ATIS 0100014-2007 Information & Communications Security for NGN Converged Services IP Networks and Infrastructure.pdf
《ATIS 0100014-2007 Information & Communications Security for NGN Converged Services IP Networks and Infrastructure.pdf》由会员分享,可在线阅读,更多相关《ATIS 0100014-2007 Information & Communications Security for NGN Converged Services IP Networks and Infrastructure.pdf(235页珍藏版)》请在麦多课文档分享上搜索。
1、 TECHNICAL REPORT ATIS-0100014 INFORMATION Confidentiality Policies versus Integrity Policies . 63 4.8.2 Available Security Models . 64 4.8.3 Security Model Summary 68 4.9 Security Requirements . 68 5 SECURITY ARCHITECTURES, SERVICES AND MECHANISMS . 69 5.1 Architectural Types 69 5.1.1 Abstract Arch
2、itectures . 69 5.1.2 Generic Architecture 69 5.1.3 Logical Architecture . 73 5.1.4 Specific Architecture 73 5.2 Security Services 74 5.2.1 Authentication 75 5.2.2 Authorization - Access Control 76 5.2.3 Data confidentiality 76 5.2.4 Integrity 77 5.2.5 Non-repudiation . 79 5.3 Necessary Communication
3、s Security Services 79 5.3.1 Architectural Context for Security Services . 79 5.3.2 Mapping Security Services to the Architectural Model 110 5.4 Security Mechanisms . 120 5.4.1 Operating System Security Mechanisms and Hardening 120 5.4.2 Applicable Protocol Security Mechanisms 152 5.4.3 Major Securi
4、ty Protocols 167 5.4.4 Application Frameworks 179 5.5 Management of Security Mechanisms . 179 5.5.1 Integrated Security Management 179 5.5.2 Securing management Related Communications . 179 5.5.3 Storage of Security Information . 180 5.5.4 Security Management within Elements . 180 5.6 Certification,
5、 Auditing December 2002 RFC 3415 View-based Access Control Model (VACM) for the Simple Network Management Protocol (SNMP), December 2002 RFC 3436 Transport Layer Security over Stream Control Transmission Protocol, December 2002 RFC 3456 Dynamic Host Configuration Protocol (DHCPv4) Configuration of I
6、Psec Tunnel Mode, January 2003 RFC 3472 Generalized Multi-Protocol Label Switching (GMPLS) Signaling Constraint-based Routed Label Distribution Protocol (CR-LDP) Extensions RFC 3526 More Modular Exponential (MODP) Diffie-Hellman groups for Internet Key Exchange (IKE), May 2003 RFC 3534 Media Gateway
7、 Control Protocol (MGCP) Version 1.0, January 2003. RFC 3546 Transport Layer Security (TLS) Extensions, June 2003 RFC 3550 RTP: A Transport Protocol for Real-Time Applications, July 2003 RFC 3554 On the Use of Stream Control Transmission Protocol (SCTP) with IPsec, July 2003 RFC 3566 The AES-XCBC-MA
8、C-96 Algorithm and Its Use With IPsec, September 2003 RFC 3602 The AES-CBC Cipher Algorithm and Its Use with IPsec, September 2003 RFC 3664 The AES-XCBC-PRF-128 Algorithm for the Internet Key Exchange Protocol (IKE), January 2004 RFC 3686 Using Advanced Encryption Standard (AES) Counter Mode With IP
9、sec Encapsulating Security Payload (ESP), January 2004 RFC 3711 The Secure Real-time Transport Protocol (SRTP), March 2004 RFC 3826 The Advanced Encryption Standard (AES) Cipher Algorithm in the SNMP User-based Security Model, June 2004 ATIS-0100014 7 RFC 3830 MIKEY: Multimedia Internet KEYing, Augu
10、st 2004 RFC 3947 Negotiation of NAT-Traversal in the IKE, January 2005 RFC 3948 UDP Encapsulation of IPsec ESP Packets, January 2005 RFC 4030 The Authentication Suboption for the Dynamic Host Configuration Protocol (DHCP) Relay Agent Option, March 2005 RFC 4033 DNS Security Introduction and Requirem
11、ents, March 2005 RFC 4034 Resource Records for the DNS Security Extensions, March 2005 RFC 4035 Protocol Modifications for the DNS Security Extensions, March 2005. RFC 4086 Randomness Requirements for Security, June 2005 RFC 4106 The Use of Galois/Counter Mode (GCM) in IPsec Encapsulating Security P
12、ayload (ESP), June 2005 RFC 4109 Algorithms for Internet Key Exchange version 1 (IKEv1), May 2005 RFC 4217 Securing FTP with TLS, October 2005 RFC 4251 The Secure Shell (SSH) Protocol Architecture, January 2006 RFC 4252 The Secure Shell (SSH) Authentication Protocol, January 2006 RFC 4253 The Secure
13、 Shell (SSH) Transport Layer Protocol, January 2006 RFC 4256 Generic Message Exchange Authentication for the Secure Shell Protocol (SSH), January 2006 RFC 4279 Pre-Shared Key Ciphersuites for Transport Layer Security (TLS), December 2005 RFC 4282 The Network Access Identifier, December 2005 RFC 4301
14、 Security Architecture for the Internet Protocol, December 2005 RFC 4302 IP Authentication Header, December 2005 RFC 4303 P Encapsulating Security Payload (ESP), December 2005 RFC 4304 Extended Sequence Number (ESN) Addendum to IPsec Domain of Interpretation (DOI) for Internet Security Association a
15、nd Key Management Protocol (ISAKMP), December 2005 RFC 4306 Internet Key Exchange (IKEv2) Protocol, December 2005 RFC 4307 Cryptographic Algorithms for Use in the Internet Key Exchange Version 2 (IKEv2), December 2005 RFC 4308 Cryptographic Suites for IPsec, December 2005 RFC 4309 Using Advanced Enc
16、ryption Standard (AES) CCM Mode with IPsec Encapsulating Security Payload (ESP), December 2005 RFC 4344 The Secure Shell (SSH) Transport Layer Encryption Modes RFC 4345 Improved Arcfour Modes for the Secure Shell (SSH) Transport Layer Protocol, January 2006 RFC 4346 The Transport Layer Security (TLS
17、) Protocol Version 1.1, April 2006 RFC 4347 Datagram Transport Layer Security, April 2006 RFC 4359 The Use of RSA/SHA-1 Signatures within Encapsulating Security Payload (ESP) and Authentication Header (AH), January 2006 RFC 4419 Diffie-Hellman Group Exchange for the Secure Shell (SSH) Transport Laye
18、r Protocol, March 2006 RFC 4432 RSA Key Exchange for the Secure Shell (SSH) Transport Layer Protocol, March 2006 RFC 4434 The AES-XCBC-PRF-128 Algorithm for the Internet Key Exchange Protocol (IKE), February 2006 RFC 4470 Minimally Covering NSEC Records and DNSSEC On-line Signing, April 2006 RFC 449
19、4 The AES-CMAC-96 Algorithm and Its Use with IPsec, June 2006 RFC 4510 Lightweight Directory Access Protocol (LDAP): Technical Specification Road Map, June 2006 RFC 4511 Lightweight Directory Access Protocol (LDAP): The Protocol, June 2006 RFC 4512 Lightweight Directory Access Protocol (LDAP): Direc
20、tory Information Models, June 2006 RFC 4513 Lightweight Directory Access Protocol (LDAP): Authentication Methods and Security Mechanisms, June 2006 RFC 4543 The Use of Galois Message Authentication Code (GMAC) in IPsec ESP and AH, May 2006 RFC 4567 Key Management Extensions for Session Description P
21、rotocol (SDP) and Real Time Streaming Protocol (RTSP), July 2006 RFC 4568 Session Description Protocol (SDP) Security Descriptions for Media Streams, July 2006 RFC 4615 The Advanced Encryption Standard-Cipher-based Message Authentication Code-Pseudo-Random Function-128 (AES-CMAC-PRF-128) Algorithm f
22、or the Internet Key Exchange Protocol (IKE), August 2006 RFC 4650 HMAC-Authenticated Diffie-Hellman for Multimedia Internet KEYing (MIKEY); September 2006 RFC 4718 IKEv2 Clarifications and Implementation Guidelines, October 2006 RFC 4738 MIKEY-RSA-R: An Additional Mode of Key Distribution in Multime
23、dia Internet KEYing (MIKEY), November 2006 ATIS-0100014 8 RFC 4785 Pre-Shared Key (PSK) Ciphersuites with NULL Encryption for Transport Layer Security (TLS), January 2007 RFC 4819 Secure Shell Public Key Subsystem, March 2007 RFC 4835 Cryptographic Algorithm Implementation Requirements for Encapsula
24、ting Security Payload (ESP) and Authentication Header (AH)., April 2007. RFC 4868 Using HMAC-SHA-256, HMAC-SHA-384, and HMAC-SHA-512 with IPsec, May 2007 RFC 4869 Suite B Cryptographic Suites for IPsec, May 2007 RFC 4895 Authenticated Chunks for the Stream Control Transmission Protocol (SCTP), Augus
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ATIS01000142007INFORMATIONCOMMUNICATIONSSECURITYFORNGNCONVERGEDSERVICESIPNETWORKSANDINFRASTRUCTUREPDF

链接地址:http://www.mydoc123.com/p-540849.html