发明名称 Hitless manual cryptographic key refresh in secure packet networks
摘要 In a hitless manual cryptographic key refresh scheme, a state machine is independently maintained at each network node. The state machine includes a first state, a second state, and a third state. In the first state, which is the steady state, a current cryptographic key is used both for generating signatures for outgoing packets and for authenticating signatures of incoming packets. In the second state, which is entered when a new cryptographic key is provisioned, the old (i.e. formerly current) key is still used for generating signatures for outgoing packets, however one or, if necessary, both of the old key and the newly provisioned key is used for authenticating signatures of incoming packets. In the third state, the new key is used for generating signatures for outgoing packets and either one or both of the old key and new key are used for authenticating signatures of incoming packets.
申请公布号 US8082441(B2) 申请公布日期 2011.12.20
申请号 US20090482187 申请日期 2009.06.10
申请人 GAUVREAU RICHARD;AALDERS MICHAEL;EDWARDS KIM;NORTEL NETWORKS LIMITED 发明人 GAUVREAU RICHARD;AALDERS MICHAEL;EDWARDS KIM
分类号 H04L29/06;H04L9/00;H04L9/08;H04L9/32 主分类号 H04L29/06
代理机构 代理人
主权项
地址