首页> 外国专利> COMMUNITY OF INTEREST-BASED SECURED COMMUNICATIONS OVER IPSEC

COMMUNITY OF INTEREST-BASED SECURED COMMUNICATIONS OVER IPSEC

机译:IPSEC上基于兴趣的安全通信社区

摘要

A method and system for establishing secure communications between endpoints includes transmitting a first message including a token having one or more entries each corresponding to a community of interest associated with a user of the first endpoint and including an encryption key and a validation key associated with the first endpoint. The method includes receiving a second message including a second authorization token including one or more entries, each entry corresponding to a community of interest associated with a second user and including an encryption key and a validation key associated with the second endpoint. The method includes, for each community of interest associated with both users, decrypting an associated entry in the second authorization token to obtain the encryption key and validation key associated with the second endpoint. The method also includes generating a shared secret based on the key pair, transmitting a third message including the created key pair to the second endpoint, and initializing tunnel using the shared secret to derive encryption keys used for IPsec-secured communications between the endpoints.
机译:一种用于在端点之间建立安全通信的方法和系统,包括发送第一消息,该第一消息包括令牌,该令牌具有一个或多个条目,每个条目对应于与第一端点的用户相关联的兴趣社区,并且包括与该端点相关联的加密密钥和验证密钥。第一个端点。该方法包括接收第二消息,该第二消息包括第二授权令牌,该第二授权令牌包括一个或多个条目,每个条目对应于与第二用户相关联的关注社区并且包括与第二端点相关联的加密密钥和验证密钥。该方法包括,对于与两个用户相关联的每个兴趣社区,解密第二授权令牌中的相关条目,以获得与第二端点相关联的加密密钥和验证密钥。该方法还包括:基于密钥对生成共享秘密;将包括创建的密钥对的第三消息发送到第二端点;以及使用共享秘密初始化隧道,以导出用于端点之间的IPsec安全通信的加密密钥。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号