首页> 外文会议>Meeting of the internet engineering task force;IETF >Independent Data Unit Protection Generic Security Service Application Program Interface (IDUP-GSS-API)
【24h】

Independent Data Unit Protection Generic Security Service Application Program Interface (IDUP-GSS-API)

机译:独立数据单元保护通用安全服务应用程序接口(IDUP-GSS-API)

获取原文

摘要

The IDUP-GSS-API extends the GSS-API [RFC-2078] for applicationsrequiring protection of a generic data unit (such as a file ormessage) in a way which is independent of the protection of any otherdata unit and independent of any concurrent contact with designated'receivers' of the data unit. Thus, it is suitable for applicationssuch as secure electronic mail where data needs to be protectedwithout any on-line connection with the intended recipient(s) of thatdata. The protection offered by IDUP includes services such as dataorigin authentication with data integrity, data confidentiality withdata integrity, and support for non-repudiation services. Subsequentto being protected, the data unit can be transferred to therecipient(s) - or to an archive - perhaps to be processed('unprotected') only days or years later.Throughout the remainder of this document, the 'unit' of datadescribed in the above paragraph will be referred to as an IDU(Independent Data Unit). The IDU can be of any size (the applicationmay, if it wishes, split the IDU into pieces and have the protectioncomputed a piece at a time, but the resulting protection tokenapplies to the entire IDU). However, the primary characteristic ofan IDU is that it represents a stand-alone unit of data whoseprotection is entirely independent of any other unit of data. If anapplication protects several IDUs and sends them all to a singlereceiver, the IDUs may be unprotected by that receiver in any orderover any time span; no logical connection of any kind is implied bythe protection process itself.As with RFC-2078, this IDUP-GSS-API definition provides securityservices to callers in a generic fashion, supportable with a range ofunderlying mechanisms and technologies and hence allowing sourcelevelportability of applications to different environments. Thisspecification defines IDUP-GSS-API services and primitives at a levelindependent of underlying mechanism and programming languageenvironment, and is to be complemented by other, relatedspecifications:1. documents defining specific parameter bindings for particularlanguage environments;2. documents defining token formats, protocols, and procedures tobe implemented in order to realize IDUP-GSS-API services atop
机译:IDUP-GSS-API扩展了GSS-API [RFC-2078],适用于需要保护通用数据单元(例如文件消息)的应用程序,其方式独立于任何其他数据单元的保护并且独立于任何并发联系与数据单元的指定“接收方”。因此,它适用于需要保护数据而无需与该数据的预期接收者进行任何在线连接的应用,例如安全电子邮件。 IDUP提供的保护包括服务,例如具有数据完整性的数据源身份验证,具有数据完整性的数据机密性以及对不可否认服务的支持。在受到保护之后,可以仅在几天或几年后将数据单元转移到收件人(或存档),也许要对其进行处理(“未保护”)。在本文档的其余部分中,本文档中描述的数据“单元”上一段称为IDU(独立数据单元)。 IDU可以是任何大小(应用程序可以根据需要将IDU拆分为多个部分,并一次计算一个保护,但是最终得到的保护令牌适用于整个IDU)。但是,IDU的主要特征是它代表独立的数据单元,其保护完全独立于任何其他数据单元。如果某个应用程序保护多个IDU,并将它们全部发送到单个接收器,则该IDU可能在任何时间范围内不受任何顺序受该接收器的保护;与RFC-2078一样,此IDUP-GSS-API定义以通用方式向调用方提供安全服务,并受一系列底层机制和技术支持,因此允许应用程序在源代码级进行移植不同的环境。该规范在不依赖于底层机制和编程语言环境的级别上定义了IDUP-GSS-API服务和原语,并且将由其他相关规范进行补充:1。定义用于特定语言环境的特定参数绑定的文档; 2。定义令牌格式,协议和过程以实现IDUP-GSS-API服务之上的文档

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号