BS ISO IEC 10736-1995 Information technology - Telecommunications and information exchange between systems - Transport layer security protocol《信息技术 系统间信和信息交换 传输层安全协议》.pdf
《BS ISO IEC 10736-1995 Information technology - Telecommunications and information exchange between systems - Transport layer security protocol《信息技术 系统间信和信息交换 传输层安全协议》.pdf》由会员分享,可在线阅读,更多相关《BS ISO IEC 10736-1995 Information technology - Telecommunications and information exchange between systems - Transport layer security protocol《信息技术 系统间信和信息交换 传输层安全协议》.pdf(62页珍藏版)》请在麦多课文档分享上搜索。
1、BRITISH STANDARD BS ISO/IEC 10736:1995 Implementation of ISO/IEC 10736:1995 Information technology Telecommunications and information exchange between systems Transportlayer security protocolBSISO/IEC10736:1995 This British Standard, having been prepared under the directionof the Information Systems
2、 Technology Assembly,was published underthe authority of the Standards Board and comes intoeffect on 15September1995 BSI 01-2000 The following BSI references relate to the work on this standard: Committee reference IST/6 Draft for comment 91/69325 DC ISBN 0 580 24459 8 Committees responsible for thi
3、s British Standard The preparation of this British Standard was entrusted to Technical Committee IST/6 Data communications, upon which the following bodies were represented: British Computer Society British Telecommunications CCTA (Government Centre for Information Systems) Digital Equipment Co. Ltd
4、. IBM United Kingdom Ltd. Institution of Electrical Engineers International Computers Limited Logica UK Ltd. Nine Tiles Computer Systems Ltd. Rank Xerox (UK) Ltd. Amendments issued since publication Amd. No. Date CommentsBSISO/IEC10736:1995 BSI 01-2000 i Contents Page Committees responsible Inside f
5、ront cover National foreword ii Foreword vii Text of ISO/IEC 10736 1BSISO/IEC10736:1995 ii BSI 01-2000 National foreword This British Standard reproduces verbatim ISO/IEC10736:1995 and implements it as the UK national standard. This British Standard is published under the direction of the Informatio
6、n Systems Technology Assembly whose Technical Committee IST/6, Data communications, has the responsibility to: aid enquirers to understand the text; present to the responsible international committee any enquiries on interpretation, or proposals for change, and keep UK interests informed; monitor re
7、lated international and European developments and promulgate them in the UK. NOTEInternational and European Standards, as well as overseas standards, are available from Customer Services, BSI, 389 Chiswick High Road, LondonW44AL. A British Standard does not purport to include all the necessary provi
8、sions of a contract. Users of British Standards are responsible for their correct application. Compliance with a British Standard does not of itself confer immunity from legal obligations. Summary of pages This document comprises a front cover, an inside front cover, pagesi andii, theISO/IEC title p
9、age, pagesii toviii, pages1 to48 and aback cover. This standard has been updated (see copyright date) and may have had amendments incorporated. This will be indicated in the amendment table on the inside front cover.ISO/IEC10736:1995(E) ii BSI 01-2000 Contents Page Foreword vii Introduction 1 1 Scop
10、e 1 2 Normative references 2 2.1 Identical Recommendations|International Standards 2 2.2 Paired Recommendations|International Standards equivalent in technical content 2 2.3 Additional references 2 3 Definitions 3 3.1 Security reference model definitions 3 3.2 Additional definitions 3 4 Symbols and
11、abbreviations 4 5 Overview of the Protocol 5 5.1 Introduction 5 5.2 Security Associations and attributes 6 5.2.1 Security services for connection-oriented Transport protocol 9 5.2.2 Security Service for connectionless Transport protocol 9 5.3 Service assumed of the Network Layer 9 5.4 Security manag
12、ement requirements 9 5.5 Minimum algorithm characteristics 10 5.6 Security encapsulation function 10 5.6.1 Data encipherment function 10 5.6.2 Integrity function 10 5.6.3 Security label function 11 5.6.4 Security padding function 11 5.6.5 Peer Entity Authentication function 11 5.6.6 SA Function usin
13、g in band SA-P 11 6 Elements of procedure 11 6.1 Concatenation and separation 12 6.2 Confidentiality 12 6.2.1 Purpose 12 6.2.2 TPDUs and parameters used 12 6.2.3 Procedure 12 6.3 Integrity processing 13 6.3.1 Integrity Check Value (ICV) processing 13 6.3.1.1 Purpose 13 6.3.1.2 TPDUs and parameters u
14、sed 13 6.3.1.3 Procedure 13 6.3.2 Direction indicator processing 15 6.3.2.1 Purpose 15 6.3.2.2 TPDUs and parameters used 15 6.3.2.3 Procedure 15 6.3.3 Connection integrity sequence number processing 15 6.3.3.1 Unique sequence numbers 15 6.3.3.2 Purpose 16 6.3.3.3 Procedure 16 6.4 Peer address check
15、processing 16 6.4.1 Purpose 16 6.4.2 Procedure 16 6.5 Security labels for Security Associations 16ISO/IEC10736:1995(E) BSI 01-2000 iii Page 6.5.1 Purpose 16 6.5.2 TPDUs and parameters used 16 6.5.3 Procedure 17 6.6 Connection release 17 6.7 Key replacement 17 6.8 Unprotected TPDUs 17 6.9 Protocol id
16、entification 17 6.10 Security Association-Protocol 17 7 Use of elements of procedure 18 8 Structure and encoding of TPDUs 18 8.1 Structure of TPDU 18 8.2 Security encapsulation TPDU 19 8.2.1 Clear header 19 8.2.1.1 PDU clear header length 19 8.2.1.2 PDU type 19 8.2.1.3 SA-ID 19 8.2.2 Crypto sync 19
17、8.2.3 Protected contents 20 8.2.3.1 Structure of protected contents field 20 8.2.3.2 Content length 20 8.2.3.3 Flags 21 8.2.3.4 Label 21 8.2.3.5 Protected data 21 8.2.3.6 Integrity PAD 21 8.2.4 ICV 22 8.2.5 Encipherment PAD 22 8.3 Security Association PDU 22 8.3.1 LI 22 8.3.2 PDU Type 22 8.3.3 SA-ID
18、 22 8.3.4 SA-P Type 22 8.3.5 SA PDU Contents 22 9 Conformance 23 9.1 General 23 9.2 Common static conformance requirements 23 9.3 TLSP with ITU-T Rec. X.234|ISO8602 static conformance requirements 23 9.4 TLSP with ITU-T Rec. X.224|ISO/IEC8073 static conformance requirements 23 9.5 Common dynamic con
19、formance requirements 23 9.6 TLSP with ITU-T Rec. X.234|ISO8602 dynamic conformance requirements 23 9.7 TLSP with ITU-T Rec. X.224|ISO/IEC8073 dynamic conformance requirements 23 10 Protocol implementation conformance statement (PICS) 23 Annex A PICS proforma 24 A.1 Introduction 24 A.1.1 Background
20、24 A.1.2 Approach 24ISO/IEC10736:1995(E) iv BSI 01-2000 Page A.2 Implementation identification 24 A.3 General statement of conformance 25 A.4 Protocol implementation 25 A.5 Security services supported 25 A.6 Supported functions 27 A.7 Supported Protocol Data Units (PDUs) 29 A.7.1 Supported Transport
21、 PDUs (TPDUs) 29 A.7.2 Supported parameters of issued TPDUs 30 A.7.3 Supported parameters of received TPDUs 30 A.7.4 Allowed values of issued TPDU parameters 31 A.8 Service, function, and protocol relationships 31 A.8.1 Relationship between services and functions 31 A.8.2 Relationship between servic
22、es and protocol 32 A.9 Supported algorithms 32 A.10 Error handling 33 A.10.1 Security errors 33 A.10.2 Protocol errors 33 A.11 Security Association 33 A.11.1 SA Generic Fields 33 A.11.2 Content Fields Specific to Key Exchange SA-P 35 Annex B Security Association Protocol Using Key Token Exchange and
23、 Digital Signatures 36 B.1 Overview 36 B.2 Key Token Exchange (KTE) 37 B.3 SA-Protocol Authentication 37 B.4 SA Attribute Negotiation 38 B.4.1 Service Negotiation 38 B.4.2 Label Set Negotiation 38 B.4.3 Key and ISN Selection 38 B.4.4 Miscellaneous SA Attribute Negotiation 38 B.4.5 Re-keying Overview
24、 39 B.4.6 SA Abort/Release Overview 39 B.5 Mapping of SA-Protocol Functions to Protocol Exchanges 39 B.5.1 KTE (First) Exchange 39 B.5.1.1 Request to Initiate the SA-Protocol 39 B.5.1.2 Receipt of the First Exchange PDU by Recipient 40 B.5.2 Authentication and Security Negotiation (Second) Exchange
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- BSISOIEC107361995INFORMATIONTECHNOLOGYTELECOMMUNICATIONSANDINFORMATIONEXCHANGEBETWEENSYSTEMSTRANSPORTLAYERSECURITYPROTOCOL

链接地址:http://www.mydoc123.com/p-396199.html