




免费预览已结束,剩余18页可下载查看
下载本文档
版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
CryptographyandNetworkSecurityChapter16,FourthEditionbyWilliamStallingsLectureslidesbyLawrieBrown,Chapter16IPSecurity,Ifasecretpieceofnewsisdivulgedbyaspybeforethetimeisripe,hemustbeputtodeath,togetherwiththemantowhomthesecretwastold.TheArtofWar,SunTzu,IPSecurity,havearangeofapplicationspecificsecuritymechanismseg.S/MIME,PGP,Kerberos,SSL/HTTPShowevertherearesecurityconcernsthatcutacrossprotocollayerswouldlikesecurityimplementedbythenetworkforallapplications,IPSec,generalIPSecuritymechanismsprovidesauthenticationconfidentialitykeymanagementapplicabletouseoverLANs,acrosspublic&privateWANs,&fortheInternet,IPSecUses,BenefitsofIPSec,inafirewall/routerprovidesstrongsecuritytoalltrafficcrossingtheperimeterinafirewall/routerisresistanttobypassisbelowtransportlayer,hencetransparenttoapplicationscanbetransparenttoenduserscanprovidesecurityforindividualuserssecuresroutingarchitecture,IPSecurityArchitecture,specificationisquitecomplexdefinedinnumerousRFCsincl.RFC2401/2402/2406/2408manyothers,groupedbycategorymandatoryinIPv6,optionalinIPv4havetwosecurityheaderextensions:AuthenticationHeader(AH)EncapsulatingSecurityPayload(ESP),IPSecServices,AccesscontrolConnectionlessintegrityDataoriginauthenticationRejectionofreplayedpacketsaformofpartialsequenceintegrityConfidentiality(encryption)Limitedtrafficflowconfidentiality,SecurityAssociations,aone-wayrelationshipbetweensender&receiverthataffordssecurityfortrafficflowdefinedby3parameters:SecurityParametersIndex(SPI)IPDestinationAddressSecurityProtocolIdentifierhasanumberofotherparametersseqno,AH&EHinfo,lifetimeetchaveadatabaseofSecurityAssociations,AuthenticationHeader(AH),providessupportfordataintegrity&authenticationofIPpacketsendsystem/routercanauthenticateuser/apppreventsaddressspoofingattacksbytrackingsequencenumbersbasedonuseofaMACHMAC-MD5-96orHMAC-SHA-1-96partiesmustshareasecretkey,AuthenticationHeader,Transport&TunnelModes,EncapsulatingSecurityPayload(ESP),providesmessagecontentconfidentiality&limitedtrafficflowconfidentialitycanoptionallyprovidethesameauthenticationservicesasAHsupportsrangeofciphers,modes,paddingincl.DES,Triple-DES,RC5,IDEA,CASTetcCBC&othermodespaddingneededtofillblocksize,fields,fortrafficflow,EncapsulatingSecurityPayload,TransportvsTunnelModeESP,transportmodeisusedtoencrypt&optionallyauthenticateIPdatadataprotectedbutheaderleftinclearcandotrafficanalysisbutisefficientgoodforESPhosttohosttraffictunnelmodeencryptsentireIPpacketaddnewheaderfornexthopgoodforVPNs,gatewaytogatewaysecurity,CombiningSecurityAssociations,SAscanimplementeitherAHorESPtoimplementbothneedtocombineSAsformasecurityassociationbundlemayterminateatdifferentorsameendpointscombinedbytransportadjacencyiteratedtunnelingissueofauthentication&encryptionorder,CombiningSecurityAssociations,KeyManagement,handleskeygeneration&distributiontypicallyneed2pairsofkeys2perdirectionforAH&ESPmanualkeymanagementsysadminmanuallyconfigureseverysystemautomatedkeymanagementautomatedsystemforondemandcreationofkeysforSAsinlargesystemshasOakley&ISAKMPelements,Oakley,akeyexchangeprotocolbasedonDiffie-Hellmankeyexchangeaddsfeaturestoaddressweaknessescookies,groups(globalparams),nonces,DHkeyexchangewithauthenticationcanusearithmeticinprimefieldsorellipticcurvefields,ISAKMP,InternetSecurityAssociationandKeyManagementProtocolprovidesframeworkforkeymanagementdefinesproceduresandpacketformatstoestablish,negotiate,modify,&deleteSAsindependentofkeyexchangeprotocol,encryptionalg,&authenticationmethod,ISAKMP,ISAKMPPayloads&Exchanges,haveanumberofISAKMPpayloadtypes:Security,Proposal,Transform,Key,Identification,Certificate,Certificate,Hash,Signature,Nonce,Notification,DeleteIS
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 四年级数学单元测试卷及答题技巧
- 老年健康档案管理创新创业项目商业计划书
- 老年心理健康评估与干预创新创业项目商业计划书
- 云南省近三年生物中考试题知识点细目分析
- 高校招生宣传文案策划
- 公司节能减排项目执行报告
- 江苏安全B证考试题库及答案
- 江陵中学入学考试卷子及答案
- 戏剧影视文学专业课程培养方案及要求
- 通信设备维修工标准操作规程指南
- 发电机的工作原理
- AI一体化智慧校园建设方案中学版
- 《机电一体化技术》课件-第七章 机电一体化系统设计
- DB51T 692-2018 中小学实验室设备技术规范
- 2024电气安全事故案例
- 期末高频易错测评卷 (试题)-2024-2025学年五年级上册人教版数学
- 工程审计报告(共5篇)
- 物业服务品质控制培训
- 消除“艾梅乙”医疗歧视-从我做起
- DB34∕T 4433-2023 检测实验室公正性风险评估技术规范
- 系统商用密码应用方案v5-2024(新模版)
评论
0/150
提交评论