[comp.protocols.ibm] Ethernet Security Devices

X040BK@TAMVM1.BITNET (Butch Kemper) (05/06/88)

DEC has announced a product that provides network security.  The box
is called the "Digital Ethernet Secure Network Controller" or DESNC
and has a companion software product known as "VAX Key Distribution
Center" or VAX KDC.

The DESNC is attaches to the ethernet via a transceiver and has four
thinwire ethernet ports.  Client nodes attach to the TW ports.  To
quote DEC:

   "Together the DESNC controller and VAX KDC system implement a
    default access control policy that enables all nodes on a
    network to communicate with each other (after successful
    authentication). This allows for rapid integration of DESNC
    controllers and VAX KDC systems with minimal impact on existing
    network operatons.  Under this open policy, client nodes (i.e.,
    nodes connected to DESNC controllers) communicate with each
    other using encrypted frames on the network.  All other communication
    (i.e., client node-to-node, and node-to-node) is unencrypted
    (see example configuration below)."


    //=+=========+======+== ethernet =+=========+===================//
       |         |      |             |         |
       |         |      |             |         |
   --------- ---------  |         --------- ---------
   |       | |       |  |         |       | |       |
   | DESNC | | Node  |  |         | Node  | | DESNC |
   |       | |       |  |         |       | |       |
   --------- ---------  |         --------- ---------
       |                |                       |
       |                |                       |
   ---------        ---------               ---------
   | Client|        |  KDC  |               | Client|
   | Node  |        | DESNC |               | Node  |
   |       |        |       |               |       |
   ---------        ---------               ---------
                        |
                        |
                    ---------
                    |VAX KDC|
                    | Node  |
                    |       |
                    ---------


I have only see a sales document that announces the product but not
any detailed information.  So, call your friendly DEC salesperson.

Butch

estevax_b.UUCP (Hr Fuchs Norbert ) (05/20/88)

hi

	i have more questions about DECs product announcement: DESNC.
	i think the 'black box' must have the following hardware-design


	_________________________________________________
	|						|
	|		-----------------		|
	|		|		|		|
	|		| shared memory	|		|
	|		|		|		|
	|		-----------------		|
	|			x			|
	|     xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx	|
	|	x	    x	        x		|
	|   ---------   ---------   --------- 		|
	|   | 82586 |   | 80186 |   | 82586 | 		|
	|   ---------   ---------   ---------		|
	|	X			X		|
	--------X-----------------------X----------------
		X			X
	connected to LAN	connected to station

	it may be that the DESNC also have a speciall encryption-chip.

	who has information about the hardware design of the DESNC?
	how do the KDC communicate with the DESNC (e.g. data link service
	or transport service or ?)?
	which parts of the iso-protocol are encrypted?
	what is the price?

			norbert

Norbert Fuchs
Ultrasoft Co.
West-Germany

...!unido!estevax!estevax_b!ultra361