802.1X-2010 - IEEE Standard for Local and metropolitan area networks--Port-Based Network Access Control.pdf
《802.1X-2010 - IEEE Standard for Local and metropolitan area networks--Port-Based Network Access Control.pdf》由会员分享,可在线阅读,更多相关《802.1X-2010 - IEEE Standard for Local and metropolitan area networks--Port-Based Network Access Control.pdf(222页珍藏版)》请在麦多课文档分享上搜索。
1、 !“#$ $% +1 978 750 8400. Permission to photocopy portions of any individual standard for educational classroom use can also be obtained through the Copyright Clearance Center.iv Copyright 2010 IEEE. All rights reserved. IntroductionPort-based network access control allows a network administrator to
2、 restrict the use of IEEE 802 LAN service access points (ports) to secure communication between authenticated and authorized devices. IEEE Std 802.1X specifies an architecture, functional elements, and protocols that support mutual authentication between the clients of ports attached to the same LAN
3、 and secure communication between the ports. The first edition of IEEE Std 802.1X was published in 2001. The second edition, IEEE Std 802.1X-2004, clarified areas related to mutual authentication and the interface between IEEE 802.1X specified state machine, and those specified by the Extensible Aut
4、hentication Protocol (EAP), and by IEEE Std 802.11 in support of IEEE Std 802.1X. Work on this edition, IEEE Std 802.1X-2010, began as IEEE P802.1af an amendment to specify authenticated key agreement in support of IEEE 802.1AE MAC Security. Part of that work clarified and generalized the relationsh
5、ip between the common architecture specified for port-based network access control, and the functional elements and protocols that support that architecture as specified in IEEE Std 802.1X, other IEEE 802 Standards, and in IETF RFCs. The extent of the changes necessary to IEEE Std 802.1X-2004 made i
6、t appropriate to revise IEEE Std 802.1X as a whole. Further changes updated the standard to reflect best current practice, insisting, for example, upon mutual authentication methods and using such methods in examples. A greater emphasis is placed on the security of systems accessing the network, as
7、well as upon the security of the network accessed, and some prior provisions, such as the controlled directions parameters, have been removed and replaced with a more comprehensive treatment of segregating and limiting connectivity to unauthenticated systems. Every effort has been made to maintain i
8、nteroperability, without prior configuration, with implementations conforming to IEEE Std 802.1X-2004 and IEEE Std 802.1X-2001. However it is anticipated that claims of conformance in respect of some existing implementations will continue to refer to IEEE Std 802.1X-2004. Changes to the functionalit
9、y provided by that prior edition and its documentation include those detailed in the following paragraph. This edition, IEEE Std 802.1X-2010, describes applications of port-based network access that use IEEE 802.1AE MAC Security (MACsec) and/or MKA (MACsec Key Agreement protocol) as well as those pr
10、eviously supported. The specification of the use of EAP for authentication has been updated, enforcing a stricter separation between the port access control protocol (PACP), local to the Supplicant and Authenticator, and the EAP state machines proper. Details of particular EAP methods are no longer
11、interpreted by the PACP machines. The existing EAPOL (EAP over LANs) PDU formats have not been modified, but additional EAPOL PDUs have been added to support MKA and the specification of EAPOL improved. The bibliography, previously Annex F, has been moved to Annex B. The discussions previously in An
12、nex B and Annex C have been updated and integrated into the main body of the standard. The state machine diagram and language conventions, now used by a number of clauses in the standard, have been moved to a new Annex C. Notice to users Laws and regulations Users of these documents should consult a
13、ll applicable laws and regulations. Compliance with the provisions of this standard does not imply compliance to any applicable regulatory requirements. This introduction is not part of IEEE Std 802.1X-2010, IEEE Standard for Local and Metropolitan Area NetworksPort-Based Network Access Control.Copy
14、right 2010 IEEE. All rights reserved. v Implementers of the standard are responsible for observing or referring to the applicable regulatory requirements. IEEE does not, by the publication of its standards, intend to urge action that is not in compliance with applicable laws, and these documents may
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- 802.1 2010 IEEE Standard for Local and metropolitan area networks Port Based Network Access Control

链接地址:http://www.mydoc123.com/p-287301.html