首页> 外国专利> A SYSTEM AND METHOD FOR ESTABLISHING MUTUAL REMOTE ATTESTATION IN INTERNET PROTOCOL SECURITY (IPSEC) BASED VIRTUAL PRIVATE NETWORK (VPN)

A SYSTEM AND METHOD FOR ESTABLISHING MUTUAL REMOTE ATTESTATION IN INTERNET PROTOCOL SECURITY (IPSEC) BASED VIRTUAL PRIVATE NETWORK (VPN)

机译:建立基于互联网协议安全性(ipsec)的虚拟专用网(VPN)中的相互远程联系的系统和方法

摘要

The system and method of the present invention proposes an extension to the IPSec key exchange protocol by establishing properties-based attestation using key management service. The present invention protects integrity between network encryptor of sender-receiver/gateway to gateway platform machine by measuring properties which bundles with IPSec based VPN network. The system of the present invention comprising at least one sender and receiver platform; IPsec components extension; a plurality of properties of remote attestation modules (600); at least one signer mechanism (602); and at least one TPM (604). The methodology of the present invention establishes mutual remote attestation in IPSec based VPN by obtaining at least one key management service (KeyMS) measurement value to configure each KeyMS in VPN (102); establishing attestation in KeyMS session (104); signing Encapsulation Security Protocol (ESP) Authentication header (AH) packet with TPM certificate (106); appending signature to ESP and/or AH payload (108) and validating attestation data between gateways through trusted third party (110).
机译:本发明的系统和方法通过使用密钥管理服务建立基于属性的证明来提出对IPSec密钥交换协议的扩展。本发明通过测量与基于IPSec的VPN网络捆绑在一起的属性来保护发送者-接收者/网关的网络加密器与网关平台机器之间的完整性。本发明的系统包括至少一个发送器和接收器平台; IPsec组件扩展;远程认证模块的多个属性(600);至少一个签名机构(602);和至少一个TPM(604)。本发明的方法通过获得至少一个密钥管理服务(KeyMS)测量值来配置VPN中的每个KeyMS,在基于IPSec的VPN中建立相互远程认证(102);在KeyMS会话中建立证明(104);用TPM证书签署封装安全协议(ESP)身份验证标头(AH)数据包(106);将签名附加到ESP和/或AH有效载荷(108),并通过可信第三方验证网关之间的证明数据(110)。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号