CAN CSA-ISO IEC 10181-5-2000 Information technology - Open Systems Interconnection - Security frameworks for open systems Confidentiality framework.pdf
《CAN CSA-ISO IEC 10181-5-2000 Information technology - Open Systems Interconnection - Security frameworks for open systems Confidentiality framework.pdf》由会员分享,可在线阅读,更多相关《CAN CSA-ISO IEC 10181-5-2000 Information technology - Open Systems Interconnection - Security frameworks for open systems Confidentiality framework.pdf(29页珍藏版)》请在麦多课文档分享上搜索。
1、National Standard of Canada CAN/CSA-ISO/!IEC 101 81-5-00 (ISO/IEC 101 81 -91 996) CSA f NT E RNAT I ONAL . International Standard ISO/IEC 10181-5:1996 (first edition 1996-09-15) has been adopted without modification as CSA Standard CAN/CSA-ISO/IEC 10181-5-00, which has been approved as a National St
2、andard of Canada by the Standards Council of Canada. ISBN 1-55324-082-0 March 2000 Information technology - Open Systems Interconnection - Security frameworks for open systems: Confidentiality framework Technologies de /information - lnterconnexion de s ystemes ouverts (USI - Cadres g this remains t
3、he continuing responsibility of the accredited standards-development organization. Those who have a need to apply standards are encouraged to use National Standards of Canada whenever practicable. These standards are subject to periodic review; therefore, users are cautioned to obtain the latest edi
4、tion from the organization preparing the standard. The responsibility for approving National Standards of Canada rests with the Standards Council of Canada 45 OConnor Street, Suite 1200 Ottawa, Ontario, K1 P 6N7 Canada A National Standard of Canada is a standard which CSA INTERNATIONAL c . Les norme
5、s nationales du Canada sont publi6es en versions frangaise et anglaise. Although the intended primary application of this Standard is stated in its Scope, it is important to note that it remains the responsibility of the users to judge its suitability for their particular purpose. lnformation techno
6、logy - Open Systems Interconnection - Security frameworks for open systems: Confidentiality frumework CAN/CSA-ISO/IfC I 0 7 8 7 -5-00 CAN/CSA-ISO/IEC 101 81-5-00 Information technology - Open Systems Interconnection - Security fkamavorks for open systems: Confidentiality Famework CSA Preface Standar
7、ds development within the Information Technology sector is harmonized with international standards development. Through the CSA Technical Committee on Information Technology (TCIT), Canadians serve as the Canadian Advisory Committee (CAC) on ISO/IEC Joint Technical Committee 1 on Information Technol
8、ogy (ISO/IEC jTC1) for the Standards Council of Canada (SCC), the IS0 member body for Canada and sponsor of the Canadian National Committee of the IEC. Also, as a member of the International Telecommunication Union (ITU), Canada participates in the lnternational Telegraph and Telephone Consultative
9、Committee (ITU-T). This International Standard was reviewed by the CSA TClT under the jurisdiction of the Strategic Steering Committee on Information Technology and deemed acceptable for use in Canada. (A committee membership list is available on request from the CSA Project Manager.) From time to t
10、ime, ISO/IEC may publish addenda, corrigenda, etc. The CSA TClT will review these documents for approval and publication. For a listing, refer to the CSA Information Products catalogue or CSA lnfo Update or contact a CSA Sales representative. This Standard has been formally approved, without modific
11、ation, by these Committees and has been approved as a National Standard of Canada by the Standards Council of Canada. March 2000 0 CSA lnternational- 2000 All rights reserved. No part of this publication may be reproduced in any form whatsoever without the prior permission of the publisher, /SO/IEC
12、material is reprinted with permission. Inquiries regarding this National Standard of Canada should be addressed to CSA lnternationol, 7 78 Rexdale Boulevard, Toronto, Ontario, M9W 7 R3. March 2000 CSA/I I NT E R N AT I 0 N A L STANDARD ISO/IEC 10181-5 First edition 1996-09-1 5 Information technology
13、 - Open Systems Interconnection - Security frameworks for open systems: Confidentiality framework Technologies de /information - lnterconnexion de systemes ouverts (OS!) - Cadres genemux pour la sewrite des systemes ouverts: Cadre gengral de confidentialit4 Reference number ISO/IEC 10181-5:1996(E) C
14、ontents scope Normative references . 2.1 Identical Recommendations I International Standards 2.2 Definitions 3.1 Basic Reference Model definitions . 3.2 Security architecture definitions . 3.3 Security frameworks overview definitions . 3.4 Additional definitions . Abbreviations . Paired Recommendati
15、ons I International Standards equivalent in technical content General discussion of confidentiality . 5.1 Basic concepts . 5.1.1 Protection of information 5.1.2 Hide and reveal operations 5.2 5.3 Types of confidentiality mechanisms 5.4 Threats to confidentiality 5.4.1 5.4.2 Types of confidentiality
16、attacks Classes of confidentiality services Threats when confidentiality is provided through access prevention . Threats when confidentiality is provided through information hiding . Confidentiality policies 6.1 Policy expression 6.1.1 Information characterization . 6.1.2 Entity characterization Con
17、fidentiality infomation and facilities 5.5 7.1 Confidentiality infomation . 7.1.1 Hiding confidentiality information . 7.1.2 Revealing confidentiality infomation 7.2.1 Operation related facilities 7.2.1.1 Hide . 7.2.1.2 Reveal . 7.2.2 Management related facilities . 7.2 Confidentiality facilities Q
18、ISO/IEC 1996 All rights reserved . Unless otherwise specified. no part of this publication may be reproduced or utilized in any form or by any means. electronic or mechanical. including photocopying and microfilm. without permission in writing from the pubtisher . ISO/EC Copyright Office Case postal
19、e 56 . CH-121 I Genkve 20 Switzerland Page 1 2 2 2 2 2 3 3 3 4 4 4 4 5 5 6 6 6 7 7 7 8 8 8 8 8 8 9 9 9 9 9 9 0 ISO/IEC LSOAEC 10181-5:1996(E) 8 9 Confidentiality mechanisms. Confidentiality provision through access prevention Confidentiality protection through physical media protection Confidentiali
20、ty protection through routing control . 8.1 8.1.1 8.1.2 8.2 8.3 Confidentiality provision through . encipherment Confidentiality provision through dummy events . Confidentiality provision through time varying fields 8.2.1 Confidentiality provision through data padding . 8.2.2 8.2.3 Confidentiality p
21、rovision through PDU header protection . 8.2.4 Confidentiality provision through contextual location . Interactions with other security services and mechanisms . 9.1 Access Control Annex A . Confidentiality in the OS1 Reference Model Annex B . Example of a sequence of movements through different con
22、fidentiality protected environments . Annex C . Representation of Information Annex D . Covert Channels Annex E . Confidentiality Facilities Outline 10 10 10 10 10 10 11 11 11 11 12 12 13 15 16 17 18 . 111 Q ISO/IEC Foreword IS0 (the International Organization for Standardization) and IEC (the Inter
23、national Electrotechnical Commission) form the specialized system for worldwide standardization. National bodies that are members of IS0 or IEC participate in the development of International Standards through technical committees established by the respective organization to deal with particular fi
24、elds of technical activity. IS0 and IEC technical committees coIlaborate in fields of mutual interest. Other international organizations, governmental and non-governmental, in liaison with IS0 and IEC, also take part in the work. In the field of information technology, IS0 and IEC have established a
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- CANCSAISOIEC1018152000INFORMATIONTECHNOLOGYOPENSYSTEMSINTERCONNECTIONSECURITYFRAMEWORKSFOROPENSYSTEMSCONFIDENTIALITYFRAMEWORKPDF

链接地址:http://www.mydoc123.com/p-590205.html