Ads

Boosting Embedded Application Security PDF Print E-mail
Monday, 11 July 2005
To accommodate the security needs of developers building embedded applications for defense systems and network equipment, Mentor GraphicsAccelerated Technology has added theIPv6 IPSec protocol into its Nucleus RTOS.
According to Robert Day, director of marketing, Accelerated Technology Division, Mentor Graphics, the IPsec software has been configured to seamlessly integrate with the IPv4 layer and IPv6 layer of the Nucleus NET TCP/IP stack. "This eliminates the need to modify other layers of the open system interconnection (OSI) model data link, transport and applications layers," he said.

Protection mechanisms provided by the Nucleus IPsec software are data origin authentication, data integrity, data confidentiality, anti-replay protection and limited traffic flow confidentiality.

The IPSec add-in also includes administrative application programming interfaces (APIs), that will allow applications to manipulate the association and policy databases, affecting how traffic flows are protected as well as creating/ destroying IPsec tunnels.

A management information database (MIB) is provided with the Nucleus IPsec software, allowing for remote configuration and monitoring of the IPsec module.

To accommodate the requirements of different embedded designs, the IPsec software comes with a wide variety of authentication and encryption algorithms. In addition, it includes support for the Internet key exchange (IKE) protocol, which is used to establish dynamic, on-the-fly associations between two IP nodes discarding the need for manual keying.

The Nucleus IPsec software is fully conformant with the Internet Engineering Task Force(IETF) IPsec specifications, ensuring inter-operability with other implementations.

To help achieve a high level of conformance and inter-operability, Day said the IPsec software has been tested against Ixias Automate Network Validation Library (ANVL), which contains almost 500 test cases for IPsec/IKE alone, as well as tested against FreeBSD, Windows XP, Windows 2003 Server and Feudora Linux.
 
< Prev   Next >