標準號:BS ISO/IEC 10736-1995
中文標準名稱:信息技術(shù).系統(tǒng)間信和信息交換.傳輸層安全協(xié)議
英文標準名稱:Information technology - Telecommunications and information exchange between systems - Transport layer security protocol
標準類型:L78
發(fā)布日期:1995/9/15 12:00:00
實施日期:1995/9/15 12:00:00
中國標準分類號:L78
國際標準分類號:35.100.40
適用范圍:The procedures specified in this Recommendation | International Standard operate as extensions to those defined in ITU-T Rec. X.224 | ISO/IEC 8073 and ITU-T Rec. X.234 | ISO/IEC 8602 and do not preclude unprotected communication between transport entities implementing ITU-T Rec. X.224 | ISO/IEC 8073 or ITU-T Rec. X.234 | ISO 8602.
The protection achieved by the security protocol defined in this Recommendation | International Standard depends on the proper operation of security management including key management. However, this Recommendation | International Standard does not specify the management functions and protocols needed to support this security protocol.
This protocol can support all the integrity, confidentiality, authentication and access control services identified in CCITT Rec. X.800 | ISO 7498-2 as relevant to the transport layer. The protocol supports these services through use of cryptographic mechanisms, security labelling and attributes, such as keys and authenticated identities, pre-established by security management or established through the use of the Security Association - Protocol (SA-P).
Protection can be provided only within the context of a security policy.
This protocol supports peer-entity authentication at the time of connection establishment. In addition, rekeying is supported within the protocol through the use of SA-P or through means outside the protocol.
Security associations can only be established within the context of a security policy. It is a matter for the users to establish their own security policy, which may be constrained by the procedures specified in this Recommendation | International Standard.
The following items could be included in a Security Policy:
a) the method of SA establishment/release, the lifetime of SA;
b) Authentication/Access Control mechanisms;
c) Label mechanism;
d) the procedure of the receiving an invalid TPDU during SA establishment procedure or transmission of protected PDU;
e) the lifetime of Key;
f) the interval of the rekey procedure in order to update key and security control information (SCI) exchange procedure;
g) the time out of SCI exchange and rekey procedure;
h) the number of retries of sci exchange and rekey procedure.
This Recommendation | International Standard defines a protocol which may be used for Security Association establishment. Entities wishing to establish an SA must share common mechanisms for authentication and key distribution. This Recommendation | International Standard specifies one algorithm for authentication and key distribution which is based on public key crypto systems. The implementation of this algorithm is not mandatory; however, when an alternative mechanism is used, it shall satisfy the following conditions:
a) All SA attributes defined in 5.2 are derived.
b) Derived keys are authenticated.
相關(guān)標準
百檢網(wǎng)專注于為第三方檢測機構(gòu)以及中小微企業(yè)搭建互聯(lián)網(wǎng)+檢測電商服務(wù)平臺,是一個創(chuàng)新模式的檢驗檢測服務(wù)網(wǎng)站。百檢網(wǎng)致力于為企業(yè)提供便捷、高效的檢測服務(wù),簡化檢測流程,提升檢測服務(wù)效率,利用互聯(lián)網(wǎng)+檢測電商,為客戶提供多樣化選擇,從根本上降低檢測成本提升時間效率,打破行業(yè)壁壘,打造出行業(yè)創(chuàng)新的檢測平臺。
百檢能給您帶來哪些改變?
1、檢測行業(yè)全覆蓋,滿足不同的檢測;
2、實驗室全覆蓋,就近分配本地化檢測;
3、工程師一對一服務(wù),讓檢測更精準;
4、免費初檢,初檢不收取檢測費用;
5、自助下單 快遞免費上門取樣;
6、周期短,費用低,服務(wù)周到;
7、擁有CMA、CNAS、CAL等權(quán)威資質(zhì);
8、檢測報告權(quán)威有效、中國通用;