ANSI INCITS 501-2016 Information Technology C Security Features for SCSI Commands (SFSC).pdf
《ANSI INCITS 501-2016 Information Technology C Security Features for SCSI Commands (SFSC).pdf》由会员分享,可在线阅读,更多相关《ANSI INCITS 501-2016 Information Technology C Security Features for SCSI Commands (SFSC).pdf(153页珍藏版)》请在麦多课文档分享上搜索。
1、American National StandardDeveloped byfor Information Technology Security Features forSCSI Commands (SFSC)INCITS 501-2016INCITS 501-2016INCITS 501-2016American National Standardfor Information Technology Security Features forSCSI Commands (SFSC)SecretariatInformation Technology Industry CouncilAppro
2、ved July 7. 2016American National Standards Institute, Inc.AbstractThis standard defines security features for use by all SCSI devices. This standard defines the securitymode that is basic to every device model and the parameter data that may apply to any device model.Approval of an American Nationa
3、l Standard requires review by ANSI that therequirements for due process, consensus, and other criteria for approval havebeen met by the standards developer.Consensus is established when, in the judgement of the ANSI Board ofStandards Review, substantial agreement has been reached by directly andmate
4、rially affected interests. Substantial agreement means much more thana simple majority, but not necessarily unanimity. Consensus requires that allviews and objections be considered, and that a concerted effort be madetowards their resolution.The use of American National Standards is completely volun
5、tary; theirexistence does not in any respect preclude anyone, whether he has approvedthe standards or not, from manufacturing, marketing, purchasing, or usingproducts, processes, or procedures not conforming to the standards.The American National Standards Institute does not develop standards andwil
6、l in no circumstances give an interpretation of any American NationalStandard. Moreover, no person shall have the right or authority to issue aninterpretation of an American National Standard in the name of the AmericanNational Standards Institute. Requests for interpretations should beaddressed to
7、the secretariat or sponsor whose name appears on the titlepage of this standard.CAUTION NOTICE: This American National Standard may be revised orwithdrawn at any time. The procedures of the American National StandardsInstitute require that action be taken periodically to reaffirm, revise, orwithdraw
8、 this standard. Purchasers of American National Standards mayreceive current information on all standards by calling or writing the AmericanNational Standards Institute.American National StandardPublished byAmerican National Standards Institute, Inc.25 West 43rd Street, New York, NY 10036Copyright 2
9、016 by Information Technology Industry Council (ITI)All rights reserved.No part of this publication may be reproduced in anyform, in an electronic retrieval system or otherwise,without prior written permission of ITI, 1101 K Street NW, Suite 610, Washington, DC 20005. Printed in the United States of
10、 AmericaCAUTION: The developers of this standard have requested that holders of patents that may be re-quired for the implementation of the standard disclose such patents to the publisher. However, nei-ther the developers nor the publisher have undertaken a patent search in order to identify which,
11、ifany, patents may apply to this standard. As of the date of publication of this standard, followingcalls for the identification of patents that may be required for the implementation of the standard,notice of one or more such claims has been received. By publication of this standard, no positionis
12、taken with respect to the validity of this claim or of any rights in connection therewith. The knownpatent holder(s) has (have), however, filed a statement of willingness to grant a license underthese rights on reasonable and nondiscriminatory terms and conditions to applicants desiring to ob-tain s
13、uch a license. Details may be obtained from the publisher. No further patent search is con-ducted by the developer or publisher in respect to any standard it processes. No representation ismade or implied that this is the only license that may be required to avoid infringement in the use ofthis stan
14、dard.iContentsPageForeword. viiiIntroduction xiiSCSI standards familyxii1 Scope. 12 Normative references. 13 Definitions, symbols, abbreviations, and conventions 43.1 Definitions. 43.2 Abbreviations and symbols. 133.2.1 Abbreviations. 133.2.2 Symbols. 143.2.3 Mathematical operators . 143.3 Keywords
15、143.4 Conventions 163.5 Numeric and character conventions . 163.5.1 Numeric conventions . 163.5.2 Units of measure 173.5.3 Byte encoded character strings conventions. 183.6 Bit and byte ordering. 184 Security features model common to all device types . 204.1 Security features for SCSI devices. 204.1
16、.1 Security associations. 204.1.1.1 Principles of SAs. 204.1.1.2 SA parameters 214.1.1.3 Creating an SA . 244.1.2 Key derivation functions. 244.1.2.1 KDFs overview 244.1.2.2 IKEv2-based iterative KDF . 254.1.2.3 HMAC-based KDFs 254.1.2.4 AES-XCBC-PRF-128 IKEv2-based iterative KDF 274.1.3 Using IKEv2
17、-SCSI to create an SA 284.1.3.1 Overview. 284.1.3.2 IKEv2-SCSI Protocol summary. 314.1.3.3 IKEv2-SCSI Authentication. 344.1.3.3.1 Overview 344.1.3.3.2 Pre-shared key authentication. 354.1.3.3.3 Digital signature authentication 364.1.3.3.3.1 Overview. 364.1.3.3.3.2 Certificates and digital signature
18、authentication . 364.1.3.3.3.3 Example of certificate use for digital signature authentication 374.1.3.3.3.4 Handling of the Certificate Request payload and the Certificate payload. 374.1.3.3.4 Constraints on skipping the Authentication step 374.1.3.4 Summary of IKEv2-SCSI shared keys nomenclature a
19、nd shared key sizes 394.1.3.5 Device Server Capabilities step 404.1.3.6 IKEv2-SCSI Key Exchange step. 424.1.3.6.1 Overview 42ii4.1.3.6.2 Key Exchange step SECURITY PROTOCOL OUT command 424.1.3.6.3 Key Exchange step SECURITY PROTOCOL IN command 434.1.3.6.4 Key Exchange step completion . 444.1.3.6.5 A
20、fter the Key Exchange step . 444.1.3.7 IKEv2-SCSI Authentication step. 444.1.3.7.1 Overview 444.1.3.7.2 Authentication step SECURITY PROTOCOL OUT command 454.1.3.7.3 Authentication step SECURITY PROTOCOL IN command 464.1.3.8 Generating shared keys 474.1.3.8.1 Overview 474.1.3.8.2 Generating shared k
21、eys when the Authentication step is skipped 484.1.3.8.3 Generating shared keys when the Authentication step is processed 484.1.3.8.4 Initializing shared key generation 484.1.3.8.4.1 Initializing for SA creation shared key generation. 484.1.3.8.4.2 Initializing for generation of shared keys used by t
22、he created SA 494.1.3.8.5 Generating shared keys used for SA management. 494.1.3.8.6 Generating shared keys for use by the created SA. 504.1.3.9 IKEv2-SCSI SA generation. 514.1.3.10 Abandoning an IKEv2-SCSI CCS. 534.1.3.11 Deleting an IKEv2-SCSI SA 544.1.4 Security progress indication. 544.1.5 ESP-S
23、CSI encapsulations for parameter data 554.1.5.1 Overview. 554.1.5.2 ESP-SCSI required inputs 554.1.5.3 ESP-SCSI data format before encryption and after decryption 564.1.5.4 ESP-SCSI outbound data descriptors 574.1.5.4.1 Overview 574.1.5.4.2 ESP-SCSI CDBs or Data-Out Buffer parameter lists including
24、a descriptor length. 584.1.5.4.2.1 Initialization vector absent 584.1.5.4.2.2 Initialization vector present . 604.1.5.4.3 ESP-SCSI Data-Out Buffer parameter lists for externally specified descriptor length. 614.1.5.4.3.1 Initialization vector absent 614.1.5.4.3.2 Initialization vector present . 624.
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ANSIINCITS5012016INFORMATIONTECHNOLOGYCSECURITYFEATURESFORSCSICOMMANDSSFSCPDF

链接地址:http://www.mydoc123.com/p-435813.html