Security Architecture for Device Encryption and VPN
Ammar Alkassar, Michael Scheibel, Michael Stübel, Ahmad‐Reza Sadeghi, Marcel Winandy · Vieweg eBooks · 2007
Encryption systems are widely used to protect stored and communicated data from unauthorized access. Unfortunately, most software-based encryption products suffer from various vulnerabilities such as insecure storage and usage capabilities for security-critical cryptographic keys and operations. In this paper we present a security architecture that allows secure, reliable and user-friendly encryption of devices and of TCPIIP communication. The architecture is capable of using Trusted Computing functionalities and offers a security level which is comparable to a hardware based solution, but is far more cost-effective. We have already implemented a device encryption system and a VPN client. Moreover, the security architecture is an appropriate basis for many applications such as Enterprise Rights Management (ERM) and secure Online Banking. These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves.