当前位置:高等教育资讯网  >  中国高校课件下载中心  >  大学文库  >  浏览文档

复旦大学:《密码学基础》课程教学资源(课件讲稿)11.1 IP Security

资源类别:文库,文档格式:PDF,文档页数:31,文件大小:675.92KB,团购合买
• Cryptography • Authentication techniques • PKI, CA, cert.
点击下载完整版文档(PDF)

密码学基础11.1 P Security 復大辱软件学院

1 密码学基础 11.1 IP Security

Review Cryptography Authentication techniques PKL CA cert 復大辱软件学院

2 Review • Cryptography • Authentication techniques • PKI, CA, cert

IP Security have a range of application specific security mechanisms eg. S/mime, Pgp, Kerberos, Ssl/Https however there are security concerns that cut across protocol layers would like security implemented by the network for all applications Q: If security mechanisms in app layer have implemented. Security is needed in network level? Or vice versa? 復大辱软件学院

3 IP Security • have a range of application specific security mechanisms – eg. S/MIME, PGP, Kerberos, SSL/HTTPS • however there are security concerns that cut across protocol layers • would like security implemented by the network for all applications • Q: If security mechanisms in app layer have implemented. Security is needed in network level? Or vice versa?

ota Security facilities in TCP/IP HttpfTpsmTp S/MIME PGP SET Http Ftp SmtP SSL or tls Kerberos SMTP Http TCP TCP UDP TCP IP/IPSec IP IP (a) Network Level (b)Transport Level (c)Application Level 復大辱软件学院

4 Security facilities in TCP/IP

IPSec general IP Security mechanisms ° provides authentication confidentiality key management applicable to use over LANs, across public private WANs,& for the Internet 復大辱软件学院

5 IPSec • general IP Security mechanisms • provides – authentication – confidentiality – key management • applicable to use over LANs, across public & private WANs, & for the Internet

IPSec Uses User system with IPSec Public(Internet) or Private Network Networking device with IPSec Networking device with IPSe 復大辱软件学院

6 IPSec Uses

Benefits of iPsec in a firewall/router provides strong security to all traffic crossing the perimeter in a firewall router is resistant to bypass is below transport layer, hence transparent to applications can be transparent to end users can provide security for individual users secures routing architecture 復大辱软件学院

7 Benefits of IPSec • in a firewall/router provides strong security to all traffic crossing the perimeter • in a firewall/router is resistant to bypass • is below transport layer, hence transparent to applications • can be transparent to end users • can provide security for individual users • secures routing architecture

o IP Security Architecture specification is quite complex defined in numerous rfCs -inc|.RFC2401/2402/2406/2408 many others, grouped by category mandatory in IPv6, optional in IPv4 have two security header extensions Authentication Header(ah) Encapsulating Security payload(EsP) 復大辱软件学院

8 IP Security Architecture • specification is quite complex • defined in numerous RFC’s – incl. RFC 2401/2402/2406/2408 – many others, grouped by category • mandatory in IPv6, optional in IPv4 • have two security header extensions: – Authentication Header (AH) – Encapsulating Security Payload (ESP)

PSec Services AH ESP (encryption ESP (encryption plus only) authentication) Access control Connectionless integrity Data origin authentication Rejection of replayed ackets Confidentiality Limited traffic flow confidentiality 復大辱软件学院

9 IPSec Services

IPSec Services Access control Connectionless integrity Data origin authentication Rejection of replayed packets a form of partial sequence integrity Confidentiality(encryption) Limited traffic flow confidentiality 復大辱软件学院

10 IPSec Services • Access control • Connectionless integrity • Data origin authentication • Rejection of replayed packets – a form of partial sequence integrity • Confidentiality (encryption) • Limited traffic flow confidentiality

点击下载完整版文档(PDF)VIP每日下载上限内不扣除下载券和下载次数;
按次数下载不扣除下载券;
24小时内重复下载只扣除一次;
顺序:VIP每日次数-->可用次数-->下载券;
共31页,可试读12页,点击继续阅读 ↓↓
相关文档

关于我们|帮助中心|下载说明|相关软件|意见反馈|联系我们

Copyright © 2008-现在 cucdc.com 高等教育资讯网 版权所有