会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 3. 发明申请
    • A SYSTEM AND METHOD FOR ESTABLISHING MUTUAL REMOTE ATTESTATION IN INTERNET PROTOCOL SECURITY (IPSEC) BASED VIRTUAL PRIVATE NETWORK (VPN)
    • 一种用于建立基于互联网协议安全(IPSEC)的虚拟私有网络(VPN)中的互联远程监控的系统和方法
    • WO2013081441A1
    • 2013-06-06
    • PCT/MY2012/000160
    • 2012-06-28
    • MIMOS BERHADNORAZAH, Abd, AzizSHARIPAH, SetapaMOHD, Aminudin, Mohd, KhalidKILAUSURIA, Abdullah
    • NORAZAH, Abd, AzizSHARIPAH, SetapaMOHD, Aminudin, Mohd, KhalidKILAUSURIA, Abdullah
    • H04L29/06G06F21/00
    • H04L63/0823H04L63/164
    • The system and method of the present invention proposes an extension to the IPSec key exchange protocol by establishing properties-based attestation using key management service. The present invention protects integrity between network encryptor of sender-receiver/gateway to gateway platform machine by measuring properties which bundles with IPSec based VPN network. The system of the present invention comprising at least one sender and receiver platform; IPsec components extension; a plurality of properties of remote attestation modules (600); at least one signer mechanism (602); and at least one TPM (604). The methodology of the present invention establishes mutual remote attestation in IPSec based VPN by obtaining at least one key management service (KeyMS) measurement value to configure each KeyMS in VPN (102); establishing attestation in KeyMS session (104); signing Encapsulation Security Protocol (ESP) Authentication header (AH) packet with TPM certificate (106); appending signature to ESP and/or AH payload (108) and validating attestation data between gateways through trusted third party (110).
    • 本发明的系统和方法通过使用密钥管理服务建立基于属性的认证来提出对IPSec密钥交换协议的扩展。 本发明通过测量与基于IPSec的VPN网络捆绑的属性来保护发送器 - 接收器/网关的网络加密器与网关平台机器之间的完整性。 本发明的系统包括至少一个发送器和接收器平台; IPsec组件扩展; 远程证明模块的多个属性(600); 至少一个签名机构(602); 和至少一个TPM(604)。 本发明的方法通过获得至少一个密钥管理服务(KeyMS)测量值来在VPN(102)中配置每个密钥管理系统,在基于IPSec的VPN中建立相互远程认证; 在KeyMS会议(104)中建立认证; 签名具有TPM证书的封装安全协议(ESP)认证报头(AH)报文(106); 将签名附加到ESP和/或AH有效载荷(108),并通过可信第三方(110)验证网关之间的证明数据。