首页> 外国专利> Communication device for implementing selective encryption in a software defined network

Communication device for implementing selective encryption in a software defined network

机译:用于在软件定义的网络中实现选择性加密的通信设备

摘要

The present disclosure pertains to systems and methods for selectively encrypting data flows within a software defined network (SDN). In one embodiment, a communication device may be configured to receive a plurality of unencrypted data packets. The communication device may receive from an SDN controller a criterion used to identify at least one of the unencrypted data flows to be encrypted. Based on the criterion, an encryption subsystem may generate an encrypted data flow the unencrypted data packets based on an encryption key. In some embodiments, the encryption system may parse the packets and encrypt the data payloads without encrypting the routing information associated with the packet. In other embodiments, the encryption subsystem may be configured to encapsulate and encrypt the entire unencrypted data packet. In some embodiments, the encryption subsystem may further be configured to authenticate a sending device and/or to verify the integrity of a message.
机译:本公开涉及用于选择性地对软件定义的网络(SDN)内的数据流进行加密的系统和方法。在一个实施例中,通信设备可以被配置为接收多个未加密的数据分组。通信设备可以从SDN控制器接收用于识别要加密的未加密数据流中的至少一个的标准。基于该准则,加密子系统可以基于加密密钥来生成未加密数据分组的加密数据流。在一些实施例中,加密系统可以解析分组并加密数据有效载荷,而无需加密与分组相关联的路由信息​​。在其他实施例中,加密子系统可以被配置为封装和加密整个未加密的数据分组。在一些实施例中,加密子系统可以进一步被配置为认证发送设备和/或验证消息的完整性。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号