GL-9
Cisco Router and Security Device Manager 2.5 User’s Guide
OL-4015-12
Glossary
DH, Diffie-Hellman A public key cryptography protocol that allows two parties to establish a shared
secret over insecure communications channels. Diffie-Hellman is used within
Internet Key Exchange (IKE) to establish session keys. Diffie-Hellman is a
component of Oakley key exchange.
Diffie-Hellman key
exchange
A public key cryptography protocol that allows two parties to establish a shared
secret over insecure communication channels. Diffie-Hellman is used within
Internet Key Exchange (IKE) to establish session keys. Diffie-Hellman is a
component of Oakley key exchange. Cisco IOS software supports 768-bit and
1024-bit Diffie-Hellman groups.
digest The output of a hash function.
digital certificate A cryptographically signed, digital representation of user or device attributes
that binds a key to an identity. A unique certificate attached to a public key
provides evidence that the key has not been compromised. A certificate is issued
and signed by a trusted certification authority, and binds a public key to its
owner. Certificates typically include the owner’s name, the owner’s public key,
the certificate’s serial number, and the certificate’s expiration date. Other
information might also be present. See X.509.
digital signature An authentication method that permits the easy discovery of data forgery, and
prevents repudiation. Additionally, the use of digital signatures allows for
verification that a transmission has been received intact. Typically includes a
transmission time stamp.
distributed key A shared cryptographic key that is divided into pieces, with each piece provided
to a different participant.
DLCI data-link connection identifier. In Frame Relay connections, the identifier for a
particular data link connection between two endpoints.
DMVPN Dynamic multipoint virtual private network. A virtual private network in which
routers are arranged in a logical hub and spoke topology, and in which the hubs
have point-to-point GRE over IPSec connections with the hub. DMVPN uses
GRE and NHRP to enable the flow of packets to destinations in the network.
single DMVPN A router with a single DMVPN configuration has a connection to one DMVPN
hub, and has one configured GRE tunnel for DMVPN communication.Th e GRE
tunnel addresses for the hub and spokes must be in the same subnet.