Policy based cryptographic key distribution for network group encryption

    公开(公告)号:US09948621B2

    公开(公告)日:2018-04-17

    申请号:US14717681

    申请日:2015-05-20

    IPC分类号: H04L9/08 H04L29/06

    摘要: Various embodiments include a method for managing a group of devices in communication with each other and sharing a set of keys. The method may include opening a secure channel with each of two devices from the group; providing the set of keys to the two devices from the group, wherein the set of keys include an encryption and an authentication key; indicating to the two devices to begin using the set of keys; and performing an audit process including verifying that nodes within a key group have the same copy of encryption and authentication keys. Embodiments of the method may include synchronization, active/standby redundancy and the ability to manage the network when some nodes perform the data encryption and some node do not, do, or when both encrypted and non-encrypted tunnels and services can work together.

    POLICY BASED CRYPTOGRAPHIC KEY DISTRIBUTION FOR NETWORK GROUP ENCRYPTION
    3.
    发明申请
    POLICY BASED CRYPTOGRAPHIC KEY DISTRIBUTION FOR NETWORK GROUP ENCRYPTION 有权
    网络组加密的基于策略的CRYPTOGRAPHIC关键分配

    公开(公告)号:US20160344711A1

    公开(公告)日:2016-11-24

    申请号:US14717681

    申请日:2015-05-20

    IPC分类号: H04L29/06

    摘要: Various embodiments include a method for managing a group of devices in communication with each other and sharing a set of keys. The method may include opening a secure channel with each of two devices from the group; providing the set of keys to the two devices from the group, wherein the set of keys include an encryption and an authentication key; indicating to the two devices to begin using the set of keys; and performing an audit process including verifying that nodes within a key group have the same copy of encryption and authentication keys. Embodiments of the method may include synchronization, active/standby redundancy and the ability to manage the network when some nodes perform the data encryption and some node do not, do, or when both encrypted and non-encrypted tunnels and services can work together.

    摘要翻译: 各种实施例包括用于管理彼此通信并共享一组密钥的一组设备的方法。 该方法可以包括从组中的两个设备中的每一个打开安全通道; 向组中的两个设备提供该组密钥,其中该组密钥包括加密和认证密钥; 指示两台设备开始使用该组密钥; 并且执行审核过程,包括验证密钥组中的节点具有相同的加密和认证密钥副本。 该方法的实施例可以包括同步,主动/备用冗余以及当一些节点执行数据加密时管理网络的能力,并且某些节点没有,或者当加密和非加密隧道和服务都可以一起工作时。