標準號:BS ISO/IEC 10736-1995
中文標準名稱:信息技術.系統間信和信息交換.傳輸層安全協議
英文標準名稱:Information technology - Telecommunications and information exchange between systems - Transport layer security protocol
標準類型:L78
發布日期:1995/9/15 12:00:00
實施日期:1995/9/15 12:00:00
中國標準分類號:L78
國際標準分類號:35.100.40
適用范圍:The procedures specified in this Recommendation | International Standard operate as extensions to those defined in ITU-T Rec. X.224 | ISO/IEC 8073 and ITU-T Rec. X.234 | ISO/IEC 8602 and do not preclude unprotected communication between transport entities implementing ITU-T Rec. X.224 | ISO/IEC 8073 or ITU-T Rec. X.234 | ISO 8602.
The protection achieved by the security protocol defined in this Recommendation | International Standard depends on the proper operation of security management including key management. However, this Recommendation | International Standard does not specify the management functions and protocols needed to support this security protocol.
This protocol can support all the integrity, confidentiality, authentication and access control services identified in CCITT Rec. X.800 | ISO 7498-2 as relevant to the transport layer. The protocol supports these services through use of cryptographic mechanisms, security labelling and attributes, such as keys and authenticated identities, pre-established by security management or established through the use of the Security Association - Protocol (SA-P).
Protection can be provided only within the context of a security policy.
This protocol supports peer-entity authentication at the time of connection establishment. In addition, rekeying is supported within the protocol through the use of SA-P or through means outside the protocol.
Security associations can only be established within the context of a security policy. It is a matter for the users to establish their own security policy, which may be constrained by the procedures specified in this Recommendation | International Standard.
The following items could be included in a Security Policy:
a) the method of SA establishment/release, the lifetime of SA;
b) Authentication/Access Control mechanisms;
c) Label mechanism;
d) the procedure of the receiving an invalid TPDU during SA establishment procedure or transmission of protected PDU;
e) the lifetime of Key;
f) the interval of the rekey procedure in order to update key and security control information (SCI) exchange procedure;
g) the time out of SCI exchange and rekey procedure;
h) the number of retries of sci exchange and rekey procedure.
This Recommendation | International Standard defines a protocol which may be used for Security Association establishment. Entities wishing to establish an SA must share common mechanisms for authentication and key distribution. This Recommendation | International Standard specifies one algorithm for authentication and key distribution which is based on public key crypto systems. The implementation of this algorithm is not mandatory; however, when an alternative mechanism is used, it shall satisfy the following conditions:
a) All SA attributes defined in 5.2 are derived.
b) Derived keys are authenticated.
相關標準
百檢網專注于為第三方檢測機構以及中小微企業搭建互聯網+檢測電商服務平臺,是一個創新模式的檢驗檢測服務網站。百檢網致力于為企業提供便捷、高效的檢測服務,簡化檢測流程,提升檢測服務效率,利用互聯網+檢測電商,為客戶提供多樣化選擇,從根本上降低檢測成本提升時間效率,打破行業壁壘,打造出行業創新的檢測平臺。
百檢能給您帶來哪些改變?
1、檢測行業全覆蓋,滿足不同的檢測;
2、實驗室全覆蓋,就近分配本地化檢測;
3、工程師一對一服務,讓檢測更精準;
4、免費初檢,初檢不收取檢測費用;
5、自助下單 快遞免費上門取樣;
6、周期短,費用低,服務周到;
7、擁有CMA、CNAS、CAL等權威資質;
8、檢測報告權威有效、中國通用;