发明名称 End-to-end network security with traffic visibility
摘要 End-to-end security between clients and a server, and traffic visibility to intermediate network devices, achieved through combined mode, single pass encryption and authentication using two keys is disclosed. In various embodiments, a combined encryption-authentication unit includes a cipher unit and an authentication unit coupled in parallel to the cipher unit, and generates an authentication tag using an authentication key in parallel with the generation of the cipher text using an encryption key, where the authentication and encryption key have different key values. In various embodiments, the cipher unit operates in AES counter mode, and the authentication unit operates in parallel, in AES-GMAC mode Using a two key, single pass combined mode algorithm preserves network performance using a limited number of HW gates, while allowing an intermediate device access to the encryption key for deciphering the data, without providing that device the ability to compromise data integrity, which is preserved between the end to end devices.
申请公布号 EP2068526(B1) 申请公布日期 2014.04.30
申请号 EP20080253608 申请日期 2008.11.05
申请人 INTEL CORPORATION 发明人 LONG, MEN;WALKER, JESSE;DURHAM, DAVID;MILLIER, MARC;GREWAL, KARANVIR;DEWAN, PRASHANT;SAVAGAONKAR, UDAY;WILLIAMS, STEVEN D
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址