Creation method of end-to-end shared key and system

A technology for sharing keys and establishing methods, which is applied in the field of communication network security applications, and can solve problems such as attacks on switching devices, complex network data communications, and reduced network transmission efficiency

Active Publication Date: 2010-09-22
CHINA IWNCOMM
View PDF4 Cites 6 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

This security measure brings a huge computational burden to the switching devices in the LAN, which is easy to cause attackers to attack the switching devices; and the delay of data packets from the sending node to the destination node will also increase, reducing network transmission. efficiency
[0004] The topology of wired LAN is relatively complex, and the number of nodes involved (here, terminals a...

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Creation method of end-to-end shared key and system
  • Creation method of end-to-end shared key and system

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0086] The node N (Node) in the present invention refers to a user terminal STA (STation) and a switching device SW (SWitch) in a wired LAN. Physical layer devices such as hubs in the LAN are not treated as nodes.

[0087] In the network, all switching devices and user terminals have established secure connections with the core switching devices in the network through pre-distribution or other security mechanisms, that is, they already have shared keys. The establishment mechanism of the assumed key is not limited or defined in the present invention. The core switching device in the present invention is generally the switching device closest to the gateway in the local area network, which can be specified or configured by the network administrator, and is not limited or defined in the present invention.

[0088] to send source node N Source with destination node N Destination The establishment of the shared key between Center It is the core switching device in the network....

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The invention relates to a creation method of an end-to-end shared key, which comprises the following steps that: 1) a transmission source node NSource ransmits a firs key negotiation request packet to a core switch device SWCenter; 2) after receiving the first key negotiation request packet, the core switch device SWCenter creates a second key negotiation request packet to a destination node NDestination; 3) after receiving the second key negotiation request packet, the destination node NDestination creates a second key negotiation response packet to be transmitted to the core switch device SWCenter; 4) after receiving the second key negotiation response packet, the core switch device SWCenter creates a first key negotiation response packet to be transmitted to the transmission source node NSource; 5) and after receiving the first key negotiation response packet, the transmistion source node NSource creates an end-to-end shared key. The creation method and the system have better security performance.

Description

technical field [0001] The invention relates to the application field of communication network security, in particular to a method and system for establishing an end-to-end shared key. Background technique [0002] The wired LAN is generally a broadcast network, and the data sent by one node can be received by other nodes. All nodes on the network share the channel, which brings great security risks to the network. As long as the attacker accesses the network to monitor, he can capture all the data packets on the network. [0003] The local area network LAN defined by the existing national standard GB / T 15629.3 (corresponding to IEEE 802.3 or ISO / IEC 8802-3) does not provide data security methods, which makes it easy for attackers to steal key information. In the field of international research, the IEEE 802.1AE standard developed by IEEE provides a data encryption protocol for protecting Ethernet, and adopts hop-by-hop encryption security measures to realize the safe tran...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
IPC IPC(8): H04L29/06H04L9/08
CPCH04L9/0827H04L63/06
Inventor 李琴曹军铁满霞葛莉
Owner CHINA IWNCOMM
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products