1、KS X 3705 KSKSKSKS SKSKSKS KSKSKS SKSKS KSKS SKS KS KS X 3705 :2007 (2012 ) 2007 11 30 http:/www.kats.go.krKS X 3705:2007 : ( ) ( ) SJ ( ) : (JTC1/SC6) () ( ) SK KS X 3705:2007 : (http:/www.standard.go.kr) : :1997 12 9 :2007 11 30 :2012 12 28 : 2012-0797 : (JTC1/SC6) ( 02-509-7262) (http:/www.kats.g
2、o.kr). 10 5 , . KS X 3705:2007 (2012 ) Information technologyTelecommunications and information exchange between systemsTransport layer security protocol 1995 1 ISO/IEC 10736, Information technologyTelecommunications and information exchange between systemsTransport layer security protocol , 5. . 1
3、KS X 3702 KS X 3703 , . . . KS X ISO/IEC 74982 , , . , , (SA-P) . . , SA-P . (SA) . . . a) SA / , SA b) / c) d) SA TPDU TPDU e) f) (SCI) g) SCI h) SCI KS X 3705:2007 2 . SA . , , . a) 5.2 SA . b) . 2 . . ( ) . KS X 3701, ITUT, Recommendation X.214(1993) | ISO 8072 :1994, Information technologyOpen S
4、ystems InterconnectionTransport service definition . KS X 3702, ISO/IEC 8073, Information technologyOpen Systems InterconnectionProtocol for providing the connection-mode transport service . KS X 3703, ITUT, Recommendation X.234(1993) | ISO/IEC 8602 :1995, Information technology Protocol for providi
5、ng the OSI connectionless-mode transport service . KS X 3704, ISO/IEC 11570:1992, Information technologyTelecommunications and information exchange between systemsOpen Systems InterconnectionTransport protocol identification mechanism . KS X 4002, (ASN.1) ISO/IEC 8824, Information technologyOpen Sys
6、tems InterconnectionSpecification of Abstract Syntax Notation One(ASN.1) . KS X 4003, (ASN.1) ISO/IEC 8825, Information technologyOpen Systems InterconnectionSpecification of Basic Encoding Rules for Abstract Syntax Notation One(ASN.1) . KS X ISO/IEC 74981, 1: ISO/IEC 74981:1994, Information technol
7、ogyOpen Systems InterconnectionBasic Reference ModelPart 1:The basic model . KS X ISO/IEC 74982, 2: ISO/IEC 74982, Information processing systemsOpen Systems InterconnectionBasic Reference ModelPart 2:Security Architecture . ISO/IEC 98341:1993, Information technology Open Systems Interconnection Pro
8、cedures for the operation of OSI Registration Authorities :General Procedures ISO/IEC 98343:1990, Information technology Open Systems Interconnection Procedures for the operation of OSI Registration Authorities Part 3 :Registration of object identifier component values for joint ISO-CCITT use CCITT,
9、 Recommendation X.200(1988), Reference Model of Open Systems Interconnection for CCITT applications KS X 3705:2007 3 ISO/IEC 74981:1994, Information technologyOpen Systems InterconnectionBasic Reference ModelPart 1:The Basic Model . CCITT, Recommendation X.800(1991), Security architecture for Open S
10、ystems Interconnection for CCITT applications ITUT, Recommendation X.224(1993), Protocol for providing the OSI connection-mode transport service CCITT, Recommendation X.208(1988), Specification of Abstract Syntax Notation One(ASN.1) CCITT, Recommendation X.209(1988), Specification of Basic Encoding
11、Rules for Abstract Syntax Notation One(ASN.1) ITUT, Recommendation X.264(1993), Transport protocol identification mechanism 3 KS X ISO/IEC 74981 KS X ISO/IEC 7498 2 . . 3.1 (cryptoperiod) 3.2 (in-band protocol mechanism) 3.3 (out-of-band protocol mechanism) 3.4 (pairwise key) 3.5 (reflection protect
12、ion) 3.6 (security association) SA 3.7 (security association attributes) 3.8 SE TPDU TPDU 4 . KS X 3705:2007 4 CR TPDU TPDU(Connection request TPDU) DC TPDU TPDU(Disconnection confirm TPDU) DR TPDU TPDU(Disconnection request TPDU) DST-REF Destination reference(field) DT TPDU TPDU(Data TPDU) ED TPDU
13、TPDU(Expedited Data TPDU) ED-TPDU-NR TPDU Expedited Data TPDU number(field) ER TPDU TPDU(Error TPDU) LI Length indicator(field) NC (Network Connection) SN (Sequence Number) SRC-REF Source Reference(field) TC (Transport Connection) TPDU (Transport protocol data unit) TPDU-NR DT TPDU DT TPDU number(fi
14、eld) CBTSS (Connection Based Transport Security Service) Conf_no (Confidentiality is not to be provided) Conf_yes (Confidentiality is to be provided) DEK (Data Encipherment Key) GTSS (General Transport Security Service) ICV (Integrity Chenck Value) Integ_no (Integrity is not to be provided) Integ_ye
15、s (Integrity is to be provided) KEK (Key Encipherment Key) KEY-ID (Key Identifier) Kg_esp (A separate cryptographic key is used for each end system pair) Kg_esp_sr (A separate cryptographic key is used for each end system pair and security level set) Kg_tc (A separate cryptographic key is used for e
16、ach Transport connection) LABEL (Security Label) LLSG (Lower Layer Security Guidelines) LME (Layer Management Entity) MDC (Mainpulation Detection Code) NSAP (Network Service Access Point) NSDU (Network Service Data Unit) PAD (Padding) Ppl_abs TPDU (Security Label never used on TPDUs) Ppl_pres TPDU (
17、Security Label used on every TPDU) SA-P (Security Association-Protocol) SE TPDU TPSU(Security Encapsulation TPDU) TLSP (Transport Layer Security Protocol) 5 TLSP . , , , , , , KS X 3705:2007 5 , . 6 (KS X 3702) (KS X 3703) . SE TPDU , , , TPDU TPDU , ICV , , . 7 KS X 3702 KS X 3703 . 8 TPDU TPDU(SE
18、TPDU) PUD . SE TPDU , , , ICV, ENC PAD . 9 A . A () . B () SA, , / . C () (QoS) . D () EKE EKE . KS X 3705:2007 6 ISO/IEC 10736:1995, Information technologyTelecommunications and information exchange between systemsTransport layer security protocol KS X 3705:2007 7 KS X 3705:2007 8 KS X 3705:2007 9
19、KS X 3705:2007 10 KS X 3705:2007 11 KS X 3705:2007 12 KS X 3705:2007 13 KS X 3705:2007 14 KS X 3705:2007 15 KS X 3705:2007 16 KS X 3705:2007 17 KS X 3705:2007 18 KS X 3705:2007 19 KS X 3705:2007 20 KS X 3705:2007 21 KS X 3705:2007 22 KS X 3705:2007 23 KS X 3705:2007 24 KS X 3705:2007 25 KS X 3705:20
20、07 26 KS X 3705:2007 27 KS X 3705:2007 28 KS X 3705:2007 29 KS X 3705:2007 30 KS X 3705:2007 31 KS X 3705:2007 32 KS X 3705:2007 33 KS X 3705:2007 34 KS X 3705:2007 35 KS X 3705:2007 36 KS X 3705:2007 37 KS X 3705:2007 38 KS X 3705:2007 39 KS X 3705:2007 40 KS X 3705:2007 41 KS X 3705:2007 42 KS X 3
21、705:2007 43 KS X 3705:2007 44 KS X 3705:2007 45 KS X 3705:2007 46 KS X 3705:2007 47 KS X 3705:2007 48 KS X 3705:2007 49 KS X 3705:2007 50 KS X 3705:2007 51 KS X 3705:2007 52 KS X 3705:2007 53 KS X 3705:2007 54 KS X 3705:2007 55 KS X 3705:2007 56 KS X 3705:2007 57 KS X 3705:2007 58 KS X 3705:2007 59
22、KS X 3705:2007 60 KS X 3705:2007 61 KS X 3705:2007 62 KS X 3705:2007 63 KS X 3705:2007 64 KS X 3705:2007 , . 1 , , . 2 . OSI . 3 1995 1 ISO/IEC 10736, Information technologyTelecommunications and information exchange between systemsTransport layer security protocol . 4 , ISO, IEC, ITU . , . , . 2 3
23、. , . , . , 2007 2 2 “KS A 0001:2007 ” KS , , “ ” . KS X 3705:2007 65 “ , .” , . 153787 1 145 3(16) (02)26240114 (02)26240148 http:/ KS X 3705 :2007KSKSKS SKSKS KSKS SKS KS SKS KSKS SKSKS KSKSKS Information technology Telecommunications and information exchange between systems Transport layer security protocol ICS 35.100.40 Korean Agency for Technology and Standards http:/www.kats.go.kr
copyright@ 2008-2019 麦多课文库(www.mydoc123.com)网站版权所有
备案/许可证编号:苏ICP备17064731号-1