Chapter 4 • Network security
1037852-0001 Revision A
35
Chapter 4
Network security
This chapter describes the data security features in the HX
System. These features guarantee data integrity and
confidentiality, and protect the network from intrusion and
external exploits. The following topics are presented:
•
Data encryption
on page 35
•
Network security features
on page 36
Data encryption
The HX System can employ several information assurance
techniques to safeguard the integrity and confidentiality of data
transported through the system. These techniques include:
•
DES-encrypted outbound channel
•
Two-way IPSec encryption
DES-encrypted outbound
channel
The outbound channel is encrypted using the data encryption
standard (DES) by the HX CAS (conditional access system)
feature. This CAS feature:
•
Is hardware-based
•
Ensures that traffic is received by satellite routers legally
•
Prevents unauthorized eavesdropping
The HX CAS feature assigns a unique key to each satellite router.
It is responsible for key management and for encrypting
outbound data to satellite routers to ensure that satellite routers
can only decrypt the data intended for them.
When a satellite router is commissioned, it requests its encrypted
effective master key (EEMK) from the HX gateway. This key is
sent to the satellite router, and then:
•
Used at the HX gateway to encrypt all data sent to the
satellite router
•
Used by the satellite router to decrypt all data received from
the HX gateway
Because all data transmissions to satellite routers are uniquely
keyed, a satellite router can decrypt only the data sent to it. The
EEMK is also used by satellite routers to authenticate themselves
to the HX gateway.
Two-way IPSec encryption
IPSec in the HX System is NIST for FIPS 140-2 level 1 certified
and has these characteristics:
Содержание HX System
Страница 1: ...1037852 0001 Revision A September 4 2008 HX System System Overview Release 1 2 7 ...
Страница 8: ... Contents viii 1037852 0001 Revision A ...
Страница 10: ... Figures x 1037852 0001 Revision A ...
Страница 12: ... Tables xii 1037852 0001 Revision A ...
Страница 24: ...Chapter 1 Overview 12 1037852 0001 Revision A ...
Страница 26: ...Chapter 2 Subsystems 14 1037852 0001 Revision A Figure 3 HX Subsystems and LAN Connections ...
Страница 40: ...Chapter 3 Network management 28 1037852 0001 Revision A Figure 4 Network management system and LAN connections ...
Страница 50: ...Chapter 4 Network security 38 1037852 0001 Revision A ...
Страница 62: ...Chapter 5 Bandwidth management 50 1037852 0001 Revision A ...
Страница 70: ...Chapter 6 IP features 58 1037852 0001 Revision A ...
Страница 80: ...Chapter 8 Transmission features 68 1037852 0001 Revision A ...
Страница 88: ...Chapter 10 HX options 76 1037852 0001 Revision A ...
Страница 96: ...Appendix B Transportable Gateway TGW 84 1037852 0001 Revision A ...
Страница 100: ... Acronyms and abbreviations 88 1037852 0001 Revision A ...
Страница 106: ... Index 94 1037852 0001 Revision A ...