发明名称 Centralized secure offload of cryptographic security services for distributed security enforcement points
摘要 Embodiments of the present invention address deficiencies of the art in respect to network security and provide a method, system and computer program product for centralized secure offload of key exchange services for distributed security enforcement points. In one embodiment, a data processing system for centralized secure offload of key exchange services for distributed security enforcement points can be provided. The system can include a security enforcement point controlling communication flows between devices in different less trusted zones of protection, and a security server communicatively coupled to the security enforcement point and hosting key exchange services disposed in a more trusted zone of protection. The security enforcement point can include an interface to the key exchange services and program code enabled to offload at least one portion of a key exchange through the interface to the key exchange services disposed in the more trusted zone of protection.
申请公布号 US9137203(B2) 申请公布日期 2015.09.15
申请号 US200711626513 申请日期 2007.01.24
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 Gearhart Curtis M.;Meyer Christopher;Overby, Jr. Linwood H.;Wierbowski David J.
分类号 H04L29/06;G06F15/16 主分类号 H04L29/06
代理机构 Cuenot, Forsythe & Kim, LLC 代理人 Cuenot, Forsythe & Kim, LLC
主权项 1. A computer-implemented method within and by a security enforcement point located between a first zone of protection and a second zone of protection, comprising: controlling communication flows between a device in the first zone and a device in the second zone; performing a cryptographic security service on the communication flows; and offloading a portion of the cryptographic security service to a security server in a third zone of protection, wherein the third zone of protection is disposed separately from the first and second zones of protection anda higher zone of protection than the first and second zones of protection,wherein the security server is connected to a plurality of security enforcement points and the security enforcement points define the boundaries of the zones.
地址 Armonk NY US