Knowledge (XXG)

High Assurance Internet Protocol Encryptor

Source 📝

238: 136: 33: 74: 512:
Both the HAIPE IS v3 management and HAIPE device implementations are required to be compliant to the HAIPE IS version 3.0 common MIBs. Assurance of cross vendor interoperability may require additional effort. An example of a management application that supports HAIPE IS v3 is the
508:
Viasat and General Dynamics Mission Systems both develop their own propriety software for managing HAIPE devices, VINE and GEM One, respectively. The GEM One specifications list support for the Viasat HAIPEs, KG-250X and KG-250XS while the data sheet for VINE only lists supported Viasat
471:
in its internal Security Association Database (SAD) and picking the encrypted tunnel based on the appropriate entry. For new communications, HAIPEs use the internal Security Policy Database (SPD) to set up new tunnels with the appropriate algorithms and settings. Due to lack of support for modern
491:
There is a UK HAIPE variant that implements UKEO algorithms in place of US Suite A. Cassidian has entered the HAIPE market in the UK with its Ectocryp range. Ectocryp Blue is HAIPE version 3.0 compliant and provides a number of the HAIPE extensions as well as support for network
396:). This requires loading the same key on all HAIPE devices that will participate in the multicast session in advance of data transmission. A HAIPE is typically a secure gateway that allows two enclaves to exchange data over an untrusted or lower-classification network. 499:
In addition to site encryptors HAIPE is also being inserted into client devices that provide both wired and wireless capabilities. Examples of these include L3Harris Technologies' KOV-26 Talon and KOV-26B Talon2, and Harris Corporation's KIV-54 and PRC-117G radio.
455:
Three of these devices are compliant to the HAIPE IS v3.0.2 specification while the remaining devices use the HAIPE IS version 1.3.5, which has a couple of notable limitations: limited support for
479:
A couple of new HAIPE devices will combine the functionality of a router and encryptor when HAIPE IS version 3.0 is approved. General Dynamics has completed its TACLANE version (KG-175R), which house both
255: 99: 46: 806: 52: 655: 484:
Cisco router, and both ViaSat and L-3 Communications are coming out with a line of network encryptors at version 3.0 and above. Cisco is partnering with
302: 200: 274: 172: 627: 281: 179: 288: 186: 381: 270: 168: 667: 339: 321: 219: 117: 60: 157: 150: 751: 801: 434: 393: 723: 259: 782: 602: 295: 193: 579: 568: 89: 546: 522: 248: 146: 698: 373: 365: 631: 368:'s HAIPE IS (formerly the HAIPIS, the High Assurance Internet Protocol Interoperability Specification). The 527: 557: 388:
with additional restrictions and enhancements. One of these enhancements includes the ability to encrypt
403: 590: 95: 84: 496:(QoS). Harris has also entered the UK HAIPE market with the BID/2370 End Cryptographic Unit (ECU). 493: 485: 461: 481: 457: 361: 644: 786: 674: 473: 468: 795: 369: 412:
KG-245A fully tactical 1 Gbit/s (HAIPE IS v3.1.2 and Foreign Interoperable)
377: 237: 135: 467:
A HAIPE is an IP encryption device, looking up the destination IP address of a
779: 606: 513:
L3Harris Common HAIPE Manager (which only operates with L3Harris products).
389: 472:
commercial routing protocols the HAIPEs often must be preprogrammed with
17: 702: 420: 409:
KG-245X 10 Gbit/s (HAIPE IS v3.1.2 and Foreign Interoperable),
385: 752:"GEM One Encryptor Manager - General Dynamics Mission Systems" 231: 129: 67: 26: 451:
Airbus Defence & Space ECTOCRYP Transparent Cryptography
262:. Unsourced material may be challenged and removed. 476:and cannot adjust to changing network topology. 392:data using a "preplaced key" (see definition in 603:"Ectocrypt Blue by Cassidian, an EADS Company" 8: 271:"High Assurance Internet Protocol Encryptor" 169:"High Assurance Internet Protocol Encryptor" 807:National Security Agency encryption devices 591:General Dynamics TACLANE Encryptor (KG-175) 380:, also specified by the NSA as part of the 61:Learn how and when to remove these messages 780:CNSS Policy #19 governing the use of HAIPE 354:High Assurance Internet Protocol Encryptor 340:Learn how and when to remove this message 322:Learn how and when to remove this message 220:Learn how and when to remove this message 118:Learn how and when to remove this message 539: 156:Please improve this article by adding 558:ViaSat Information Assurance web page 547:L-3 Communication Encryption Products 7: 260:adding citations to reliable sources 628:"CASSIDIAN unveils ECTOCRYP YELLOW" 488:to propose a solution called SWAT1 399:Examples of HAIPE devices include: 382:Cryptographic Modernization Program 25: 42:This article has multiple issues. 668:"Harris KIV-54 (SECNET 54)" 630:. September 2013. Archived from 435:General Dynamics Mission Systems 236: 134: 98:has been specified. Please help 72: 31: 394:List of cryptographic key types 247:needs additional citations for 50:or discuss these issues on the 364:device that complies with the 1: 158:secondary or tertiary sources 384:. HAIPE IS is based on 645:Cisco Harris SWAT1 Solution 823: 523:ARPANET encryption devices 88:to meet Knowledge (XXG)'s 366:National Security Agency 802:Cryptographic protocols 656:Harris UK BID/2370 ECU 528:NSA encryption systems 406:' Encryption Products 145:relies excessively on 509:Network Encryptors. 404:L3Harris Technologies 756:gdmissionsystems.com 699:"Harris AN/PRC-117G" 423:'s AltaSec Products 256:improve this article 100:improve this article 785:2008-05-13 at the 494:quality of service 486:Harris Corporation 462:network management 724:"VINE Data Sheet" 482:a red and a black 458:routing protocols 437:TACLANE Products 362:Type 1 encryption 350: 349: 342: 332: 331: 324: 306: 230: 229: 222: 204: 128: 127: 120: 90:quality standards 81:This article may 65: 16:(Redirected from 814: 767: 766: 764: 762: 748: 742: 741: 739: 737: 728: 720: 714: 713: 711: 710: 701:. Archived from 695: 689: 688: 686: 685: 679: 673:. Archived from 672: 664: 658: 653: 647: 642: 636: 635: 624: 618: 617: 615: 614: 605:. Archived from 599: 593: 588: 582: 577: 571: 566: 560: 555: 549: 544: 345: 338: 327: 320: 316: 313: 307: 305: 264: 240: 232: 225: 218: 214: 211: 205: 203: 162: 138: 130: 123: 116: 112: 109: 103: 76: 75: 68: 57: 35: 34: 27: 21: 822: 821: 817: 816: 815: 813: 812: 811: 792: 791: 787:Wayback Machine 776: 771: 770: 760: 758: 750: 749: 745: 735: 733: 726: 722: 721: 717: 708: 706: 697: 696: 692: 683: 681: 677: 670: 666: 665: 661: 654: 650: 643: 639: 626: 625: 621: 612: 610: 601: 600: 596: 589: 585: 578: 574: 567: 563: 556: 552: 545: 541: 536: 519: 506: 346: 335: 334: 333: 328: 317: 311: 308: 265: 263: 253: 241: 226: 215: 209: 206: 163: 161: 155: 151:primary sources 139: 124: 113: 107: 104: 93: 77: 73: 36: 32: 23: 22: 15: 12: 11: 5: 820: 818: 810: 809: 804: 794: 793: 790: 789: 775: 774:External links 772: 769: 768: 743: 715: 690: 659: 648: 637: 634:on 2013-11-18. 619: 594: 583: 572: 561: 550: 538: 537: 535: 532: 531: 530: 525: 518: 515: 505: 504:HAIPE managers 502: 453: 452: 449: 448: 447: 446:Nano (KG-175N) 444: 441: 440:FLEX (KG-175F) 432: 431: 430: 427: 418: 417: 416: 413: 410: 348: 347: 330: 329: 244: 242: 235: 228: 227: 142: 140: 133: 126: 125: 96:cleanup reason 80: 78: 71: 66: 40: 39: 37: 30: 24: 14: 13: 10: 9: 6: 4: 3: 2: 819: 808: 805: 803: 800: 799: 797: 788: 784: 781: 778: 777: 773: 757: 753: 747: 744: 732: 725: 719: 716: 705:on 2008-09-30 704: 700: 694: 691: 680:on 2013-10-30 676: 669: 663: 660: 657: 652: 649: 646: 641: 638: 633: 629: 623: 620: 609:on 2013-11-07 608: 604: 598: 595: 592: 587: 584: 581: 580:ViaSat KG-255 576: 573: 570: 569:ViaSat KG-250 565: 562: 559: 554: 551: 548: 543: 540: 533: 529: 526: 524: 521: 520: 516: 514: 510: 503: 501: 497: 495: 489: 487: 483: 477: 475: 474:static routes 470: 465: 463: 459: 450: 445: 443:10G (KG-175X) 442: 439: 438: 436: 433: 428: 425: 424: 422: 419: 414: 411: 408: 407: 405: 402: 401: 400: 397: 395: 391: 387: 383: 379: 375: 371: 367: 363: 359: 355: 344: 341: 326: 323: 315: 312:February 2008 304: 301: 297: 294: 290: 287: 283: 280: 276: 273: –  272: 268: 267:Find sources: 261: 257: 251: 250: 245:This article 243: 239: 234: 233: 224: 221: 213: 202: 199: 195: 192: 188: 185: 181: 178: 174: 171: –  170: 166: 165:Find sources: 159: 153: 152: 148: 143:This article 141: 137: 132: 131: 122: 119: 111: 101: 97: 91: 87: 86: 79: 70: 69: 64: 62: 55: 54: 49: 48: 43: 38: 29: 28: 19: 759:. Retrieved 755: 746: 734:. Retrieved 730: 718: 707:. Retrieved 703:the original 693: 682:. Retrieved 675:the original 662: 651: 640: 632:the original 622: 611:. Retrieved 607:the original 597: 586: 575: 564: 553: 542: 511: 507: 498: 490: 478: 466: 454: 398: 370:cryptography 357: 353: 351: 336: 318: 309: 299: 292: 285: 278: 266: 254:Please help 249:verification 246: 216: 207: 197: 190: 183: 176: 164: 144: 114: 105: 82: 58: 51: 45: 44:Please help 41: 426:KG-250, and 102:if you can. 796:Categories 731:Viasat.com 709:2008-10-05 684:2013-11-18 613:2013-11-18 534:References 282:newspapers 210:March 2012 180:newspapers 147:references 108:March 2012 47:improve it 390:multicast 53:talk page 783:Archived 517:See also 460:or open 415:RedEagle 372:used is 83:require 761:19 June 736:19 June 429:KG-255 378:Suite B 374:Suite A 360:) is a 296:scholar 194:scholar 85:cleanup 18:TACLANE 469:packet 421:ViaSat 298:  291:  284:  277:  269:  196:  189:  182:  175:  167:  727:(PDF) 678:(PDF) 671:(PDF) 386:IPsec 358:HAIPE 303:JSTOR 289:books 201:JSTOR 187:books 763:2022 738:2022 376:and 275:news 173:news 258:by 149:to 94:No 798:: 754:. 729:. 464:. 352:A 160:. 56:. 765:. 740:. 712:. 687:. 616:. 356:( 343:) 337:( 325:) 319:( 314:) 310:( 300:· 293:· 286:· 279:· 252:. 223:) 217:( 212:) 208:( 198:· 191:· 184:· 177:· 154:. 121:) 115:( 110:) 106:( 92:. 63:) 59:( 20:)

Index

TACLANE
improve it
talk page
Learn how and when to remove these messages
cleanup
quality standards
cleanup reason
improve this article
Learn how and when to remove this message

references
primary sources
secondary or tertiary sources
"High Assurance Internet Protocol Encryptor"
news
newspapers
books
scholar
JSTOR
Learn how and when to remove this message

verification
improve this article
adding citations to reliable sources
"High Assurance Internet Protocol Encryptor"
news
newspapers
books
scholar
JSTOR

Text is available under the Creative Commons Attribution-ShareAlike License. Additional terms may apply.