SecureDataTransmission-SouthernCaliforniae-Business数据传输-南加利福尼亚电子商务安全

上传人:ra****d 文档编号:252483750 上传时间:2024-11-16 格式:PPT 页数:28 大小:613.50KB
返回 下载 相关 举报
SecureDataTransmission-SouthernCaliforniae-Business数据传输-南加利福尼亚电子商务安全_第1页
第1页 / 共28页
SecureDataTransmission-SouthernCaliforniae-Business数据传输-南加利福尼亚电子商务安全_第2页
第2页 / 共28页
SecureDataTransmission-SouthernCaliforniae-Business数据传输-南加利福尼亚电子商务安全_第3页
第3页 / 共28页
点击查看更多>>
资源描述
Click to edit Master title style,Click to edit Master text styles,Second level,Third level,Fourth level,Fifth level,*,Secure Data Transmission,EDI-INT AS1,AS2,AS3,Kevin Grant,Goals of this Presentation,Understanding Security Mechanisms,Understanding Applicability Statements,MDNs,Secure Transmission Loop,AS1,AS2,AS3,Product Certification,AS1/AS2/AS3 Standards,Applicability Statements 1(AS1),2(AS2),&3(AS3)are the current specifications developed by EDI-INT for transporting data via the Internet.,AS Standards specify how to exchange data,not how to process data.,AS1 d,efines how to perform secure file transfers via SMTP,AS2 d,efines how to perform secure file transfers via HTTP,AS3 d,efines how to perform secure file transfers via FTP,Specify Security Services over a Specific Communication protocol with the introduction of,Message Disposition Notifications(MDNs)to complete the Secure Transmission Loop,AS1/AS2/AS3 Options,Encrypted or not encrypted,Signed or unsigned,Receipt or no receipt,Receipt signed,or not signed,AS1/AS2/AS3 Message Flow,Outgoing Message,SMTP/HTTP/FTP,Recipient,Signed MDN back to sender with hash,Message Encrypted with Recipients,Public,Key,Signature/Hash Applied and Encrypted with Senders,Private,Key,Signature/hash Decrypted with Senders,Public,Key,Message Decrypted with Recipients,Private,Key,Document hash is computed,Computed hash compared with transmitted hash,Incoming MessageValidated,Security Mechanisms,Three basic building blocks are used:,Encryption,is used to provide confidentiality,can provide authentication and integrity protection,Hash algorithms,are used to provide integrity protection,can provide authentication,Digital signatures,are used to provide authentication,integrity protection,and non-repudiation,One or more security mechanisms are combined to provide a security service,Security Protocol,A typical security protocol provides one or more,services,Services are built from,mechanisms,Mechanisms are implemented using,algorithms,Hash Functions,Hashing is the transformation of a string of characters into a shorter fixed-length value or key that represents the original string.,It is used to index and retrieve items in a database because it is faster to find the item using the shorter hashed key than to find it using the original value.,Hash Functions,It is also used in many encryption algorithms.,Creates a unique“fingerprint or message digest.,Anyone can alter the data and calculate a new hash value,Message digest has to be protected in some way,Public-key Encryption,Uses matched public/private key pairs(Asymmetric),Anyone can encrypt with the public key,only one person can decrypt with the private key,Cryptography Digital Signatures,Heres where the public-key algorithm and the hashing algorithm work together:,Certificates,A certificate is a public key that has been digitally signed by a,trusted third party,Certificate Authority(CA).,A Certification Authority(CA)guarantees a public keys authenticity,MDNs,(Message Disposition Notifications),Document acknowledgment,Non-repudiation of delivery(confirms the document WAS received and by whom),Confirms that the recipient was able to decrypt,Gives a status message,as appropriate,Contains the receivers computed hash for comparison against the one originally sent with the message,MDN may be signed by the recipient of the original message,Defined by your trading partner(optional),MDN Request Headers,The MDN is requested by the“Disposition-Notification-To field found in the message header:,AS2-Version:1.1,AS2-From:AS2SENDER,AS2-To:AS2RECEIVER,Subject:G1 Test Case,Message-Id:,Disposition-Notification-To:,Receipt-Delivery-Option:,Disposition-Notification-Options:signed-receipt-,protocol=optional,pkcs7-signature;,signed-receipt-micalg=optional,sha1,Content-Type:multipart/signed;boundary=as2BouNdary1as2;,protocol=application/pkcs7-signature;micalg=sha1,MDN Request Headers,The“Receipt-Delivery-Option field is used to request MDNs in an asynchronous manner.If this field is not present,the MDN is returning via the active HTTP session(AS2):,AS2-Version:1.1,AS2-From:AS2SENDER,AS2-To:AS2RECEIVER,Subject:G1 Test Case,Message-Id:,Receipt-Delivery-Option:,Disposition-Notification-Options:signed-receipt-,protocol=optional,pkcs7-signature;,signed-receipt-micalg=optional,sha1,Content-Type:multipart/signed;boundary=as2BouNdary1as2;,protocol=application/pkcs7-signature;micalg=sha1,MDN Request Headers,The“Disposition-Notification-Options field determines whether the MDN is to be signed and identifies the preferred hash algorithm(SHA-1 or MD5):,AS2-Version:1.1,AS2-From:AS2SENDER,AS2-To:AS2RECEIVER,Subject:G1 Test Case,Message-Id:,Receipt-Delivery-Option:,Disposition-Notification-Options:signed-receipt-,protocol=optional,pkcs7-signature;signed-receipt-micalg=optional,sha1,Content-Type:multipart/signed;boundary=as2BouNdary1as2;,protocol=application/pkcs7-signature;micalg=sha1,The“Secure Transmission Loop(STL),The originator sends a signed and encrypted documen
展开阅读全文
相关资源
正为您匹配相似的精品文档
相关搜索

最新文档


当前位置:首页 > 商业管理 > 商业计划


copyright@ 2023-2025  zhuangpeitu.com 装配图网版权所有   联系电话:18123376007

备案号:ICP2024067431-1 川公网安备51140202000466号


本站为文档C2C交易模式,即用户上传的文档直接被用户下载,本站只是中间服务平台,本站所有文档下载所得的收益归上传人(含作者)所有。装配图网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。若文档所含内容侵犯了您的版权或隐私,请立即通知装配图网,我们立即给予删除!