1994年Netscape开发了SSL(Secure.pdfVIP

  • 11
  • 0
  • 约1.79万字
  • 约 54页
  • 2017-07-04 发布于河南
  • 举报
1994年Netscape开发了SSL(Secure

Chapter 7 WEB Security Instructor: Chen Xingshu 1 Outline • Web Security Considerations • Secure Socket Layer (SSL) and Transport Layer Security (TLS) • Secure Electronic Transaction (SET) • Recommended Reading and WEB Sites 2 7.1 Web Security Considerations 3 Web Security Considerations • The WEB is very visible. • Complex software hide many security flaws. • Web servers are easy to configure and manage. • Users are not aware of the risks. 4 Security facilities in the TCP/IP protocol stack 5 7.2 Security Socket Layer And Transport Layer Security 6 SSL and TLS • SSL was originated by Netscape • TLS working group was formed within IETF • First version of TLS can be viewed as an SSLv3.1 7 SSL/TLS协议 • 1994年Netscape开发了SSL(Secure Socket Layer)协议, 专门用于保护Web通讯 • 版本和历史 – 1.0,不成熟 – 2.0,基本上解决了Web通讯的安全问题 • Microsoft公司发布了PCT(Private Communication Technology),并在IE中支持 – 3.0,1996年发布,增加了一些算法,修改了一些缺陷 – TLS 1.0(Transport Layer Security, 也被称为SSL 3.1), 1997年IETF发布了Draft,同时,Microsoft宣布放弃 PCT,与Netscape一起支持TLS 1.0 – 1999年,发布RFC 2246(The TLS Protocol v1.0) 8 SSL/TLS协议 • 协议的设计目标 – 为两个通讯个体之间提供保密性和完整性(身份认证) – 互操作性

文档评论(0)

1亿VIP精品文档

相关文档