William Stallings,Cryptography and Network Security 4e:威廉網(wǎng)絡(luò)密碼學(xué)與網(wǎng)絡(luò)安全4E_第1頁(yè)
William Stallings,Cryptography and Network Security 4e:威廉網(wǎng)絡(luò)密碼學(xué)與網(wǎng)絡(luò)安全4E_第2頁(yè)
William Stallings,Cryptography and Network Security 4e:威廉網(wǎng)絡(luò)密碼學(xué)與網(wǎng)絡(luò)安全4E_第3頁(yè)
William Stallings,Cryptography and Network Security 4e:威廉網(wǎng)絡(luò)密碼學(xué)與網(wǎng)絡(luò)安全4E_第4頁(yè)
William Stallings,Cryptography and Network Security 4e:威廉網(wǎng)絡(luò)密碼學(xué)與網(wǎng)絡(luò)安全4E_第5頁(yè)
已閱讀5頁(yè),還剩18頁(yè)未讀, 繼續(xù)免費(fèi)閱讀

下載本文檔

版權(quán)說(shuō)明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請(qǐng)進(jìn)行舉報(bào)或認(rèn)領(lǐng)

文檔簡(jiǎn)介

1、Cryptography and Network SecurityChapter 16Fourth Editionby William StallingsLecture slides by Lawrie BrownChapter 16 IP SecurityIf a secret piece of news is divulged by a spy before the time is ripe, he must be put to death, together with the man to whom the secret was told.The Art of War, Sun TzuI

2、P Securityhave a range of application specific security mechanismseg. S/MIME, PGP, Kerberos, SSL/HTTPShowever there are security concerns that cut across protocol layerswould like security implemented by the network for all applicationsIPSecgeneral IP Security mechanismsprovidesauthenticationconfide

3、ntialitykey managementapplicable to use over LANs, across public & private WANs, & for the InternetIPSec UsesBenefits of IPSecin a firewall/router provides strong security to all traffic crossing the perimeterin a firewall/router is resistant to bypassis below transport layer, hence transparent to a

4、pplicationscan be transparent to end userscan provide security for individual userssecures routing architectureIP Security Architecturespecification is quite complexdefined in numerous RFCsincl. RFC 2401/2402/2406/2408many others, grouped by categorymandatory in IPv6, optional in IPv4have two securi

5、ty header extensions:Authentication Header (AH)Encapsulating Security Payload (ESP)IPSec ServicesAccess controlConnectionless integrityData origin authenticationRejection of replayed packetsa form of partial sequence integrityConfidentiality (encryption)Limited traffic flow confidentialitySecurity A

6、ssociationsa one-way relationship between sender & receiver that affords security for traffic flowdefined by 3 parameters:Security Parameters Index (SPI)IP Destination AddressSecurity Protocol Identifierhas a number of other parametersseq no, AH & EH info, lifetime etchave a database of Security Ass

7、ociationsAuthentication Header (AH)provides support for data integrity & authentication of IP packetsend system/router can authenticate user/appprevents address spoofing attacks by tracking sequence numbersbased on use of a MACHMAC-MD5-96 or HMAC-SHA-1-96parties must share a secret keyAuthentication

8、 HeaderTransport & Tunnel ModesEncapsulating Security Payload (ESP)provides message content confidentiality & limited traffic flow confidentialitycan optionally provide the same authentication services as AHsupports range of ciphers, modes, paddingincl. DES, Triple-DES, RC5, IDEA, CAST etcCBC & othe

9、r modespadding needed to fill blocksize, fields, for traffic flowEncapsulating Security PayloadTransport vs Tunnel Mode ESPtransport mode is used to encrypt & optionally authenticate IP datadata protected but header left in clearcan do traffic analysis but is efficientgood for ESP host to host traff

10、ictunnel mode encrypts entire IP packetadd new header for next hopgood for VPNs, gateway to gateway securityCombining Security AssociationsSAs can implement either AH or ESPto implement both need to combine SAsform a security association bundlemay terminate at different or same endpointscombined byt

11、ransport adjacencyiterated tunnelingissue of authentication & encryption order Combining Security AssociationsKey Managementhandles key generation & distributiontypically need 2 pairs of keys2 per direction for AH & ESPmanual key managementsysadmin manually configures every systemautomated key manag

12、ementautomated system for on demand creation of keys for SAs in large systemshas Oakley & ISAKMP elementsOakleya key exchange protocolbased on Diffie-Hellman key exchangeadds features to address weaknessescookies, groups (global params), nonces, DH key exchange with authenticationcan use arithmetic

13、in prime fields or elliptic curve fieldsISAKMPInternet Security Association and Key Management Protocolprovides framework for key managementdefines procedures and packet formats to establish, negotiate, modify, & delete SAsindependent of key exchange protocol, encryption alg, & authentication methodISAKMPISAKMP Payloads & Exchangeshave a number of ISAKMP payload types:Security, Proposal, Transform, Key, Identification, Certificate, Certificate, Hash, Signature, Nonce, Notification, D

溫馨提示

  • 1. 本站所有資源如無(wú)特殊說(shuō)明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請(qǐng)下載最新的WinRAR軟件解壓。
  • 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請(qǐng)聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
  • 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁(yè)內(nèi)容里面會(huì)有圖紙預(yù)覽,若沒(méi)有圖紙預(yù)覽就沒(méi)有圖紙。
  • 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
  • 5. 人人文庫(kù)網(wǎng)僅提供信息存儲(chǔ)空間,僅對(duì)用戶上傳內(nèi)容的表現(xiàn)方式做保護(hù)處理,對(duì)用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對(duì)任何下載內(nèi)容負(fù)責(zé)。
  • 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請(qǐng)與我們聯(lián)系,我們立即糾正。
  • 7. 本站不保證下載資源的準(zhǔn)確性、安全性和完整性, 同時(shí)也不承擔(dān)用戶因使用這些下載資源對(duì)自己和他人造成任何形式的傷害或損失。

最新文檔

評(píng)論

0/150

提交評(píng)論