发明名称 SECURE COMMUNICATION DEVICE AND METHOD
摘要 A security enhancement to IPSec processing is achieved by changing the algorithms used at each re-key after expiration or termination of a Security Association session between two peer nodes. The solution enables an Internet Key Exchange to negotiate multiple algorithms to ensure that every renewed IPSec Security Association has a different algorithm combination, thereby making attempts at decryption by an attacker more difficult.
申请公布号 US2016182463(A1) 申请公布日期 2016.06.23
申请号 US201414582133 申请日期 2014.12.23
申请人 Suram Chandra Sekhar;Deshpande Amruta;Vemulapalli Jyothi 发明人 Suram Chandra Sekhar;Deshpande Amruta;Vemulapalli Jyothi
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项 1. A method of managing Internet Protocol Security Associations between two nodes, wherein one of the two nodes acts as an initiator and the other of the two nodes acts as a responder in a Security Association (SA) process, the method comprising: providing local policies for configuring sets of algorithms at each node; at an initiator node, sending a message for initiating a first SA, wherein the message identifies the algorithms configured in the initiator node, receiving at a responder node, the message and in response, identifying a matching set of algorithms that are common to those configured in the responder and the initiator nodes; selecting a first algorithm combination from the matching set of algorithms to create a first SA, sending a list of negotiated combinations of algorithms comprising the selected first combination of algorithms and other matching combinations of algorithms to the initiator node, wherein both nodes use the first combination of algorithms to create the first SA and both store the negotiated combinations of algorithms for use by both first and second nodes subsequently; and on a rekey following termination of a SA, at the initiator node, selecting a further algorithm combination from the list of negotiated combinations of algorithms that is different from a previously selected algorithm combination for use by the responder and initiator in a further SA.
地址 Secunderabad IN