tailieunhanh - MISSION CRITICAL! INTERNET SECURITY phần 3

S-HTTP không yêu cầu khách hàng để có giấy chứng nhận khóa công khai vì nó có thể sử dụng các phím đối xứng để cung cấp các giao dịch tư nhân. Các phím đối xứng sẽ được cung cấp trước bằng cách sử dụng truyền thông out-of-band. | IPSec Chapter 3 85 Although ISAKMP is responsible for supplying the consistent framework under which encryption keys are transferred it is not the same as a key exchange protocol. Additionally the ISAKMP protocol is not responsible for key generation encryption algorithms or authentication mechanisms. ISAKMP is responsible for supporting the negotiation of SAs at all levels of the OSI model and its centralization of management of SAs reduces the amount of duplicated functionality within each security protocol. A Security Association is a one-way connection that defines the security services that the traffic traveling through it will be using. Security services are granted to an SA through the use of the Authentication Header AH or Encrypting Security Payload ESP but not both. When using more than one security mechanism simultaneously then two or more SAs are created to afford protection to the traffic stream. To secure typical bi-directional communication between two hosts or between two security gateways two SAs one in each direction are required. Because there are two types of IPSec tunnels that can be created host to gateway and gateway to gateway there are two distinct types of SAs that can be defined transport mode and tunnel mode. A transport mode SA or an SA between two hosts the security header appears immediately after the IP header in IPv4 and after the base IP header and extensions in IPv6 see the Authentication Header section for more information . A tunnel mode SA is an SA applied to an IP tunnel. The general rule for tunnel mode is that if either end of the association is a security gateway the SA must be a tunnel mode SA. For the determination of what a gateway is you need to look at what activities the host is performing. If the host in question is transitioning traffic it is a gateway. If the host is the destination for the datagrams in question it is a host and will not require the tunnel mode SA. This distinction is made due to packet .

TỪ KHÓA LIÊN QUAN
crossorigin="anonymous">
Đã phát hiện trình chặn quảng cáo AdBlock
Trang web này phụ thuộc vào doanh thu từ số lần hiển thị quảng cáo để tồn tại. Vui lòng tắt trình chặn quảng cáo của bạn hoặc tạm dừng tính năng chặn quảng cáo cho trang web này.