发明名称 SECURITY ENFORCEMENT POINT INSPECTION OF ENCRYPTED DATA IN AN ENCRYPTED END-TO-END COMMUNICATIONS PATH
摘要 Embodiments of the present invention address deficiencies of the art in respect to security function processing of encrypted data in a security enforcement point and provide a method, system and computer program product for security enforcement point inspection of a traversing encrypted data in a secure, end-to-end communications path. In an embodiment of the invention, a method for security enforcement point inspection of encrypted data in a secure, end-to-end communications path can be provided. The method can include establishing a persistent secure session with a key server holding an SA for an end-to-end secure communications path between endpoints, receiving the SA for the end-to-end secure communications path over the persistent secure session, decrypting an encrypted payload for the end-to-end secure communications path using session key data in the SA, and performing a security function on the decrypted payload.
申请公布号 US2008263356(A1) 申请公布日期 2008.10.23
申请号 US20070738500 申请日期 2007.04.22
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 OVERBY LINWOOD H.
分类号 H04L9/00 主分类号 H04L9/00
代理机构 代理人
主权项
地址