ANSI INCITS 426-2007 for Information Technology C Fibre Channel C Security Protocols (FC-SP).pdf
《ANSI INCITS 426-2007 for Information Technology C Fibre Channel C Security Protocols (FC-SP).pdf》由会员分享,可在线阅读,更多相关《ANSI INCITS 426-2007 for Information Technology C Fibre Channel C Security Protocols (FC-SP).pdf(306页珍藏版)》请在麦多课文档分享上搜索。
1、American National StandardDeveloped byfor Information Technology Fibre Channel Security Protocols(FC-SP)ANSI INCITS 426-2007ANSIINCITS426-2007ANSIINCITS 426-2007American National Standardfor Information Technology Fibre Channel Security Protocols(FC-SP)SecretariatInformation Technology Industry Coun
2、cilApproved February 1, 2007 American National Standards Institute, Inc.AbstractThis standard describes the protocols used to implement security in a Fibre Channel fabric. This stan-dard includes the definition of protocols to authenticate Fibre Channel entities, protocols to set up ses-sion keys, p
3、rotocols to negotiate the parameters required to ensure frame-by-frame integrity andconfidentiality, and protocols to establish and distribute policies across a Fibre Channel fabric.Approval of an American National Standard requires review by ANSI that therequirements for due process, consensus, and
4、 other criteria for approval havebeen met by the standards developer.Consensus is established when, in the judgement of the ANSI Board ofStandards Review, substantial agreement has been reached by directly andmaterially affected interests. Substantial agreement means much more thana simple majority,
5、 but not necessarily unanimity. Consensus requires that allviews and objections be considered, and that a concerted effort be madetowards their resolution.The use of American National Standards is completely voluntary; theirexistence does not in any respect preclude anyone, whether he has approvedth
6、e standards or not, from manufacturing, marketing, purchasing, or usingproducts, processes, or procedures not conforming to the standards.The American National Standards Institute does not develop standards andwill in no circumstances give an interpretation of any American NationalStandard. Moreover
7、, no person shall have the right or authority to issue aninterpretation of an American National Standard in the name of the AmericanNational Standards Institute. Requests for interpretations should beaddressed to the secretariat or sponsor whose name appears on the titlepage of this standard.CAUTION
8、 NOTICE: This American National Standard may be revised orwithdrawn at any time. The procedures of the American National StandardsInstitute require that action be taken periodically to reaffirm, revise, orwithdraw this standard. Purchasers of American National Standards mayreceive current informatio
9、n on all standards by calling or writing the AmericanNational Standards Institute.American National StandardPublished byAmerican National Standards Institute, Inc.25 West 43rd Street, New York, NY 10036Copyright 2007 by Information Technology Industry Council (ITI)All rights reserved.No part of this
10、 publication may be reproduced in anyform, in an electronic retrieval system or otherwise,without prior written permission of ITI, 1250 Eye Street NW, Washington, DC 20005. Printed in the United States of AmericaCAUTION: The developers of this standard have requested that holders of patents that may
11、 be re-quired for the implementation of the standard disclose such patents to the publisher. However, nei-ther the developers nor the publisher have undertaken a patent search in order to identify which, ifany, patents may apply to this standard. As of the date of publication of this standard, follo
12、wingcalls for the identification of patents that may be required for the implementation of the standard,notice of one or more such claims has been received. By publication of this standard, no positionis taken with respect to the validity of this claim or of any rights in connection therewith. The k
13、nownpatent holder(s) has (have), however, filed a statement of willingness to grant a license underthese rights on reasonable and nondiscriminatory terms and conditions to applicants desiring to ob-tain such a license. Details may be obtained from the publisher. No further patent search is con-ducte
14、d by the developer or publisher in respect to any standard it processes. No representation ismade or implied that this is the only license that may be required to avoid infringement in the use ofthis standard.iContentsPageForeword viiIntroduction x1 Scope . 12 Normative References . 22.1 Overview 22
15、.2 Approved references 22.3 References under development . 22.4 Other References . 23 Definitions and conventions . 53.1 Overview 53.2 Definitions 53.3 Editorial Conventions . 83.4 Abbreviations, acronyms, and symbols . 103.5 Keywords . 113.6 T10 Vendor ID 123.7 Sorting 123.7.1 Sorting alphabetic ke
16、ys 123.7.2 Sorting numeric keys . 123.8 Terminate Communication . 123.9 State Machine notation 134 Structure and Concepts . 154.1 Overview 154.2 FC-SP Compliance 154.3 Fabric Security Architecture . 154.4 Authentication Infrastructure 154.5 Authentication 164.6 Security Associations . 174.7 Cryptogr
17、aphic Integrity and Confidentiality 174.7.1 Overview 174.7.2 ESP_Header Processing . 184.7.3 CT_Authentication Processing . 194.8 Authorization (Access Control) 214.8.1 Policy Definition . 214.8.2 Policy Enforcement 224.8.3 Policy Distribution 224.8.4 Policy Check 224.9 Name Format . 22iiPage5 Authe
18、ntication Protocols 235.1 Overview 235.2 Authentication Messages Structure . 245.2.1 Overview 245.2.2 SW_ILS Authentication Messages 245.2.3 ELS Authentication Messages . 265.2.4 Fields Common to All AUTH Messages 275.2.5 Vendor Specific Messages 285.3 Authentication Messages Common to Authenticatio
19、n Protocols . 285.3.1 Overview 285.3.2 AUTH_Negotiate Message 295.3.3 Names used in Authentication . 305.3.4 Hash Functions 305.3.5 Diffie-Helmann Groups 315.3.6 AUTH_Reject Message . 325.3.7 AUTH_Done Message . 355.4 DH-CHAP Protocol 365.4.1 Protocol Operations . 365.4.2 AUTH_Negotiate DH-CHAP Para
20、meters . 385.4.3 DHCHAP_Challenge Message 395.4.4 DHCHAP_Reply Message . 405.4.5 DHCHAP_Success Message 425.4.6 Key Generation for the Security Association Management Protocol 435.4.7 Reuse of Diffie-Hellman Exponential . 435.4.8 DH-CHAP Security Considerations . 435.5 FCAP Protocol . 455.5.1 Protoc
21、ol Operations . 455.5.2 AUTH_Negotiate FCAP Parameters . 485.5.3 FCAP_Request Message 495.5.4 FCAP_Acknowledge Message 525.5.5 FCAP_Confirm Message . 545.5.6 Key Generation for the Security Association Management Protocol 545.5.7 Reuse of Diffie-Hellman Exponential . 545.6 FCPAP Protocol . 555.6.1 P
22、rotocol Operations . 555.6.2 AUTH_Negotiate FCPAP Parameters . 585.6.3 FCPAP_Init Message 595.6.4 FCPAP_Accept Message 605.6.5 FCPAP_Complete Message 605.6.6 Key Generation for the Security Association Management Protocol 615.6.7 Reuse of Diffie-Hellman Exponential . 615.7 AUTH_ILS Specification 625
23、.7.1 Overview 625.7.2 AUTH_ILS Request Sequence 635.7.3 AUTH_ILS Reply Sequence 64iiiPage5.8 B_AUTH_ILS Specification 645.8.1 Overview 645.8.2 B_AUTH_ILS Request Sequence 665.8.3 B_AUTH_ILS Reply Sequence 675.9 AUTH_ELS Specification . 675.9.1 Overview 675.9.2 AUTH_ELS Request Sequence . 695.9.3 AUT
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ANSIINCITS4262007FORINFORMATIONTECHNOLOGYCFIBRECHANNELCSECURITYPROTOCOLSFCSPPDF

链接地址:http://www.mydoc123.com/p-435731.html