tailieunhanh - Firewalls and Internet Security, Second Edition phần 9

sáp nhập mạng trong tương lai. Phần trăm của tất cả các bộ định tuyến được phát hiện trên mạng nội bộ SNMP công chuỗi cộng đồng. Hầu hết các công ty muốn giá trị này là 0% Phần trăm của tất cả các bộ định tuyến được phát hiện trên mạng nội bộ phản ứng lo các chuỗi cộng đồng phổ biến SNMP | Modes of Operation 341 Cipher Feedback Mode Cipher Feedback CFB mode is a more complex mechanism for encrypting streams. If we are encrypting 128-bit blocks we encipher as follows Decryption is essentially the same operation That is. the last ciphertext block sent or received is fed back into the encryptor. As in OFB mode. AES is used in encryption mode only. If we are sending 8-bit bytes CFB8 mode is used. The difference is that the input to the AES function is from a shift register the 8 bits of the transmitted ciphertext are shifted in from the right and the leftmost 8 bits are discarded. Errors in received CFB data affect the decryption process while the garbled bits are in the shift register. Thus for CFB8 mode. 9 bytes are affected. The error in the first of these 9 bytes can be controlled by the enemy. As with OFB mode the IV for CFB encryption may and arguably should be transmitted in the clear. Counter Mode Counter mode is a new mode of operation suitable for use with AES. The underlying block cipher is used to encrypt a counter T. If the starting counter for plaintext block m is Tm Ci ---- P K Tm Tm ---- Tm 1 where Pi represents the AES blocks of a single message. A new Tm is picked for each message. While there is no mandatory mechanism for picking these counters care is needed Counter mode is a stream cipher with all the dangers that implies if a counter is ever reused. The usual scheme is to divide T into two sections. The left-hand section is a per-message value it can either be a message counter or some pseudorandom value. The right-hand section is the count of blocks within a message. It must be long enough to handle the longest message possible. The advantage of counter mode is that it s parallelizable. That is each block within a message can be encrypted or decrypted simultaneously with any other block. This allows a hardware designer to throw lots of chips at the problem of very high speed cryptography. The older modes such as CBC are

TỪ KHÓA LIÊN QUAN