DocumentCode :
2593676
Title :
Design of a key agile cryptographic system for OC-12c rate ATM
Author :
Stevenson, Daniel ; Hillery, Nathan ; Byrd, Greg ; Gong, Fengmin ; Winkelstein, Dan
Author_Institution :
MCNC, Research Triangle Park, NC, USA
fYear :
1995
fDate :
16-17 Feb 1995
Firstpage :
17
Lastpage :
30
Abstract :
The paper describes an experimental key agile cryptographic system under design at MCNC. The system is compatible with ATM local- and wide-area networks. The system establishes and manages secure connections between hosts in a manner which is transparent to the end users and compatible with existing public network standards. A Cryptographic Unit supports hardware encryption and decryption at the ATM protocol layer. The system is SONET compatible and operates full duplex at the OC-12c rate (622 Mbps). Separate encryption keys are negotiated for each secure connection. Each Cryptographic Unit can manage more than 65,000 active secure connections. The Cryptographic Unit can be connected either in a security gateway mode referred to as a `bump-in-the-fiber´ or as a direct ATM host interface. Authentication and access control are implemented through a certificate-based system. The current status of the system is that hardware and software detail designs have been completed. An early version of the key management software has been completed and demonstrated. Hardware fabrication and systems integration are expected to take place over the next several months. Once completed the proof-of concept system will be used to explore issues of privacy, access control and authentication in relation to communications over emerging public networks
Keywords :
access protocols; asynchronous transfer mode; authorisation; local area networks; message authentication; public key cryptography; wide area networks; ATM local-area networks; ATM protocol layer; ATM wide-area network; OC-12c rate ATM; SONET compatible system; access control; authentication; certificate-based system; communication; cryptographic unit; direct ATM host interface; encryption keys; end users; hardware decryption; hardware encryption; hardware fabrication; key agile cryptographic system; privacy; public network standards; secure host connections; security gateway mode; systems integration; Access control; Authentication; Cryptographic protocols; Cryptography; Fabrication; Hardware; Privacy; SONET; Security; Software design;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Network and Distributed System Security, 1995., Proceedings of the Symposium on
Conference_Location :
San Diego, CA
Print_ISBN :
0-8186-7027-4
Type :
conf
DOI :
10.1109/NDSS.1995.390648
Filename :
390648
Link To Document :
بازگشت