ECMA TR 46-1988 SECURITY IN OPEN SYSTEMS A SECURITY FRAMEWORK《开放系统中的安全性 一项安全框架》.pdf
《ECMA TR 46-1988 SECURITY IN OPEN SYSTEMS A SECURITY FRAMEWORK《开放系统中的安全性 一项安全框架》.pdf》由会员分享,可在线阅读,更多相关《ECMA TR 46-1988 SECURITY IN OPEN SYSTEMS A SECURITY FRAMEWORK《开放系统中的安全性 一项安全框架》.pdf(86页珍藏版)》请在麦多课文档分享上搜索。
1、ECMA EUROPEAN COMPUTER MAN U FACTURERS ASSOCIATIOR SECURITY IN OPEN SYSTEMS A SECURITY FRAMEWORK ECMA TR/46 July 1988 Free copies of this document are available from ECMA, European Computer Manufacturers Association 114 Rue du Khne- 1204 Geneva (Switzerland) ECMA EUROPEAN CO YPUTE R MAN U FACTURER S
2、 ASS OC1 ATIOIQ SECURITY IN OPEN SYSTEMS A SECURITY FRAMEWORK ECNIA TR/46 July 1988 Brief History ECMA, IS0 and CCITT are working on standards for distributed applications in an Open System environment. Exampla are the OS1 Reference Model, the work on Open Distributed Processing and the Framework fo
3、r Distributed Office Applications. Security is a major concern in information processing. The security aspects of interconnection have been addressed by IS0 in the work on the OS1 Reference Model (DIS 7498/2, Security Architecture). The purpose of this Technical Report is to provide a Framework for
4、the development of security provisions in the Application Layer. This Framework unifies many views of security needs and of security functionality including notions about end-systems security and therefore it allows a coherent approach to the specification of protocols and protocol elements as neede
5、d to realize secure Open Systems. This Report gives an overview of security needs and of the basic functionality needed to answer these needs. Using a generic building block approach it shows how supportive security applications may be constructed to satisfy a wide range of uses. in doing so this Re
6、port makes extensive use of the concepts developed in ECMA TW42, Framework for Distributed Office Applications as well as in ISO/OSI standards. However, other concepts such as the Object Model of processing used in the work of ECMMC32-TG2 on the Distributed Application Services Environment, may also
7、 be used to describe the security functions developed in this document. This Report is one of a set of Standards and Reports for Open Systems Interconnection. Open Systems Interconnection standards are intended to facilitate homogeneous interconnection between heterogeneous information processing sy
8、stems. This Report is within the framework for the coordination of standards for Open Systems Interconnection which is defined by IS0 7498. This Report is based on the practical experience of ECMA member Companies worldwide and on the results of their active participation in the work of IS0 and CCIT
9、 as well as in national standards bodies in Europe and the USA.lt represents a pragmatic, widely based consensus. This Report emphasises the need for specification of the externally visible and verifiable characteristics needed for the communication of security related information. However, it avoid
10、s placing unnecessary constraints upon the internal design and implementation of information processing system that process and exchange security related information. This Report is oriented towards urgent and well understood needs and supports rapid and effective standardization. It is intended to
11、be capable of extensions to cover future developments in technology and needs. Adopted as an ECMA Technical Report by the General Assembly of June 30, 1988. TABLE OF CONTENTS Page 1. INTRODUffION 1 1.1 Need and Application 1.2 Scope of Security in this Report 1.3 The Application Layer Security Frame
12、work 1.4 References 1.5 Definitions 1 21.1 General Terminology 1.5.2 Specific Terminology 1 S.3 Acronyms 2. REQUIREMENTS 2.1 Requirements on this Report 2.2 Environment Compatibility 2.3 General Security Requirements 2.3.1 User View Of Security 2.3.2 Threats to be addressed 2.3.3 Methods of Attack 2
13、.4 Security Policies and Domains 2.4.1 Security Policy 2.4.2 Security Administration Domains 2.4.3 Cooperation between Security Domains 2.4.4 Levels of Policy 2.4.5 Implementation of Policies 2.5 Functional Security Requirements 2.5.1 Access Control 2.5.2 Resource Protection 2.5.3 Information Protec
14、tion 2.5.4 Security Management 2.6 Implementation Considerations 2.6. I 2.6.2 Cryptography 2.7 Design Requirements Use of Supportive Applications 2.7.1 Separation of Functionality 2.7.2 Distributed Operation 2.7.3 RobustnesdResilience 2.7.4 Selective implementation 2.7.5 Usability 2.7.6 Evaluation a
15、nd Testing 2.7.7 Certification and Accreditation 4 4 7 7 7 8 8 8 9 10 10 10 11 11 12 13 14 14 15 16 17 18 18 19 19 19 19 20 20 20 20 3. SECURITY CONCEPTS AND MODELS 3.1 The Security Domain Concept 3. i .I Introduction 3.1.2 Autonomous Peer Domains 3.1.3 The Security Subdomain 3.1.4 Types of Security
16、 Domain 3.2 The Security Facility Concept 3.2.1 Introduction 4. DETAILED DESCRIPTION OF SECURITY FACILITIES 4.1 Subject Sponsor 4.1.1 Introduction 4.1.2 Functionality 4.1.3 Interaction With Other Facilities 4.1.4 4.1.5 Use of Other Applications 4.1.6 Facility Management 4.1.7 Interactions with Commu
17、nications Layer Management Characteristics of the Subject Sponsor 4.2 Authentication Facility 4.2.1 Introduction 4.2.2 4.2.3 Interactions With other Facilities 4.2.4 4.2.5 Use of Other Applications 4.2.6 Facility Management 4.3 Association Management Facility Functions Of the Authentication Facility
18、 Interactions with Communications Layer Management 4.3.1 Introduction 4.3.2 Functions of Association Management 4.3.3 Interaction With Other Facilities 4.3.4 4.3.5 Interactions With Other Applications 4.3.6 Facility Management Interactions With Communication Layer Management 4.4 Security State Facil
19、ity 4.4.1 Introduction 4.4.2 4.4.3 Interactions with other Facilities 4.4.4 4.4.5 Use Of Other Applications 4.4.6 Facility Management Functions Of the Security State Facility Interactions with Communication Layer Management 4.5 Security Attribute Management Facility 4.5.1 Introduction 4.5.2 Function
20、s Of the Facility 4.5.3 Interactions With other Facilities 4.5.4 4.5.5 Use of Other Applications 4.5.6 Facility Management Interactions with Communications Layer Management 20 20 20 21 21 23 25 25 29 29 29 29 30 30 31 31 31 31 31 32 32 33 33 33 34 34 34 35 35 36 36 36 36 36 36 36 37 37 37 37 38 38 3
21、8 39 39 4.6 Authorization Facility 4.6.1 Introduction 4.6.2 4.6.3 Interactions With other Facilities 4.6.4 4.6.5 Use of Other Applications 4.6.6 Facility Management Functions Of the Authorization Facility Interactions with Communications Layer Management 4.7 Inter-Domain Facility 4.7.1 Introduction
22、4.7.2 4.7.3 Interactions With other Facilities 4.7.4 4.7.5 Use of Other Applications 4.7.6 Facility Management Functions Of the Inter-Domain Facility Interactions with Communication Layer Management 4.8 Security Audit Facility 4.8.1 Introduction 4.8.2 4.8.3 interactions With other Facilities 4.8.4 4
23、.8.5 Use of Other Applications 4.8.6 Facility Management Functions Of The Security Audit Facility Interactions with Communications Layer Management 4.9 Security Recovery Facility 4.9.1 Introduction 4.9.2 Functions Of the Facility 4.9.3 Interactions With other Facilities 4.9.4 4.9.5 Use of Other Appl
24、ications 4.9.6 Facility Management Interactions with Communications Layer Management 4.1 O Cryptographic Support Facility 4. IO. I Introduction 4.10.2 Functions Of The Cryptographic Support Facility 4.10.3 Interactions With other Facilities 4.10.4 Interactions with Communications Layer Management 4.
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ECMATR461988SECURITYINOPENSYSTEMSASECURITYFRAMEWORK 开放系统 中的 安全性 一项 安全 框架 PDF

链接地址:http://www.mydoc123.com/p-704863.html