ECMA 271-1999 Extended Commercially Oriented Functionality Class for Security Evaluation (E - COFC)《安全性评估用扩展的面向商业的功能性类别(COFC) 第2版》.pdf
《ECMA 271-1999 Extended Commercially Oriented Functionality Class for Security Evaluation (E - COFC)《安全性评估用扩展的面向商业的功能性类别(COFC) 第2版》.pdf》由会员分享,可在线阅读,更多相关《ECMA 271-1999 Extended Commercially Oriented Functionality Class for Security Evaluation (E - COFC)《安全性评估用扩展的面向商业的功能性类别(COFC) 第2版》.pdf(46页珍藏版)》请在麦多课文档分享上搜索。
1、Standard ECMA-2712ndEdition - December 1999Standardizing Information and Communication SystemsPhone: +41 22 849.60.00 - Fax: +41 22 849.60.01 - URL: http:/www.ecma.ch - Internet: helpdeskecma.chExtended Commercially OrientedFunctionality Class for SecurityEvaluation (E - COFC).Standard ECMA-271Decem
2、ber 1999Standardizing Information and Communication SystemsPhone: +41 22 849.60.00 - Fax: +41 22 849.60.01 - URL: http:/www.ecma.ch - Internet: helpdeskecma.chLL ECMA-271.DOC 25-01-00 09,30Extended CommerciallyOriented Functionality Class forSecurity Evaluation (E - COFC)Brief HistoryECMA published
3、Standard ECMA-205 “Commercially Oriented Functionality Class for Security Evaluation (COFC)“ inDecember 1993. This standard was a contribution to the ongoing harmonization process for internationally accepted securityevaluation criteria, called Common Criteria.Standard ECMA-205 provided a set of fun
4、ctional criteria, which was based on commercial requirements with the additionalintention in mind to make security evaluation easier and therefore more economical. Many world wide operating computermanufacturers supported this approach.After completion of Standard ECMA-205, ECMA TC36 (IT Security) c
5、ontinued its work to extend the Standard into the areaof interconnected systems. This work had to consider network security as well as commercial requirements for secureelectronic business and secure electronic shopping and services.This new standard is based on the COFC and provides additional func
6、tionalities for an enterprise internal network ofinterconnected systems, for secure electronic business within a closed user group, and for secure electronic shopping andservices via a communication line or network. The standard takes aspects of protection against misuse, espionage, fraud etc.into a
7、ccount, but also legal aspects to secure business operations against denial of actually performed business actions.Standard ECMA-271 is called “Extended Commercially Oriented Functionality Class for Security Evaluation (E - COFC)“.The standard is based on ECMA-205 (COFC) and then hierarchically buil
8、t up with the Enterprise Business class as first layer,the Contract Business Class as second layer and the Public Business Class as third layer.After completion of Standard ECMA-271 (E-COFC) ECMA TC36 improved the E-COFC Standard to an E-COFC Version 2(Standard ECMA-271 Second Edition). This new ver
9、sion addresses the usage of the INTERNET in all three sub-classes andincorporates a number of corrections and improvements. The changes were mostly a result of the development of a ProtectionProfile for the E-COFC Standard. The E-COFC Protection Profile allows the binding of the E-COFC Functional Cr
10、iteria to theAssurance Criteria of the ISO/IEC/SC27 Common Criteria Standard. The motivation to develop the E-COFC ProtectionProfile was based on the fact that international mutual acceptance agreements are presently being negotiated. Once theseagreements are made, evaluations on the basis of E-COFC
11、 and the Common Criteria can be made and the results will beaccepted in all countries.The E-COFC Protection Profile for the Public Business Class is published as an ECMA Technical Report (ECMA TR/78).This second edition of Standard ECMA-271 has been adopted by the ECMA General Assembly of December 1
12、999.- i -Table of contents1Scope 12 Conformance 13 References 14 Definitions 14.1 Terms defined in this Standard 14.1.1 EB-class 14.1.2 CB-class 24.1.3 PB-class 24.1.4 Regulatory Board 24.1.5 Business action 24.1.6 Originator 24.1.7 Destination 24.1.8 Qualification of Originator and Destination 24.1
13、.9 Attestation of submission 24.1.10 Attestation of delivery 24.1.11 Attestation of reception by Destination 24.1.12 Commitment of Originator 24.1.13 Customer 24.1.14 Provider 24.2 Terms defined in Standard ECMA-205 (COFC) 24.2.1 Access right 24.2.2 Administration 24.2.3 Customer-specifiable 24.2.4
14、Identification 34.2.5 User identifier, user ID 34.3 Terms defined in other documents 35 Acronyms 36E - COFC 36.1 Overview 36.2 The TOE environment 46.3 Hierarchical subclasses 56.4 Usage of the INTERNET 67 The Enterprise Business class (EB-class) 67.1 The model 67.2 Commercial security requirements
15、77.2.1 Secure user authentication 7- ii -7.2.2 Secure client/server communication 77.2.3 Software integrity 77.2.4 Availability and reliability 77.2.5 Accountability and audit 77.3 Threat analysis 77.4 Security functionalities 97.4.1 Identification and authentication 97.4.2 Access Control 107.4.3 Cl
16、ient / server communication 117.4.4 Accountability and audit 117.4.5 Object reuse 137.4.6 Accuracy 137.4.7 Availability and reliability of service 137.4.8 Key management (if cryptographic means are applied by the TOE) 148 The Contract Business class (CB-class) 148.1 The model 148.1.1 Exchange of inf
17、ormation 158.1.2 Regulatory Board 158.1.3 Closed User Group Contract 158.2 Commercial security requirements 168.2.1 Authorization of Originator and Destination 168.2.2 Attestation of submission 178.2.3 Attestation of delivery 178.2.4 Attestation of reception by Destination 178.2.5 Commitment of Orig
18、inator and Destination 178.2.6 Chronology of events 178.2.7 Accountability and audit 178.2.8 Document integrity 178.2.9 Document confidentiality 178.3 Threat analysis 178.4 Security functionalities 188.4.1 Access control (user authorization) 188.4.2 Accountability and audit 189 The Public Business c
19、lass (PB-class) 189.1 The model 189.2 Commercial security requirements 199.2.1 Multistage identification and authentication 199.2.2 Interrelated commitments 199.2.3 Protection against unlawful multiple use of unique data 199.2.4 Unauthorized building of user profiles from business data 199.2.5 Inter
20、related accountability 199.3 Threat analysis 20- iii -9.4 Security functionalities 219.4.1 Identification and authentication 219.4.2 Access control 219.4.3 Accountability and audit 219.4.4 Communication of commitment data 219.4.5 Trust Center security functionalities (key management) 21Annex A (info
21、rmative) Examples for the Contract Business class (CB-class) 23Example 1: Sending a Contract 23Example 2: Order placement 24Example 3: Submitting an offer 24Example 4: Public call for tender 24Example 5: Financial order 25Annex B (informative) Examples of Customer/Provider based business (PB-class)
22、27Scenario 1: Customer/Provider public business 27Scenario 2: Customer/Provider public business via a credit card organization (CCO) 28Scenario 3: Customer/Provider public business with pay-card 29Scenario 4: Electronic advertising 30Annex C (informative) Terms defined in other documents 31.- 1 -1Sc
23、opeThe Extended Commercially Oriented Functionality Class (E - COFC) extends the application of ECMAs class ofcommercial security functions (Standard ECMA-205), to an environment of network based systems. The identifiedsecurity requirements specify a minimal set of security functions for interconnec
24、ted IT systems.COFCE-COFCFigure 1 - The ECMA security functionality classes2 ConformanceA TOE conforms to the requirements of this Standard if it conforms to Standard ECMA-205 and to the securityfunctionalities of at least one of the identified classes of this Standard (EB-Class, CB-Class, or PB-Cla
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ECMA2711999EXTENDEDCOMMERCIALLYORIENTEDFUNCTIONALITYCLASSFORSECURITYEVALUATIONECOFC 安全性 评估 扩展 面向 商业 功能

链接地址:http://www.mydoc123.com/p-704729.html