EP0436799B1

Communication network with key distribution

Abstract

This record has no abstract on file.

EP0436799B1, drawing sheet 1
Sheet 1 of 3

Term

Term ended

Expired 10 November 2010, 15.9 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

9 claims: 9 independent, 0 dependent

  1. 1
    Communication network intended for secure transmission of information, including different types of subscriber terminals (10-15) and switching modules (4-6), where subscriber lines connect each subscriber terminal with a switching module and transmission links connect each switching module to other switching modules in the network, and where the network further comprises crypto devices to undertake encryption-/decryption of information transmitted through the network, characterized in this that at least one of the crypto devices is constituted by a crypto-pool device (7,8,9) having a number of encrypting/decrypting units based on enciphering keys - crypto modules (CM) -, said crypto-pool device (7,8,9) being physically separated from an associated switching module (4,5,6), but interconnected with said associated switching module through standardized interface and communication protocols which make the device accessible from network equipment such as subscriber terminals and other switching modules, each crypto-pool device (7,8,9;20) being provided with a managing device (MA, 26) for communicating with a ciphering key distribution authority through standardized communication protocols and distributing keys to the relevant crypto module (CM) through a control path (25) of the crypto-pool. Kommunikationsnetzwerk, das für eine sichere Übertragung von Informationen bestimmt ist und verschiedene Arten von Teilnehmeranschlüssen (10 bis 15) und Schaltmodulen (4 bis 6) enthält, wobei Teilnehmeranschlußleitungen jeden Teilnehmeranschluß mit einem Schaltmodul und Übertragungsleitungen jedes Schaltmodul mit anderen Schaltmodulen in dem Netzwerk verbinden und wobei das Netzwerk des weiteren Verschlüsselungsgeräte zur Verschlüsselung/Entschlüsselung der durch das Netzwerk übertragenen Informationen umfaßt, dadurch gekennzeichnet, daß mindestens eines der Verschlüsselungsgeräte von einem Verschlüsselungspool-Gerät (7, 8, 9) gebildet wird, das eine Reihe von Verschlüsselungs-/Entschlüsselungseinheiten hat, die auf Chiffrierschlüssel-Verschlüsselungsmodulen (CM) basieren, wobei das Verschlüsselungspool-Gerät (7, 8, 9) von einem zugehörigen Schaltmodul (4, 5, 6) physisch getrennt, aber mit dem zugehörigen Schaltmodul über standardisierte Schnittstellen- und Übertragungsprotokolle verbunden ist, die den Zugriff auf das Gerät von Netzwerkeinheiten wie beispielsweise Teilnehmeranschlüssen und anderen Schaltmodulen ermöglichen, wobei jedes Verschlüsselungspool-Gerät (7, 8, 9;20) mit einer Verwaltungseinrichtung (MA, 26) ausgestattet ist, um mit einer Chiffrierschlüssel-Verteilungsinstanz über standardisierte Übertragungsprotokolle zu kommunizieren und um über einen Steuerpfad (25) des Verschlüsselungspools Schlüssel an das relevante Verschlüsselungsmodul (CM) zu verteilen. Réseau de transmission destiné à des transmissions d'information sécurisées, comprenant différents types de terminaux d'abonnés (10-15) et modules de commutation (4-6), avec des lignes d'abonné reliant chaque terminal d'abonné à un module de commutation et des liaisons de transmission reliant chaque module de commutation à d'autres modules de commutation dans le réseau, le réseau comprenant en outre des dispositifs de cryptophonie pour assurer le codage/décodage des informations transmises à travers le réseau, caractérisé en ce que au moins un des dispositifs de cryptophonie se compose d'un dispositif de pool de cryptophonie (7, 8, 9) possédant un certain nombre d'unités de codage/décodage s'articulant autour de clés de chiffrement - modules de cryptophonie (MC) - ledit dispositif de cryptophonie (7, 8, 9) étant séparé physiquement d'un module de commutation associé (4, 5, 6) mais relié audit module de commutation associé (4, 5, 6) à travers des protocoles d'interface et de communication standardisés qui rendent le dispositif accessible à partir d'équipements de réseau tels des terminaux d'abonnés et d'autres modules de commutation, chaque dispositif de pool de cryptophonie (7, 8, 9 ;20) étant muni d'un dispositif de gestion (GC, 26) pour communiquer avec une autorité de distribution de clés de chiffrement à travers des protocoles de communication standardisés et distribuer des clés au module de cryptophonie (MC) pertinent à travers un chemin de commande (25) du pool de cryptophonie.
  2. 2
    Network according to claim 1, characterized in this that each crypto-pool device has access to an authentication server (AS, 16;41,43) providing a directory of security certificates necessary in the authentication process and encryption key exchange, when initiating a network connection. Netzwerk nach Anspruch 1, dadurch gekennzeichnet, daß jedes Verschlüsselungspool-Gerät Zugriff auf einen Berechtigungszuweisungs-Server (AS, 16;41, 43) hat, der ein Verzeichnis von Sicherheitszertifikaten zur Verfügung stellt, die im Berechtigungszuweisungsprozeß und beim Austausch von Chiffrierschlüsseln notwendig sind, wenn eine Netzwerkverbindung eingeleitet wird. Réseau selon la revendication 1, caractérisé en ce que chaque dispositif de pool de cryptophonie peut accéder à un serveur d'authentification (SA, 16 ;41, 43) fournissant un répertoire de certificats de sécurité nécessaires au processus d'authentification et aux échanges de clés de codage lors de l'établissement d'une liaison réseau.
  3. 3
    Network according to claim 1, characterized in this that the crypto-pool devices (44,45) are arranged in a public ISDN environment (Fig. 3) having a number of ISPABX switches (31,32). Netzwerk nach Anspruch 1, dadurch gekennzeichnet, daß die Verschlüsselungspool-Geräte (44, 45) in einer Umgebung eines öffentlichen ISDN (Fig. 3), das eine Reihe von ISPABX-Vermittlungsstellen (31, 32) hat, angeordnet sind. Réseau selon la revendication 1, caractérisé en ce que le dispositif de pool de cryptophonie (44, 45) est disposé dans un environnement de RNIS public (figure 3) présentant un certain nombre d'autocommutateurs privés à intégration de services (31, 32).
  4. 4
    Network according to claim 1, characterized in this that the crypto-pool device (44,45) may be activated both from a subscriber terminal (35,36,40) without security module and from a subscriber terminal (34,38) with security module (46,47). Netzwerk nach Anspruch 1, dadurch gekennzeichnet, daß das Verschlüsselungspool-Gerät (44, 45) sowohl von einem Teilnehmeranschluß (35, 36, 40) ohne Sicherheitsmodul als auch von einem Teilnehmeranschluß (34, 38) mit Sicherheitsmodul (46, 47) aktiviert werden kann. Réseau selon la revendication 1, caractérisé en ce que le dispositif de pool de cryptophonie (44, 45) peut être activé à partir d'un terminal d'abonné (35, 36, 40) sans module de sécurité et également à partir d'un terminal d'abonné (34, 38) avec un module de sécurité (46, 47).
  5. 5
    Network according to claim 1, characterized in this that the crypto-pool device (44,45) may be activated directly by an attached PABX switch or ISPABX switch, so that the subscriber terminals are not aware of the crypto-pool device usage. Netzwerk nach Anspruch 1, dadurch gekennzeichnet, daß das Verschlüsselungspool-Gerät (44, 45) direkt von einer angeschlossenen PABX-Vermittlungsstelle oder einer ISPABX-Vermittlungsstelle aktiviert werden kann, so daß den Teilnehmeranschlüssen die Verwendung des Verschlüsselungspool-Geräts nicht bekannt ist. Réseau selon la revendication 1, caractérisé en ce que le dispositif de pool de cryptophonie (44, 45) peut être activé directement par un autocommutateur privé ou par un autocommutateur privé à intégration de services rattaché, de sorte que les terminaux d'abonnés n'ont pas connaissance de l'exploitation du dispositif de pool de cryptophonie.
  6. 6
    Network according to claim 3, characterized in this that the crypto-pool device (44,45) may be activated directly by the subscriber terminal (33,34,37,38) having a security module (52,46,53,47) through the authentication servers (AS,41,43) which is attached to the same ISPABX switch as the available crypto-pool device. Netzwerk nach Anspruch 3, dadurch gekennzeichnet, daß das Verschlüsselungspool-Gerät (44, 45) von dem Teilnehmeranschluß (33, 34, 37, 38), der ein Sicherheitsmodul (52, 46, 53, 47) hat, durch die Berechtigungszuweisungs-Server (AS, 41, 43), die mit derselben ISPABX-Vermittlungsstelle wie das zur Verfügung stehende Verschlüsselungspool-Gerät verbunden sind, direkt aktiviert werden kann. Réseau selon la revendication 3, caractérisé en ce que le dispositif de pool de cryptophonie (44, 45) peut être activé par le terminal d'abonné(33, 34, 37, 38) muni d'un module de sécurité (52, 46, 53, 47) par l'intermédiaire du serveur d'authentification (SA, 41, 43) qui est rattaché au même autocommutateur privé à intégration de services que le dispositif de pool de cryptophonie disponible.
  7. 7
    Network according to claim 3, characterized in this that the crypto-pool device (44,45) may be activated indirectly by accessing an ISPABX switch service through an end-to-end D-channel or a dedicated B-channel. Netzwerk nach Anspruch 3, dadurch gekennzeichnet, daß das Verschlüsselungspool-Gerät (44, 45) indirekt aktiviert werden kann, indem über einen Endpunkt-zu-Endpunkt-D-Kanal oder einen zugeordneten B-Kanal auf einen Dienst einer ISPABX-Vermittlungsstelle zugegriffen wird. Réseau selon la revendication 3, caractérisé en ce que le dispositif de pool de cryptophonie (44, 45) peut être activé indirectement en accédant à un service d'autocommutateur privé à intégration de services à travers une voie D de bout en bout ou une voie B dédiée.
  8. 8
    Network according to claim 3, characterized in this that the standardized communication channels (bearer services) which can be handled by a crypto module (CM) are a B-channel at a rate of 64 kbi/sec, an H0-channel at a rate of 384 kbi/sec corresponding to six B-channels, an H11-channel at a rate of 1536 kbi/sec corresponding to 24 B-channels, and an H12-channel at a rate of 1920 kbi/sec corresponding to 30 B-channels. Netzwerk nach Anspruch 3, dadurch gekennzeichnet, daß es sich bei den standardisierten Übertragungskanälen (Trägerkanaldiensten), die von einem Verschlüsselungsmodul (CM) bearbeitet werden können, um einen B-Kanal mit einer Übertragungsgeschwindigkeit von 64 Kbit/Sek., einen H0-Kanal mit einer Übertragungsgeschwindigkeit von 384 Kbit/Sek., was 6 B-Kanälen entspricht, einen H11-Kanal mit einer Übertragungsgeschwindigkeit von 1536 Kbit/Sek., was 24 B-Kanälen entspricht, und einen H12-Kanal mit einer Übertragungsgeschwindigkeit von 1920 Kbit/Sek., was 30 B-Kanälen entspricht, handelt. Réseau selon la revendication 3, caractérisé en ce que les voies de transmission standardisées (services support) pouvant être prises en charge par un module de cryptophonie (MC) sont les suivantes :une voie B à une vitesse de 64 kbits/sec, une voie H0 à une vitesse de 384 kbits/sec correspondant à 6 voies B, une voie H11 à une vitesse de 1536 kbits/sec correspondant à 24 voies B, et une voie H12 à une vitesse de 1920 kbits/sec correspondant à 30 voies B.
  9. 9
    Network according to claim 1, characterized in this that a non-secure subscriber terminal (35) can communicate with a secure subscriber terminal(38) through a crypto-pool device (44) without any weakening of existing security, as the secure subscriber terminal (38) and the crypto-pool device (44) will authenticate each other and exchange session encryption keys. Netzwerk nach Anspruch 1, dadurch gekennzeichnet, daß ein nichtsicherer Teilnehmeranschluß (35) mit einem sicheren Teilnehmeranschluß (38) über ein Verschlüsselungspool-Gerät (44) kommunizieren kann, ohne die vorhandene Sicherheit zu beeinträchtigen, da der sichere Teilnehmeranschluß (38) und das Verschlüsselungspool-Gerät (44) einander eine Berechtigung erteilen und Sitzungs-Chiffrierschlüssel austauschen. Réseau selon la revendication 1, caractérisé en ce qu'un terminal d'abonné non sécurisé (35) peut communiquer avec un terminal d'abonné sécurisé (38) à travers un dispositif de pool de cryptophonie (44) sans le moindre affaiblissement de la sécurité existante, du fait que le terminal d'abonné sécurisé (38) et le dispositif de pool de cryptophonie (44) s'authentifieront mutuellement et feront un échange de clés de codage de session.