HAIPE

HAIPE

A HAIPE (High Assurance Internet Protocol Encryptor) is a Type 1 encryption device that complies with the National Security Agency's HAIPE IS (formerly the HAIPIS, the High Assurance Internet Protocol Interoperability Specification). The cryptography used is Suite A and Suite B, also specified by the NSA as part of the Cryptographic Modernization Program. HAIPE IS is based on IPsec with additional restrictions and enhancements. One of these enhancements includes the ability to encrypt multicast data using a "preplaced key" (see definition in List of cryptographic key types). This requires loading the same key on all HAIPE devices that will participate in the multicast session in advance of data transmission. A HAIPE is typically a secure gateway that allows two enclaves to exchange data over an untrusted or lower-classification network.

Examples of HAIPE devices include
* L-3 Communication's [http://www.l-3com.com/HAIPE L-3 HAIPE] ] [http://www.l-3com.com/HAIPE HAIPE]
** KG-245X 10Gbit/s,
** KG-245A fully-tactical 1 Gbit/s, and
** KG-240A fully-ruggedized 100 Mbit/s
** KOV-26 [http://www.l-3com.com/Talon L-3 Talon] ] [http://www.l-3com.com/Talon Talon]
* [http://www.viasat.com/government-communications/information-assurance ViaSat's AltaSec Products] [http://www.viasat.com/government-communications/information-assurance/altasec-kg-250 ViaSat AltaSec KG-250] ]
** [http://www.viasat.com/government-communications/information-assurance/altasec-kg-250 KG-250] [http://www.viasat.com/government-communications/information-assurance/altasec-kg-250 ViaSat AltaSec KG-250] ] , and
** KG-255 [1 Gbit/s] [http://www.viasat.com/files/assets/KG-255_datasheet_014.pdf ViaSat KG-255 Datasheet] ]
* General Dynamics' [http://www.gdc4s.com/content/detail.cfm?item=f3f0ef4c-cced-46b2-937e-69c42fd1fe3b TACLANE Encryptor (KG-175)] ] TACLANE KG-175.

These devices use the current HAIPE IS version 1.3.5, which has a couple of notable limitations: no support for routing protocols or open network management. A HAIPE is an IP encryption device, looking up the destination IP address of a packet in its internal Security Association Database (SAD) and picking the encrypted tunnel based on the appropriate entry. For new communications, HAIPEs use the internal Security Policy Database (SPD) to set up new tunnels with the appropriate algorithms and settings. By not supporting routing protocols the HAIPEs must be preprogrammed with static routes and cannot adjust to changing network topology. While manufacturers support centralized management of their devices through proprietary software [ [http://www.viasat.com/government-communications/information-assurance/viasat-ine-manager-software-vine ViaSat's VINE website] ] [ [http://www.gdc4s.com/content/detail.cfm?item=45b9abed-a178-486e-908b-28f858754155 General Dynamics's GEM website] ] , the current devices offer no management functionality through open protocols or standards. Both of these limitations are due to be addressed in HAIPE IS version 3.0 due to be accredited in late 2008, but that date has slipped multiple times.Fact|date=April 2008 Both the HAIPE IS v3 management and HAIPE device implementations are required to be compliant to the HAIPE IS version 3.0 common MIBs. Assurance of cross vendor interoperability may require additional effort. An example of a management application that supports HAIPE IS v3 is the [http://www.l-3com.com/HAIPE Common HAIPE Manager] ] [http://www.l-3com.com/HAIPE Common HAIPE Manager] .

A couple of new HAIPE devices will combine the functionality of a router and encryptor when HAIPE IS version 3.0 is approved. General Dynamics has completed its TACLANE version (KG-175R), which house both a red and a black Cisco router, and both ViaSat and L-3 Communications are coming out with a line of network encryptors at version 3.0 and above. Cisco has dropped its plans for producing its own HAIPE device.Fact|date=March 2008

There is a UK HAIPE variant that implements UKEO algorithms in place of US Suite A. EADS has entered the HAIPE market in the UK with its Ectocryp range [http://www.cogent-dsn.com/news_frame.php?tb=5&artid=34 EADS Defence & Security Systems Ltd. wins prestigious secure communications award for encryption innovation] ] . Ectocryp Blue is HAIPE version 3.0 compliant and provides a number of the HAIPE extensions as well as support for network quality of service (QoS). Harris has also entered the UK HAIPE market with the BID/2370 End Cryptographic Unit (ECU) [http://www.rfcomm.harris.com/products/embeddable-security/chimp.pdf Harris UK BID/2370 ECU] ] .

In addition to site encryptors HAIPE is also being inserted into client devices that provide both wired and wireless capabilities. Examples of these include L-3 Communication's KOV-26 [http://www.l-3com.com/cs-east/ia/talon/ie_ia_talon.shtml Talon] and [http://www.l-3com.com/cs-east/ia/smeped/ie_ia_smeped.shtml Guardian] SME-PED, and Harris's [http://www.rfcomm.harris.com/products/embeddable-security/ Harris KIV-54] ] KIV-54 and PRC-117G [http://www.rfcomm.harris.com/117G/ Harris PRC-117G] ] radio .

Sources

[http://www.cnss.gov/Assets/pdf/CNSSP-19.pdf CNSS Policy #19 governing the use of HAIPE]

References

* Cryptography
* NSA encryption systems


Wikimedia Foundation. 2010.

Игры ⚽ Поможем сделать НИР

Look at other dictionaries:

  • HAIPE — High Assurance Internet Protocol Encryptor (Governmental » Military) High Assurance Internet Protocol Encryptor (Computing » Software) High Assurance Internet Protocol Encryptor (Computing » Networking) …   Abbreviations dictionary

  • NSA encryption systems — The National Security Agency took over responsibility for all U.S. Government encryption systems when it was formed in 1952. The technical details of most NSA approved systems are still classified, but much more about its early systems has become …   Wikipedia

  • KIV-7 — The KIV 7 is a National Security Agency type 1 encryptor and was originally designed in the mid 1990s by AlliedSignal Corporation to meet the demand for secure data communications from personal computers (PC), workstations, and FAXs. It has data… …   Wikipedia

  • BATON — For other uses, see baton. Infobox block cipher name = BATON caption = designers = National Security Agency publish date = derived from = derived to = key size = 320 bits (160 effective) block size = 128 bits structure = rounds = cryptanalysis =… …   Wikipedia

  • Solomon Mutswairo — Solomon Mangwiro Mutswairo (born April 26, 1924) is a Zimbabwean novelist and poet. A member of the Zezuru people of central Zimbabwe, Mutswairo wrote the first novel in the Shona language, Feso. Feso, originally published in Zezuru in 1957 (when …   Wikipedia

  • Cryptographic Modernization Program — The Cryptographic Modernization Program is a Department of Defense directed, NSA Information Assurance Directorate led effort to transform and modernize Information Assurance capabilities for the 21st century. It has three phases: Replacement All …   Wikipedia

  • безопасный протокол для связи и взаимодействия — Используется для связи в режиме секретности, обеспечивает шифрование и компрессию голоса, а также поддерживает спецификацию HAIPE IS (High Assurance Internet Protocol Encryptor Interoperability Specification) для доступа в SIPRNet.… …   Справочник технического переводчика

Share the article and excerpts

Direct link
Do a right-click on the link above
and select “Copy Link”