发明名称 Out-of-band session key information exchange
摘要 A source device that plans to participate in one or more encrypted communication sessions with a destination device sends a discovery message towards the destination device. An intermediary device that processes this discovery message requests a master key from the source device. The source verifies that the intermediary device is a trusted device and then sends the intermediary device the requested master key. Prior to transmitting encrypted messages to the destination device, the source device sends session key information, encrypted using the master key, to the intermediary device. The intermediary device uses this session key information to decrypt and process encrypted messages sent as part of the encrypted communication session between the source device and the destination device.
申请公布号 US9197616(B2) 申请公布日期 2015.11.24
申请号 US201012727493 申请日期 2010.03.19
申请人 Cisco Technology, Inc. 发明人 Sinha Alok Kumar
分类号 H04L29/06 主分类号 H04L29/06
代理机构 Campbell Stephenson LLP 代理人 Campbell Stephenson LLP
主权项 1. A method comprising: prior to a protocol successfully establishing an encrypted communication session between a source device and a destination device, wherein the source device sends messages to the destination device as part of the encrypted communication session established between the source device and the destination device, wherein the destination device is configured to use session key information to decrypt encrypted payloads within the messages, wherein the encrypted payloads are encrypted by the source device and sent to the destination device by the source device as part of the encrypted communication session, wherein the encrypted payloads are sent to the destination device via an intermediary device, wherein the intermediary device is neither the source device nor the destination device: sending a discovery message from the source device to the destination device, wherein the discovery message indicates that the source device will be sending one or more messages comprising encrypted payloads to the destination device via a network;sending a master key from the source device to the intermediary device, subsequent to the sending the discovery message; andsending the session key information, encrypted using the master key, from the source device to the intermediary device, wherein the session key information is usable by the intermediary device to decrypt the encrypted payloads within a message in the encrypted communication session between the source device and the destination device.
地址 San Jose CA US