×

TERMINAL DEVICE CAPABLE OF LINK LAYER ENCRYPTION AND DECRYPTION AND DATA PROCESSING METHOD THEREOF

  • US 20130283045A1
  • Filed: 06/17/2011
  • Published: 10/24/2013
  • Est. Priority Date: 12/20/2010
  • Status: Active Grant
First Claim
Patent Images

1. A terminal device capable of link layer encryption and decryption, wherein the terminal device comprises a link layer processing module comprising a control module, a data frame encryption module, a data frame decryption module, a key management module, an algorithm module, a transmission port and a reception port;

  • and the control module is connected with the transmission port through the data frame encryption module, the reception port is connected with the control module through the data frame decryption module, the control module is connected with the key management module, the data frame encryption module is connected with the data frame decryption module through the key management module, and the data frame encryption module is connected with the data frame decryption module through the algorithm module, and wherein;

    the control module is capable of strategy management and control;

    the key management module is capable of link layer key management and creates a shared key between the terminal device and another terminal device in a network and/or between the terminal device and a switch device in the network in response to a strategy demand of the control module and is responsible for performing management operations of storage, update or deletion on key; and

    the created shared key is pre-shared or negotiated about upon successful identity authentication of the terminal device with another terminal device or the switch device;

    upon reception of user data to be sent, the data frame encryption module interacts with the key management module to obtain a corresponding key and then invokes the algorithm module to thereby encrypt the user data to obtain a cipher-text of the user data, constructs a link layer encrypted data frame and sends the link layer encrypted data frame via the transmission port;

    upon reception of a data frame via the reception port, the data frame decryption module interacts with the key management module to obtain a corresponding key and then invokes the algorithm module to thereby decrypt the data frame to obtain plaintext information of user data and submits the plaintext information to a higher layer through the control module; and

    the algorithm module relates to an encryption algorithm and/or an integrity check algorithm.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×