全网唯一标准王
D. Maughan Network working Group Request for Comments: 2408 National Security Agency Category: Standards Track M. Schertler Securify, Inc. M. Schneider National Security Agency J. Turner RABA Technologies, Inc. November 1998 Internet Security Association and Key Management Protocol (ISAKMP) Status of this Memo This document specifies an Internet standards track protocol for the Internet community, and requests discussion and suggestions for improvements. Please refer to the current edition of the "Internet Official Protocol Standards" (STD 1) for the standardization state and status of this protocol. Distribution of this memo is unlimited. Copyright Notice Copyright (C) The Internet Society (1998). All Rights Reserved. Abstract This memo describes a protocol utilizing security concepts necessary for establishing Security Associations (SA) and cryptographic keys in an Internet environment. A Security Association protocol that negotiates, establishes, modifies and deletes Security Associations and their attributes is required for an evolving Internet, where there will be numerous security mechanisms and several options for each security mechanism. The key management protocol must be robust in order to handle public key generation for the Internet community at large and private key requirements for those private networks with that requirement. The Internet Security Association and Key Management Protocol (ISAKMP) defines the procedures for authenticating a communicating peer, creation and management of Security Associations, key generation techniques, and threat mitigation (e.g. denial of service and replay attacks). All of these are necessary to establish and maintain secure communications (via IP Security Service or any other security protocol) in an Internet environment. Maughan, et. al. Standards Track [Page 1] RFC 2408 ISAKMP November 1998 Table of Contents 1 Introduction 4 1.1 Requirements Terminology 5 1.2 The Need for Negotiation 5 1.3 What can be Negotiated? 6 l.4 Security Associations and Management 7 1.4.1 Security Associations and Registration 7 1. 4.2 ISAKMP Requirements 8 1.5 Authentication 8 1.5.1 Certificate Authorities 9 1. 5.2 Entity Naming 9 1.5.3 ISAKMP Requirements 10 1.6 Public Key Cryptography 10 1.6.1 Key Exchange Properties 11 1.6.2 ISAKMP Requirements 12 1.7 ISAKMP Protection . 12 1.7.1 Anti-Clogging (Denial of Service) 12 1.7.2 Connection Hijacking 13 1.7.3 Man-in-the-Middle Attacks 13 1.8 Multicast Communications 13 2 Terminology and Concepts 14 2.1 ISAKMP Terminology 14 2.2 ISAKMP Placement 16 2. 3 Negotiation Phases 16 2.4 Identifying Security Associations 17 2.5 Miscellaneous . 20 2.5.1 Transport Protocol 20 2.5.2 RESERVED Fields 20 2.5.3 Anti-Clogging Token ("Cookie") Creation 20 3 ISAKMP Payloads 21 3.1 ISAKMP Header Format 21 3.2 Generic Payload Header 25 3.3 Data Attributes . 25 3.4 Security Association Payload 27 3.5 Proposal Payload 28 3. 6 Transform Payload 29 3.7 Key Exchange Payload 31 3.8 Identification Payload 32 3.9 Certificate Payload 33 3.10 Certificate Request Payload 34 3. 11 Hash Payload 36 3.12 Signature Payload 37 3. 13 Nonce Payload 37 3.14 Notification Payload 38 3.14.1 Notify Message Types 40 3.15 Delete Payload 41 3.16 Vendor ID Payload 43 Maughan, et. al. Standards Track [Page 2] ISAKMP RFC2408 November 1998 4 ISAKMP Exchanges 44 4.1 ISAKMP Exchange Types 45 4. 1.1 Notation 46 4.2 Security Association Establishment 46 4.2.1 Security Association Establishment Examples 48 4.3 Security Association Modification 50 4.4 Base Exchange . 51 4.5 Identity Protection Exchange 52 4.6 Authentication Only Exchange 54 4.7 Aggressive Exchange 55 4.8 Informational Exchange 57 5 ISAKMP Payload Processing 58 5.1 General Message Processing 58 5. 2 ISAKMP Header Processing 59 5. 3 Generic Payload Header Processing 61 5.4 Security Association Payload Processing 62 5.5 Proposal Payload Processing 63 5. 6 Transform Payload Processing 64 5.7 Key Exchange Payload Processing 65 5.8 Identification Pa

.pdf文档 rfc2408 Internet Security Association and Key Management Protocol (ISAKMP)173页

文档预览
中文文档 5 页 50 下载 1000 浏览 0 评论 309 收藏 3.0分
温馨提示:本文档共5页,可预览 3 页,如浏览全部内容或当前文档出现乱码,可开通会员下载原始文档
rfc2408 Internet Security Association and Key Management Protocol (ISAKMP)173页 第 1 页 rfc2408 Internet Security Association and Key Management Protocol (ISAKMP)173页 第 2 页 rfc2408 Internet Security Association and Key Management Protocol (ISAKMP)173页 第 3 页
下载文档到电脑,方便使用
本文档由 人生无常 于 2026-01-06 05:20:57上传分享
友情链接
站内资源均来自网友分享或网络收集整理,若无意中侵犯到您的权利,敬请联系我们微信(点击查看客服),我们将及时删除相关资源。