Claims
- 1. In a packet switched network, a method for changing keys used for encrypted switched virtual circuit communication between a first Data Terminal Equipment (DTE) and a second DTE, said first and second DTE having an associated first and second encryption device, comprising the steps of:
- issuing a call request packet from said first DTE to said second DTE;
- intercepting said call request packet at said first encryption device and substituting a call request for a key management center;
- transferring a key from said key management center to said first DTE;
- balancing counters at a link associated with said first DTE and first encryption device using a dummy packet in order to make frame send and receive sequence numbers equal and packet send and receive sequence numbers equal;
- establishing a channel between said first and second data encrypters; and
- transferring a key from said first data encrypter to said second encrypter.
- 2. In a packet switched network, method for changing keys used for encrypted permanent virtual circuit communication between a first Data Terminal Equipment (DTE) and a second DTE, said first and second DTE having an associated first and second encryption device, comprising the steps of:
- issuing a call request packet from a key management center to said first encryption device;
- issuing a call request packet from said key management center to said second encryption device;
- from said key management center, sending a stop packet flow message from said first DTE to said second DTE and obtaining a last MAC from said first data encryption device and transferring a new key to said first data encryption device;
- from said key management center, sending a stop packet flow message from said second DTE to said first DTE and obtaining a last MAC from said second data encryption device and transferring a new key to said first data encryption device;
- from said key management center, sending a restart packet flow message to restart packet flow between said first and second DTE; and
- balancing link counters at said first and second links by transmission of dummy packets in order to make frame send and receive sequence numbers equal and packet send and receive sequence numbers equal.
Parent Case Info
This is a divisional of copending application U.S. Ser. No. 305,672 filed on 2/3/89, now U.S. Pat. No. 4,965,804, issued 10/23/1990.
US Referenced Citations (4)
Number |
Name |
Date |
Kind |
4182933 |
Rosenblum |
Jan 1980 |
|
4578531 |
Everhart et al. |
Mar 1986 |
|
4607137 |
Jansen et al. |
Aug 1986 |
|
4965804 |
Trbovich et al. |
Oct 1990 |
|
Non-Patent Literature Citations (2)
Entry |
The Cipher X 5000 Product Brochure and Technical Reference Manual. |
The Dynapack Product Brochure. |
Divisions (1)
|
Number |
Date |
Country |
Parent |
305672 |
Feb 1989 |
|