1461146041-1b2350ca-ab6b-40cc-b2fb-b0a0fcf20c77

1. A slat ripper, comprising:
a hollow body comprising a longitudinal axis, a front end, a back end, a top wall, a bottom wall, two side walls, wherein each such wall has an inside and an outside face, and wherein the ends of the body are open, said hollow body having an internal portion defining a chamber of uniform cross-sectional geometry; and
cutting means comprising a cutting end and a non-cutting end fixedly disposed within the body chamber between and attached to the inside faces of the top wall and the bottom wall, wherein the cutting end of the cutting means is exposed only to the chamber;
wherein the cutting means further comprises material formed by cutting a right triangular slot into the back end of the top wall, wherein the cut wall material is bent inwards generally perpendicularly to the top wall and extends to the inner face of the bottom wall, and wherein the cut wall material is curved defining a curved portion cutting edge directed towards the front end, and wherein the cutting edge directed towards the front end is sharpened to form a blade.
2. The apparatus according to claim 1, wherein the body further comprises two U-shaped channels and means to fixedly attach one channel to the other.
3. The apparatus according to claim 2, wherein the uniform cross-sectional geometry is a rectangle.
4. The apparatus according to claim 3, wherein at least one slat from a plurality of uniformly sized slats is provided and the cross-sectional area of the chamber is sized slightly larger than the cross-sectional area of at least one slat of the slats provided wherein the apparatus can receive at least one slat within the inner wall faces along the chamber longitudinal axis of the apparatus.
5. The apparatus according to claim 4, wherein the apparatus is constructed of twenty gauge stainless steel.
6. The apparatus according to claim 5, wherein the means to fixedly attach one channel to the other further comprises two spot welds equidistantly spaced on each side wall wherein an outside face of one channel wall is thus welded to an inside face of the other channel wall to form one conjoined side, with the reverse relationship with respect to the respective inside-outside faces of the channel walls on the other conjoined side, and a spot weld attaching the curved portion of the cutting means to the inside face of the bottom wall.
7. The apparatus according to claim 6, wherein the slat hollow body further comprises an external height dimension of 0.5 inches, an external width dimension of 2.5 inches, an external length dimension of 4.0 inches, and the dimensions of the triangle provided by the slot are a hypotenuse of 1.25 inches, a height of \u215d inches, and a base of \u215e inches.
8. The apparatus according to claim 7, wherein the blade is located 1.5 inches from the outside face of one side wall.
9. The apparatus according to claim 6, wherein the slat hollow body further comprises an external height dimension of 0.5 inches, an external width dimension of 2{fraction (1516)} inches, an external length dimension of 4.0 inches, and the dimensions of the triangle provided by the slot are a hypotenuse of 1.25 inches, a height of \u215d inches, and a base of \u215e inches.
10. The apparatus according to claim 9, wherein the blade is located 1.5 inches from the outside face of one side wall.
11. The apparatus according to claim 1, wherein the apparatus is constructed from molded, high impact graphite.
12. A slat ripper, comprising:
a hollow body constructed of twenty gauge stainless steel comprising a longitudinal axis, a front end, a back end, a top wall, a bottom wall, two side walls, wherein each such wall has an inside and an outside face, wherein the ends of the body are open, and wherein the hollow body has an internal portion defining a chamber of uniform cross-sectional geometry, an external height dimension, an external width dimension, and an external length dimension;
a blade having a cutting edge and formed by cutting a right triangular slot into the back end of the top wall, wherein the cut wall material is bent inwards generally perpendicularly to the top wall and extends to the inner face of the bottom wall, wherein the cut wall material is curved defining a curved portion cutting edge is directed towards the front end; and wherein the blade is located 1.5 inches from the outside face of one side wall.
13. The apparatus of claim 12, wherein the hollow body further comprises an external height dimension of 0.5 inches, an external width dimension of 2.5 inches, an external length dimension of 4.0 inches, and the dimensions of the triangle provided by the slot are a hypotenuse of 1.25 inches, a height of \u215d inches, and a base of \u215e inches.
14. The apparatus of claim 12, wherein the hollow body further comprises an external height dimension of 0.5 inches, an external width dimension of 2{fraction (1516)} inches, an external length dimension of 4.0 inches, and the dimensions of the triangle provided by, the slot are a hypotenuse of 1.25 inches, a height of \u215d inches, and a base of \u215e inches.

The claims below are in addition to those above.
All refrences to claim(s) which appear below refer to the numbering after this setence.

1-6. (canceled)
7. A field retrofittable and reconfigurable lethal threat protection system for a vehicle for protecting an occupant in the vehicle from a lethal threat, the vehicle having an OEM windscreen for viewing out of a front of the vehicle, the OEM windscreen being mounted in a peripheral channel of an OEM windscreen frame surrounding the OEM windscreen, the peripheral channel extending into a front surface of the OEM windscreen frame and the OEM windscreen being mounted with OEM fasteners extending into OEM holes in the OEM windscreen frame, the lethal threat protection system comprising:
a ballistic resistant windscreen mounted in a frame adapted to be located in the peripheral channel;
armor caps extending around a periphery of the frame;
armor fasteners extending through the armor caps and into holes in the OEM windscreen frame other than the OEM holes, the armor fasteners, armor caps and the ballistic resistant windscreen being removable from the peripheral channel and permitting the OEM windscreen to be remounted in the peripheral channel by the OEM fasteners extending through the OEM holes.
8. The field retrofittable and reconfigurable lethal threat protection system of claim 7 the frame locates the ballistic resistant windscreen substantially forward of the front surface of the OEM windscreen frame.
9. The field retrofittable and reconfigurable lethal threat protection system of claim 7 wherein the armor caps comprising manufactured holes providing a drill guide for drilling holes for the armor fasteners in the OEM windscreen frame.
10-11. (canceled)
12. A field retrofittable and reconfigurable lethal threat protection system for protecting an occupant in a vehicle from a lethal threat, the vehicle having a pair of rear wheel wells and the occupant being positioned forward of the rear wheel wells, the lethal threat protection system comprising:
armor adapted to be attachable with fasteners to a lower most surface of one of the rear wheel wells exposed to an interior the vehicle, the armor extending upward adjacent a forward surface of the one of the rear wheel wells, the fasteners and the armor being removable from the one of the rear wheel wells.
13. The field retrofittable and reconfigurable lethal threat protection system of claim 12 wherein the armor extends rearward adjacent a side surface of the one of the rear wheel wells.
14. The field retrofittable and reconfigurable lethal threat protection system of claim 12 further comprising rear partition armor adapted to be connected with fasteners to the rear wheel wells, the rear partition armor extending in a first direction between the rear wheel wells and extending in a second upward direction from a location between the rear wheel wells, the rear partition armor comprising insulation extending over an area substantially equal to a forward directed area of the rear partition armor.
15. A field retrofittable and reconfigurable lethal threat protection system for a vehicle for protecting an occupant in the vehicle from a lethal threat, the vehicle having a forward portion in which the lower legs and feet of the occupant are positioned, the lethal threat protection system comprising:
armor adapted to be attachable with fasteners to the vehicle adjacent a forward surface of the forward portion in which the lower legs and feet of the occupant are positioned, the fasteners and the armor being removable from the vehicle.
16. The field retrofittable and reconfigurable lethal threat protection system of claim 15 wherein the armor is located on an outer forward side of the forward surface.
17. The field retrofittable and reconfigurable lethal threat protection system of claim 15 wherein the armor is located on an inner rearward side of the forward surface.
18-20. (canceled)
21. A method of attaching a field retrofittable and reconfigurable lethal threat protection system for a vehicle for protecting an occupant in the vehicle from a lethal threat, the vehicle having OEM components connected thereto with OEM fasteners using OEM holes in the vehicle, the method comprising:
removing, in the field, at least one of the OEM components;
drilling, in the field, fastener holes in the vehicle that do not overlap or interfere with the OEM holes;
mounting, in the field, with second fasteners and using the fastener holes a component of the lethal threat protection system that substitutes for the at one of the OEM components;
subsequently removing, in the field, the second fasteners and the component of the lethal threat protection system; and
thereafter reinstalling, in the field, the at least one of the OEM components using the OEM holes.

1461146029-191ad7c2-0122-4547-928c-c0b5eef69361

1-13. (canceled)
14. Granules for controlled release of Tamsulosin comprising: Tamsulosin and a carrier matrix, wherein the carrier matrix comprises:
a) 2 to 25% by weight of an alginate,
b) 30 to 70% weight of a macromolecular substance selected from the group consisting of: methacrylic acidethyl acrylate 1:1 copolymer, methacrylic acidmethyl methacrylate 1:1 copolymer, methacrylic acidmethyl methacrylate 1:2 copolymer, aminoalkyl methacrylate copolymer, vinyl acetatecrotonic acid copolymer, polyvinyl acetate phthalate, ethylene-vinyl acetate, cellulose acetate phthalate, hydroxypropylmethylcellulose, sodium carboxymethyl-cellulose, carrageenan, crosslinked chitosan, polyethylene-vinyl acetate, poly-L-lactic acid, xanthan gum, polyvinyl acetate and mixtures thereof, and
c) 10 to 50% by weight of a hydrophobic substance selected from the group consisting of: glycerol behenate, glyceryl monostearate, wax, mono-substituted glyceride, disubstituted glycerides, trisubstituted glycerides, calcium stearate, and mixtures thereof.
15. Granules as claimed in claim 14, wherein the macromolecular substance is methacrylic acidethyl acrylate 1:1 copolymer.
16. Granules as claimed in claim 14, wherein the hydrophobic substance is glycerol behenate.
17. Granules as claimed in claim 14, further comprising a binder selected from the group consisting of: maltodextrin, polyvinylpyrrolidone, pregelatinized starch, sodium starch glycolate, and mixtures thereof.
18. Granules as claimed in claim 14, further comprising a surface active agent selected from the group consisting of: sodium lauryl sulfate, poloxamer, polyoxyethylene stearate, polyoxyethylene castor oil derivatives, and mixtures thereof.
19. Granules as claimed in claim 14, further comprising a plasticizer selected from the group consisting of: condensation polymers of ethylene oxide and water, sorbitol oleic acid ester reacted with ethylene oxide, and anhydrides thereof, triethyl citrate, acetyl triethyl citrate, tributyl citrate, propylene glycol, diethyl phthalate, triacetin, acetyl tributyl citrate, dibutyl sebacate, and mixtures thereof.
20. Granules as claimed in claim 14, further comprising a pH-adjusting agent.
21. Granules as claimed in claim 14, further comprising an antifoam.
22. Granules as claimed in claim 14, further comprising a glidant.
23. Granules as claimed in claim 14, further comprising water.
24. Granules as claimed in claim 23, further comprising a solvent, wherein the solvent is selected from the group consisting of ethanol, isopropyl alcohol, and acetone.
25. Granules as claimed in claim 14, further comprising a mixture of water and a solvent.
26. Granules as claimed in claim 25, wherein the solvent is selected from the group consisting of ethanol, isopropyl alcohol and acetone.
27. Granules as claimed in claim 14, further comprising:
a) 0.15 to 0.35% by weight of Tamsulosin;
b) 6 to 8% by weight of sodium alginate;
c) 55 to 65% by weight of methacrylic acidethyl acrylate 1:1 copolymer;
d) 12 to 18% by weight of glycerol behenate;
e) 12 to 18% by weight of maltodextrin; and
f) 0 to 10% by weight of excipients.
28. A hard gelatin capsule comprising: granules for controlled release of Tamsulosin comprising: Tamsulosin and a carrier matrix, wherein the carrier matrix comprises:
a) 2 to 25% by weight of an alginate,
b) 30 to 70% by weight of a macromolecular substance selected from the group consisting of: methacrylic acidethyl acrylate 1:1 copolymer, methacrylic acidmethyl methacrylate 1:1 copolymer, methacrylic acidmethyl methacrylate 1:2 copolymer, aminoalkyl methacrylate copolymer, vinyl acetatecrotonic acid copolymer, polyvinyl acetate phthalate, ethylene-vinyl acetate, cellulose acetate phthalate, hydroxypropylmethylcellulose, sodium carboxymethylcellulose, carrageenan, crosslinked chitosan, polyethylene-vinyl acetate, poly-L-lactic acid, xanthan gum, polyvinyl acetate, and mixtures thereof, and
c) 10 to 50% by weight of a hydrophobic substance selected from the group consisting of: glycerol behenate, glyceryl monostearate, wax, monosubstituted glycerides, disubstituted glycerides, trisubstituted glycerides, calcium stearate, and mixtures thereof.
29. A process for producing granules comprising Tamsulosin, the process comprising:
a) mixing sodium alginate, a first part of a macromolecular substance, and a hydrophobic substance, resulting in a homogeneous powder mixture;
b) mixing water or a solvent, a second part of the macromolecular substance, and Tamsulosin, resulting in a homogeneous granulating liquid,
c) adding with vigorous stirring the homogeneous granulating liquid to the homogeneous powder mixture; and
d) drying the resulting granules.
30. The process as claimed in claim 29, wherein the homogeneous powder mixture is obtained by mixing the sodium alginate, the first part of the macromolecular substance, the hydrophobic substance, and a binder.
31. The process as claimed in claim 29, where the granulating liquid is obtained by performing the process comprising:
a) heating water or the solvent;
b) adding a plasticizer thereto and mixing,
c) cooling the solution obtained in this way and comprising the plasticizer;
d) mixing Tamsulosin and at least one surface-active agent, and adding to this mixture the second part of the macromolecular substance, mixing, and
e) adding the mixture obtained in the manner recited in process d) to the solution comprising the plasticizer obtained by the process recited in c).

The claims below are in addition to those above.
All refrences to claim(s) which appear below refer to the numbering after this setence.

1. A method of generating a cryptographic transform for use in a point-to-point secure communication session among a first node and a second node that are enrolled in a secure communication group, the method comprising the computer-implemented steps of:
receiving a group key for use in secure communication among members of the secure communications group that includes the first node and the second node, wherein the first node is seeking to initiate the secure point-to-point communication session within the secure communications group with the second node wherein the secure point-to-point communication session allows the first and the second node to communicate with each other privately with respect to other members of the secure communications group;
determining first and second nonce values as part of performing a first phase of Internet Key Exchange (IKE) among the first node and the second node to establish an Internet Security Association and Key Management Protocol (ISAKMP) security association (SA) wherein the first and second nodes comprise ISAKMP peers;
deriving, based on the group key and the first and second nonce values, a data-security session key for use in the secure point-to-point communication session by only the first node and the second node privately with respect to the other secure communications group members;
wherein the secure communications group comprises at least one node besides the first and second node, wherein the group key comprises a single group key that is common to all nodes of the secure communications group and wherein the deriving step is performed within the secure communications group by only each of the first and second nodes;
encrypting one or more data packets using the data-security session key; and
communicating the one or more data packets privately with respect to the other secure communications group members, to the second node as part of the secure communication session.
2. A method as recited in claim 1, further comprising the steps of:
receiving one or more policy data values in a Group Domain of Interpretation (\u201cGDOI\u201d) security association (\u201cSA\u201d) payload; and
encrypting one or more data packets using a keystream segment that is generated by providing the data-security session key and the one or more policy data values to a keystream generator function.
3. A method as recited in claim 2, wherein the security association payload comprises a GDOI SA traffic encryption key (\u201cTEK\u201d) payload.
4. A method as recited in claim 2, wherein the policy data values include a group key lifetime value, and wherein the steps of determining, deriving, encrypting and communicating are performed only when the group key is received within the group key lifetime value.
5. A method as recited in claim 2, wherein the policy data values include a group membership list, and wherein the steps of determining, deriving, encrypting and communicating are performed only when second node is identified within the group membership list.
6. A method as recited in claim 1, wherein the step of deriving the data-security session key comprises the steps of applying the group key and the first and second nonce values to a key derivation function, resulting in generating a data-security session key that is unique for a pair of peers consisting of the first node and the second node.
7. A method as recited in claim 6, wherein the key derivation function is a one-way hash function.
8. A method as recited in claim 1,
wherein the determining step comprises the steps of determining a first identity value of the first node, and determining a second identity value of the second node using a Tunnel Endpoint Detection (TED) probe; and
wherein the deriving step comprises the steps of deriving, based on the group key and the first and second identity values, a data-security session key for use in the secure point-to-point communication session.
9. A method as recited in claim 8, wherein the step of deriving the data-security session key comprises the steps of applying the group key and the first and second identity values to a key derivation function, resulting in generating a data-security session key that is unique for a pair of peers consisting of the first node and the second node.
10. A method as recited in claim 9, wherein the key derivation function is a one-way hash function.
11. A method as recited in claim 1,
wherein the determining step comprises the steps of determining a first IP address value that identifies the first node, and determining a second IP address value that identifies the second node using a Tunnel Endpoint Detection (TED) probe; and
wherein the deriving step comprises the steps of deriving, based on the group key and the first and second nonce values, a data-security session key for use in the secure point-to-point communication session.
12. A method as recited in claim 11, wherein the step of deriving the data-security session key comprises the steps of applying the group key and the first and second IP address values to a key derivation function, resulting in generating a data-security session key that is unique for a pair of peers consisting of the first node and the second node.
13. A method as recited in claim 12, wherein the key derivation function is a one-way hash function.
14. In a network comprising a key server and first and second nodes that are communicatively coupled to the key server, wherein the first and second nodes each have received a group key for use in a secure communication group that comprises a first node and the second node and have performed a determining step wherein were determined first and second nonce values as part of performing a first phase of Internet Key Exchange (IKE) among the first node and the second node, a method of generating a cryptographic transform for use to secure the communication session among the first node and the second node, the method comprising the computer-implemented steps of:
deriving, based on the group key and the first and second nonce values, a data-security session key for use in the secure point-to-point communication session between only the first node and the second node wherein the secure communications session allows the first and second node to communicate with each other within the secure communications group privately with respect to other members of the secure communications group wherein the first phase of the IKE establishes an Internet Security Association and Key Management Protocol (ISAKMP) security association (SA) wherein the first and second nodes comprise ISAKMP peers;
wherein the secure communications group comprises at least one node besides the first and second node, wherein the group key comprises a single group key that is common to all nodes of the secure communications group and wherein the deriving step is performed within the secure communications group by only each of the first and second nodes;
encrypting one or more data packets using the data-security session key; and
communicating the one or more data packets to the second node privately with respect to other members of the secure communications group as part of the secure communication session.
15. A method as recited in claim 14, further comprising the steps of:
receiving one or more policy data values in a Group Domain of Interpretation (\u201cGDOI\u201d) security association (\u201cSA\u201d) payload; and
encrypting one or more data packets using a keystream segment that is generated by providing the data-security session key and the one or more policy data values to a keystream generator function.
16. A method as recited in claim 15, wherein the security association payload comprises a GDOI SA traffic encryption key (\u201cTEK\u201d) payload.
17. A method as recited in claim 14, wherein the policy data values include a group key lifetime value, and wherein the steps of determining, deriving, encrypting and communicating are performed only when the group key is received within the group key lifetime value.
18. A method as recited in claim 14, wherein the policy data values include a group membership list, and wherein the steps of determining, deriving, encrypting and communicating are performed only when second node is identified within the group membership list.
19. A method as recited in claim 14, wherein the step of deriving the data-security session key comprises the steps of applying the group key and the first and second nonce values to a key derivation function, resulting in generating a data-security session key that is unique for a pair of peers consisting of the first node and the second node.
20. A method as recited in claim 19, wherein the key derivation function is a one-way hash function.
21. A method as recited in claim 14,
wherein the determining step comprises the steps of determining a first identity value of the first node, and determining a second identity value of the second node using a Tunnel Endpoint Detection (TED) probe; and
wherein the deriving step comprises the steps of deriving, based on the group key and the first and second identity values, a data-security session key for use in the secure point-to-point communication session.
22. A method as recited in claim 21, wherein the step of deriving the data-security session key comprises the steps of applying the group key and the first and second identity values to a key derivation function, resulting in generating a data-security session key that is unique for a pair of peers consisting of the first node and the second node.
23. A method as recited in claim 22, wherein the key derivation function is a one-way hash function.
24. A method as recited in claim 14,
wherein the determining step comprises the steps of determining a first IP address value that identifies the first node, and determining a second IP address value that identifies the second node using a Tunnel Endpoint Detection (TED) probe; and
wherein the deriving step comprises the steps of deriving, based on the group key and the first and second nonce values, a data-security session key for use in the secure point-to-point communication session.
25. A method as recited in claim 24, wherein the step of deriving the data-security session key comprises the steps of applying the group key and the first and second IP address values to a key derivation function, resulting in generating a data-security session key that is unique for a pair of peers consisting of the first node and the second node.
26. A method as recited in claim 25, wherein the key derivation function is a one-way hash function.
27. A computer-readable storage medium carrying one or more sequences of instructions for generating a cryptographic transform for use in a point-to-point secure communication session among a first node and a second node that are enrolled in a secure communication group, which instructions, when executed by one or more processors, cause the one or more processors to carry out a process comprising the steps of:
receiving a group key for use in secure communication among members of the secure communications group that includes the first node and the second node, wherein the first node is seeking to initiate the secure point-to-point communication session within the secure communications group with the second node wherein the secure point-to-point communication session allows the first and the second node to communicate with each other privately with respect to other members of the secure communications group;
determining first and second nonce values as part of performing a first phase of Internet Key Exchange (IKE) among the first node and the second node privately with respect to the other secure communications group members to establish a Internet Security Association and Key Management Protocol (ISAKMP) security association (SA) wherein the first and second nodes comprise ISAKMP peers;
deriving, based on the group key and the first and second nonce values, a data-security session key for use in the secure point-to-point communication session by only the first node and the second node privately with respect to the other secure communications group members;
wherein the secure communications group comprises at least one node besides the first and second node, wherein the group key comprises a single group key that is common to all nodes of the secure communications group and wherein the deriving step is performed within the secure communications group by only each of the first and second nodes;
encrypting one or more data packets using the data-security session key; and
communicating the one or more data packets privately with respect to the other secure communications group members, to the second node as part of the secure point-to-point communication session.
28. A computer-readable medium as recited in claim 27, wherein the process further comprises the steps of:
receiving one or more policy data values in a Group Domain of Interpretation (\u201cGDOI\u201d) security association (\u201cSA\u201d) payload; and
encrypting one or more data packets using a keystream segment that is generated by providing the data-security session key and the one or more policy data values to a keystream generator function.
29. A computer-readable medium as recited in claim 28, wherein the security association payload comprises a GDOI SA traffic encryption key (\u201cTEK\u201d) payload.
30. A computer-readable medium as recited in claim 28, wherein the policy data values include a group key lifetime value, and wherein the steps of determining, deriving, encrypting and communicating are performed only when the group key is received within the group key lifetime value.
31. A computer-readable medium as recited in claim 30, wherein the policy data values include a group membership list, and wherein the steps of determining, deriving, encrypting and communicating are performed only when second node is identified within the group membership list.
32. A computer-readable medium as recited in claim 27, wherein the step of deriving the data-security session key comprises the steps of applying the group key and the first and second nonce values to a key derivation function, resulting in generating a data-security session key that is unique for a pair of peers consisting of the first node and the second node.
33. A computer-readable medium as recited in claim 32, wherein the key derivation function is a one-way hash function.
34. A computer-readable medium as recited in claim 27,
wherein the determining step comprises the steps of determining a first identity value of the first node, and determining a second identity value of the second node using a Tunnel Endpoint Detection (TED) probe; and
wherein the deriving step comprises the steps of deriving, based on the group key and the first and second identity values, a data-security session key for use in the secure point-to-point communication session.
35. A computer-readable medium as recited in claim 34, wherein the step of deriving the data-security session key comprises the steps of applying the group key and the first and second identity values to a key derivation function, resulting in generating a data-security session key that is unique for a pair of peers consisting of the first node and the second node.
36. A computer-readable medium as recited in claim 35, wherein the key derivation function is a one-way hash function.
37. A computer-readable medium as recited in claim 27,
wherein the determining step comprises the steps of determining a first IP address value that identifies the first node, and determining a second IP address value that identifies the second node using a Tunnel Endpoint Detection (TED) probe; and
wherein the deriving step comprises the steps of deriving, based on the group key and the first and second nonce values, a data-security session key for use in the secure point-to-point communication session.
38. A computer-readable medium as recited in claim 37, wherein the step of deriving the data-security session key comprises the steps of applying the group key and the first and second IP address values to a key derivation function, resulting in generating a data-security session key that is unique for a pair of peers consisting of the first node and the second node.
39. A computer-readable medium as recited in claim 38, wherein the key derivation function is a one-way hash function.
40. An apparatus for generating a cryptographic transform for use in a point-to-point secure communication session among a first node and a second node that are enrolled in a secure communication group, comprising:
means for receiving a group key for use in secure communication among members of the secure communications group that includes the first node and the second node, wherein the first node is seeking to initiate the secure point-to-point communication session within the secure communications group with the second node wherein the secure point-to-point communication session allows the first and the second node to communicate with each other privately with respect to other members of the secure communications group;
means for determining first and second nonce values as part of performing a first phase of Internet Key Exchange (IKE) among the first node and the second node to establish an Internet Security Association and Key Management Protocol (ISAKMP) security association (SA) wherein the first and second nodes comprise ISAKMP peers;
means for deriving, based on the group key and the first and second nonce values, a data-security session key for use in the secure point-to-point communication session by only the first node and the second node privately with respect to the other secure communications group members;
wherein the secure communications group comprises at least one node besides the first and second node, wherein the group key comprises a single group key that is common to all nodes of the secure communications group and wherein the deriving means function within the secure communications group in only each of the first and second nodes;
means for encrypting one or more data packets using the data-security session key; and
means for communicating the one or more data packets to the second node privately with respect to the other secure communications group members as part of the secure communication session.
41. The apparatus as recited in claim 40, further comprising:
means for receiving one or more policy data values in a Group Domain of Interpretation (GDOI) security association (SA) payload; and
means for encrypting one or more data packets using a keystream segment that is generated by providing the data-security session key and the one or more policy data values to a keystream generator function.
42. The apparatus as recited in claim 41, wherein at least one of:
the security association payload comprises a GDOI SA traffic encryption key (TEK) payload; and
the policy data values comprise at least one of:
a group key lifetime value, wherein the determining, deriving, encrypting and communicating means function only when the group key is received within the group key lifetime value; and
a group membership list, wherein the determining, deriving, encrypting and communicating means function only when second node is identified within the group membership list.
43. The apparatus as recited in claim 40, wherein the deriving means comprise:
means for applying the group key and the first and second nonce values and the to a key derivation function; and
generating a data-security session key, based on the applying the group key and the first and second nonce values, that is unique for the ISAKMP pair of peers comprising the first node and the second node.
44. The apparatus as recited in claim 40, wherein the determining means comprise:
means for determining a first identity value of the first node and a second identity value of the second node with a Tunnel Endpoint Detection (TED) probe; and
wherein the deriving means comprise means for deriving, based on the group key and the first and second identity values, a data-security session key for use in the secure point-to-point communication session between the first and second nodes that is effectively private within the secure communications group.
45. The apparatus as recited in claim 44, wherein the deriving means further comprise:
means for applying the group key and the first and second identity values to a key derivation function; and
means for generating a data-security session key, based on a function of the applying means, the group key and the first and second identity values, that is unique for the ISAKMP pair of peers that comprise the first and the second nodes.
46. The apparatus as recited in claim 40, wherein the determining means comprise:
means for determining a first IP address value that identifies the first node and determining a second IP address value that identifies the second node with a Tunnel Endpoint Detection (TED) probe; and
wherein the deriving means comprise means for deriving, based on the group key and the first and second nonce values, a data-security session key for use in the secure point-to-point communication session between the first and second nodes that is private within the secure communications group.
47. The apparatus as recited in claim 46, wherein deriving the means comprise:
means for applying the group key and the first and second IP address values to a key derivation function; and
means for generating a data-security session key, based on a function of the applying means, the group key and the first and second IP address values, that is unique for the ISAKMP pair of peers comprising the first node and the second node.
48. An apparatus for generating a cryptographic transform for use in a point-to-point secure communication session among a first node and a second node that are enrolled in a secure communication group, comprising:
a network interface that is coupled to the data network for receiving one or more packet flows therefrom;
a processor coupled to the network interface; and
at least one of a storage and a computer readable storage medium coupled to the processor and providing thereto one or more stored sequences of instructions which, when executed by the processor, cause the processor to carry out a process that comprises:
receiving a group key for use in secure communication among members of the secure communications group that includes the first node and the second node, wherein the first node is seeking to initiate the secure point-to-point communication session within the secure communications group with the second node wherein the secure point-to-point communication session allows the first and the second node to communicate with each other privately with respect to other members of the secure communications group;
determining first and second nonce values as part of performing a first phase of Internet Key Exchange (IKE) among the first node and the second node to establish an Internet Security Association and Key Management Protocol (ISAKMP) security association (SA) wherein the first and second nodes comprise ISAKMP peers;
deriving, based on the group key and the first and second nonce values, a data-security session key for use in the secure point-to-point communication session privately with respect to the other secure communications group members;
wherein the secure communications group comprises at least one node besides the first and second node, wherein the group key comprises a single group key that is common to all nodes of the secure communications group and wherein the deriving step is performed within the secure communications group by only each of the first and second nodes;
encrypting one or more data packets using the data-security session key; and
communicating the one or more data packets privately with respect to the other secure communications group members, to the second node as part of the secure communication session.
49. The apparatus as recited in claim 48 wherein said process further comprises:
receiving one or more policy data values in a Group Domain of Interpretation (\u201cGDOI\u201d) security association (\u201cSA\u201d) payload; and
encrypting one or more data packets using a keystream segment that is generated by providing the data-security session key and the one or more policy data values to a keystream generator function.
50. The apparatus as recited in claim 49, wherein at least one of:
the security association payload comprises a GDOI SA traffic encryption key (TEK) payload; and
the policy data values comprise at least one of:
a group key lifetime value, wherein the determining, deriving, encrypting and communicating are performed only when the group key is received within the group key lifetime value; and
a group membership list, wherein the determining, deriving, encrypting and communicating are performed only when second node is identified within the group membership list.
51. The apparatus as recited in claim 48, wherein the deriving the data-security session key comprises:
applying the group key and the first and second nonce values to a key derivation function; and
generating a data-security session key, based on the applying the group key and the first and second nonce values, that is unique for the ISAKMP pair of peers comprising the first node and the second node.
52. The apparatus as recited in claim 48, wherein the determining first and second nonce values comprises:
determining a first identity value of the first node and a second identity value of the second node with a Tunnel Endpoint Detection (TED) probe; and
wherein the deriving a data-security session key based on the group key and the first and second nonce values comprises deriving, based on the group key and the first and second identity values, a data-security session key for use in the secure point-to-point communication session between the first and second nodes that is effectively private within the secure communications group.
53. The apparatus as recited in claim 52, wherein the deriving the data-security session key comprises:
applying the group key and the first and second identity values to a key derivation function; and
generating a data-security session key, based on the applying the group key and the first and second identity values, that is unique for the ISAKMP pair of peers comprising the first node and the second node.
54. The apparatus as recited in claim 48, wherein the determining first and second nonce values comprises:
determining a first IP address value that identifies the first node and determining a second IP address value that identifies the second node using a Tunnel Endpoint Detection (TED) probe; and
wherein the deriving a data-security session based on the group key and the first and second nonce values comprises deriving, based on the group key and the first and second nonce values, a data-security session key for use in the secure point-to-point communication session between the first and second nodes that is effectively private within the secure communications group.
55. The apparatus as recited in claim 54, wherein deriving the data-security session key comprises:
applying the group key and the first and second IP address values to a key derivation function; and
generating a data-security session key, based on the applying the group key and the first and second IP address values, that is unique for the ISAKMP pair of peers comprising the first node and the second node.