首页> 外国专利> A SYSTEM AND METHOD FOE ESTABLISHING MUTUAL REMOTE ATTESTATION IN INTERNET PROTOCOL SECURITY (IPSEC) BASED VIRTUAL PRIVATE NETWORK (VPN)

A SYSTEM AND METHOD FOE ESTABLISHING MUTUAL REMOTE ATTESTATION IN INTERNET PROTOCOL SECURITY (IPSEC) BASED VIRTUAL PRIVATE NETWORK (VPN)

机译:建立基于互联网协议安全性(ipsec)的虚拟专用网(VPN)中的相互远程联系的系统和方法

摘要

THE SYSTEM AND METHOD OF THE PRESENT INVENTION PROPOSES AN EXTENSION TO THE IPSEC KEY EXCHANGE PROTOCOL BY ESTABLISHING PROPERTIES-BASED ATTESTATION USING KEY MANAGEMENT SERVICE. THE PRESENT INVENTION PROTECTS INTEGRITY BETWEEN NETWORK ENCRYPTOR OF SENDER-RECEIVER/GATEWAY TO GATEWAY PLATFORM MACHINE BY MEASURING PROPERTIES WHICH BUNDLES WITH IPSEC BASED VPN NETWORK. THE SYSTEM OF THE PRESENT INVENTION COMPRISING AT LEAST ONE SENDER AND RECEIVER PLATFORM; IPSEC COMPONENTS EXTENSION; A PLURALITY OF PROPERTIES OF REMOTE ATTESTATION MODULES (600); AT LEAST ONE SIGNER MECHANISM (602); AND AT LEAST ONE TPM (604). THE METHODOLOGY OF THE PRESENT INVENTION ESTABLISHES MUTUAL REMOTE ATTESTATION IN IPSEC BASED VPN BY OBTAINING AT LEAST ONE KEY MANAGEMENT SERVICE (KEYMS) MEASUREMENT VALUE TO CONFIGURE EACH KEYMS IN VPN (102); ESTABLISHING ATTESTATION IN KEYMS SESSION (104); SIGNING ENCAPSULATION SECURITY PROTOCOL (ESP) AUTHENTICATION HEADER (AH) PACKET WITH TPM CERTIFICATE (106); APPENDING SIGNATURE TO ESP AND AH PAYLOAD (108) AND VALIDATING ATTESTATION DATA BETWEEN GATEWAYS THROUGH TRUSTED THIRD PARTY (110). THE MOST ILLUSTRATIVE DRAWING IS FIG. 1.
机译:本发明的系统和方法通过使用密钥管理服务建立基于属性的指示来提议对IPSEC密钥交换协议的扩展。本发明通过利用基于IPSEC的VPN网络测量捆绑的属性来保护发送方/网关的网络加密器到网关平台机器之间的完整性。本发明的系统包括至少一个发送方和接收方平台; IPSEC组件扩展;远程兴趣模块的多个属性(600);至少有一个签​​名者机制(602);并至少达到1 TPM(604)。通过获得至少一个密钥管理服务(KEYMS)测量值来配置VPN中的每个密钥,本发明的方法论在基于IPSEC的VPN中建立了相互远程通知(102);在KEYMS会议中建立兴趣(104);使用TPM证书签署封装安全协议(ESP)认证标头(AH)包(106);将签名附加到ESP和AH有效负载(108)上,并通过可信第三方验证网关之间的吸引力数据(110)。最具说明性的图是图。 1。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号