链路层安全传输的交换机设备和数据处理方法。 用于支持链路层安全传输的交换机设备包括交换机模块和多个端口模块,每个端口模块分别与交换机模块电连接; 端口模块支持链路层密钥管理功能,用于建立共享密钥,用于加密和解密交换机设备与其他网络节点之间的数据帧。

    METHOD AND SYSTEM FOR AUTHENTICATING ENTITY BASED ON SYMMETRIC ENCRYPTION ALGORITHM
    19.
    发明申请
    METHOD AND SYSTEM FOR AUTHENTICATING ENTITY BASED ON SYMMETRIC ENCRYPTION ALGORITHM 有权
    基于对称加密算法认证实体的方法和系统

    公开(公告)号:US20130212390A1

    公开(公告)日:2013-08-15

    申请号:US13879619

    申请日:2010-12-22

    IPC分类号: H04L9/32

    CPC分类号: H04L9/32 H04L9/3271 H04W12/06

    摘要: A method and a system for authenticating an entity based on a symmetric encryption algorithm are provided. The method includes the following steps: 1) an entity A sends an authentication request message to an entity B; 2) after receiving the authentication request message, the entity B sends an authentication response message to the entity A; 3) the entity A determines the validity of the entity B according to the received authentication response message. The implementation cost of the system can be reduced by using the authentication according to the invention.

    摘要翻译: 提供了一种基于对称加密算法认证实体的方法和系统。 该方法包括以下步骤:1)实体A向实体B发送认证请求消息; 2)接收到认证请求报文后,实体B向实体A发送认证响应消息; 3)实体A根据收到的认证响应消息确定实体B的有效性。 通过使用根据本发明的认证可以减少系统的实现成本。

    Method and system for authenticating entity based on symmetric encryption algorithm
    20.
    发明授权
    Method and system for authenticating entity based on symmetric encryption algorithm 有权
    基于对称加密算法认证实体的方法和系统

    公开(公告)号:US09450756B2

    公开(公告)日:2016-09-20

    申请号:US13879619

    申请日:2010-12-22

    IPC分类号: H04L9/32 H04W12/06

    CPC分类号: H04L9/32 H04L9/3271 H04W12/06

    摘要: A method and a system for authenticating an entity based on a symmetric encryption algorithm are provided. The method includes the following steps: 1) an entity A sends an authentication request message to an entity B; 2) after receiving the authentication request message, the entity B sends an authentication response message to the entity A; 3) the entity A determines the validity of the entity B according to the received authentication response message. The implementation cost of the system can be reduced by using the authentication according to the invention.

    摘要翻译: 提供了一种基于对称加密算法认证实体的方法和系统。 该方法包括以下步骤:1)实体A向实体B发送认证请求消息; 2)接收到认证请求报文后,实体B向实体A发送认证响应消息; 3)实体A根据收到的认证响应消息确定实体B的有效性。 通过使用根据本发明的认证可以减少系统的实现成本。