Content deleted Content added
→HAIPE managers: fixed misspelling of proprietary |
|||
(2 intermediate revisions by 2 users not shown) | |||
Line 1:
{{Short description|Encryption device}}
{{multiple issues|
{{cleanup|date=March 2012}}
Line 4 ⟶ 5:
{{refimprove |date= February 2008}}
}}
{{Use mdy dates|date=March 2025}}
A '''High Assurance Internet Protocol Encryptor''' ('''HAIPE''') is a [[Type 1 encryption]] device that complies with the [[National Security Agency]]'s HAIPE IS (formerly the HAIPIS, the High Assurance Internet Protocol Interoperability Specification). The [[cryptography]] used is [[NSA Suite A Cryptography|Suite A]] and [[NSA Suite B|Suite B]], also specified by the NSA as part of the [[Cryptographic Modernization Program]]. HAIPE IS is based on [[IPsec]] with additional restrictions and enhancements. One of these enhancements includes the ability to encrypt [[multicast]] data using a "preplaced key" (see definition in [[List of cryptographic key types]]). This requires loading the same key on all HAIPE devices that will participate in the multicast session in advance of data transmission. A HAIPE is typically a secure gateway that allows two enclaves to exchange data over an untrusted or lower-classification network.
==Examples==
Examples of HAIPE devices include:
* [[L3Harris Technologies]]' Encryption Products<ref>[https://www2.l3t.com/cs-east/what-we-do/products/encryption-products_red-eagle.htm L-3 Communication Encryption Products]</ref>
Line 19 ⟶ 22:
** 10G (KG-175X)
** Nano (KG-175N)
* Airbus Defence & Space ECTOCRYP Transparent Cryptography<ref>{{Cite web |url=http://www.cassidian.com/pl/web/guest/1307 |title=Ectocrypt Blue by Cassidian, an EADS Company |access-date=
Three of these devices are compliant to the HAIPE IS v3.0.2 specification while the remaining devices use the HAIPE IS version 1.3.5, which has a couple of notable limitations: limited support for [[routing protocols]] or open [[network management]].
Line 29 ⟶ 32:
There is a UK HAIPE variant that implements UKEO algorithms in place of US Suite A. Cassidian has entered the HAIPE market in the UK with its Ectocryp range. Ectocryp Blue is HAIPE version 3.0 compliant and provides a number of the HAIPE extensions as well as support for network [[quality of service]] (QoS). Harris has also entered the UK HAIPE market with the BID/2370 End Cryptographic Unit (ECU).<ref>[https://www.harris.com/press-releases/2008/12/next-generation-bid-2370-device-developed-under-uk-ministry-of-defence-chimp Harris UK BID/2370 ECU]</ref>
In addition to site encryptors HAIPE is also being inserted into client devices that provide both wired and wireless capabilities. Examples of these include L3Harris Technologies' KOV-26 Talon and KOV-26B Talon2, and Harris Corporation's KIV-54 <ref>{{Cite web |url=http://rf.harris.com/media/secnet54_emod_tcm26-9219.pdf |title=Harris KIV-54 (SECNET 54) |access-date=
== HAIPE managers ==
Viasat and General Dynamics Mission Systems both develop their own proprietary software for managing HAIPE devices, VINE and GEM One, respectively. The GEM One specifications list support for the Viasat HAIPEs, KG-250X and KG-250XS while the data sheet for VINE only lists supported Viasat Network Encryptors.<ref name="VINE Data Sheet">{{cite web |title=VINE Data Sheet |url=https://www.viasat.com/content/dam/us-site/government/documents/VINE_datasheet_040_web.pdf |website=Viasat.com |access-date=
Both the HAIPE IS v3 management and HAIPE device implementations are required to be compliant to the HAIPE IS version 3.0 common MIBs. Assurance of cross vendor interoperability may require additional effort. An example of a management application that supports HAIPE IS v3 is the L3Harris Common HAIPE Manager (which only operates with L3Harris products).{{Citation Needed|date=June 2022}}
Line 44 ⟶ 47:
== External links ==
* [http://www.cnss.gov/Assets/pdf/CNSSP-19.pdf CNSS Policy #19 governing the use of HAIPE] {{Webarchive|url=https://web.archive.org/web/20080513042825/http://www.cnss.gov/Assets/pdf/CNSSP-19.pdf |date=
[[Category:Cryptographic protocols]]
|