版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
1、Cryptography and Network SecurityChapter 16Fourth Editionby William StallingsLecture slides by Lawrie BrownChapter 16 IP SecurityIf a secret piece of news is divulged by a spy before the time is ripe, he must be put to death, together with the man to whom the secret was told.The Art of War, Sun TzuI
2、P Securityhave a range of application specific security mechanismseg. S/MIME, PGP, Kerberos, SSL/HTTPShowever there are security concerns that cut across protocol layerswould like security implemented by the network for all applicationsIPSecgeneral IP Security mechanismsprovidesauthenticationconfide
3、ntialitykey managementapplicable to use over LANs, across public & private WANs, & for the InternetIPSec UsesBenefits of IPSecin a firewall/router provides strong security to all traffic crossing the perimeterin a firewall/router is resistant to bypassis below transport layer, hence transparent to a
4、pplicationscan be transparent to end userscan provide security for individual userssecures routing architectureIP Security Architecturespecification is quite complexdefined in numerous RFCsincl. RFC 2401/2402/2406/2408many others, grouped by categorymandatory in IPv6, optional in IPv4have two securi
5、ty header extensions:Authentication Header (AH)Encapsulating Security Payload (ESP)IPSec ServicesAccess controlConnectionless integrityData origin authenticationRejection of replayed packetsa form of partial sequence integrityConfidentiality (encryption)Limited traffic flow confidentialitySecurity A
6、ssociationsa one-way relationship between sender & receiver that affords security for traffic flowdefined by 3 parameters:Security Parameters Index (SPI)IP Destination AddressSecurity Protocol Identifierhas a number of other parametersseq no, AH & EH info, lifetime etchave a database of Security Ass
7、ociationsAuthentication Header (AH)provides support for data integrity & authentication of IP packetsend system/router can authenticate user/appprevents address spoofing attacks by tracking sequence numbersbased on use of a MACHMAC-MD5-96 or HMAC-SHA-1-96parties must share a secret keyAuthentication
8、 HeaderTransport & Tunnel ModesEncapsulating Security Payload (ESP)provides message content confidentiality & limited traffic flow confidentialitycan optionally provide the same authentication services as AHsupports range of ciphers, modes, paddingincl. DES, Triple-DES, RC5, IDEA, CAST etcCBC & othe
9、r modespadding needed to fill blocksize, fields, for traffic flowEncapsulating Security PayloadTransport vs Tunnel Mode ESPtransport mode is used to encrypt & optionally authenticate IP datadata protected but header left in clearcan do traffic analysis but is efficientgood for ESP host to host traff
10、ictunnel mode encrypts entire IP packetadd new header for next hopgood for VPNs, gateway to gateway securityCombining Security AssociationsSAs can implement either AH or ESPto implement both need to combine SAsform a security association bundlemay terminate at different or same endpointscombined byt
11、ransport adjacencyiterated tunnelingissue of authentication & encryption order Combining Security AssociationsKey Managementhandles key generation & distributiontypically need 2 pairs of keys2 per direction for AH & ESPmanual key managementsysadmin manually configures every systemautomated key manag
12、ementautomated system for on demand creation of keys for SAs in large systemshas Oakley & ISAKMP elementsOakleya key exchange protocolbased on Diffie-Hellman key exchangeadds features to address weaknessescookies, groups (global params), nonces, DH key exchange with authenticationcan use arithmetic
13、in prime fields or elliptic curve fieldsISAKMPInternet Security Association and Key Management Protocolprovides framework for key managementdefines procedures and packet formats to establish, negotiate, modify, & delete SAsindependent of key exchange protocol, encryption alg, & authentication methodISAKMPISAKMP Payloads & Exchangeshave a number of ISAKMP payload types:Security, Proposal, Transform, Key, Identification, Certificate, Certificate, Hash, Signature, Nonce, Notification, D
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 2026江西九江市湖口县第一批单位选调事业编制工作人员备考题库完整答案详解
- 2026广西南宁职业技术大学公开招聘博士研究生备考题库及答案详解(新)
- 2025江苏南京医科大学第四附属医院(南京市浦口医院)招聘高层次人才5人备考题库及答案详解参考
- 2026云南保山市腾冲出入境边防检查站执勤队口岸协管(检)员招聘1人备考题库带答案详解
- 2026山东济宁市东方圣地人力资源开发有限公司招聘辅助服务人员5人备考题库及1套完整答案详解
- 2025福建福州市仓山区村(社区)专职人民调解员选聘1人备考题库及参考答案详解1套
- 2026中国联通上海市分公司校园招聘备考题库及1套完整答案详解
- 2026江苏南京大学SZYJ20260004能源与资源学院博士后招聘1人备考题库及答案详解参考
- 水解蒸煮工春节前安全考核试卷含答案
- 消费者权益保护服务手册(标准版)
- 2026年甘肃省兰州市皋兰县兰泉污水处理有限责任公司招聘笔试参考题库及答案解析
- 2025年全国高压电工操作证理论考试题库(含答案)
- 网络销售的专业知识培训课件
- CJJT 164-2011 盾构隧道管片质量检测技术标准
- 2024届高考语文复习:二元思辨类作文
- 《数字贸易学》教学大纲、二维码试题及答案
- 大锁孙天宇小品《时间都去哪了》台词剧本完整版-一年一度喜剧大赛
- 种子室内检验技术基础知识(种子质量检测技术课件)
- 智慧金库项目需求书
- DB41T 2397-2023 机关食堂反食品浪费管理规范
- TOC战略思想《关键链》
评论
0/150
提交评论