52
第第第 第第第第第第第第 第第第第第第第第第 第第第第第 第第第第第 、、 第第第第第第第第第第第第第第第第

4[1]

  • Upload
    peng-wu

  • View
    219

  • Download
    3

Embed Size (px)

Citation preview

  • 4.14.24.34.4

  • 4.1

  • : 50, 152%, , ,

    : 46/, 24 / :

  • Encryption)(Message Digest)(Digital Signature)(Secure Protocol)(Authentication Certificate)(Firewall)

  • 4.2

  • Cryptogram)Cryptography)Cryptosystem)Cryptanalysis)

  • (M)(K1)(K2)(C)(M)(M)

  • K1=K2)Private Key)K1K2)Public Key)

  • DES)RSA

  • kkk=3secure messagevhfxuh phvvdjh

  • abcdefghijklmnopqrstuvwxyzk=fivestarbcdghjklmnopquwxzysecure messageosvqns hsoofas

  • knnencryptm1mnk1knc1cn

  • DES) DESIBM1977DESm=m1m2m64k=k1k2k64DES(m)=IP-1T16T15T2T1IP(m)

  • DES)TiLiRifLi+1Ri+1+kiLi+1=RiRi+1=Lif(Ri,Ki)

  • RSAR. RivestA. Shamir L. Adleman1977RSA Data Security Inc., RSA Lab. 1982RSARSA

  • RSA p q n = p * q z =p -1*q -1)ez,eed e * d = 1 mod zd (n ,e)(n ,d)m
  • RSA p=43, q=59, n=pq=2537z=(p-1)*(q-1)=42*58=2436, e=13de=1(mod2436)d=937public key encryptionspu bl ic ke ye nc ry pt io ns1520 0111 0802 1004 2404 1302 1724 1519 0814 14180095 1648 1410 1299 1365 1379 2333 2132 1751 1289

  • RSA(M)(C)(M)

  • RSAn n RSA512n1998RSA768n,1024n2048n RSA768n2004

  • (M)(C)(M)

  • (Message Digest)hash,

  • Hashh=H(M)MhMhhMMMHMHMHushMihi-1hi

  • (Message Digest)MD5RivestRSAMDMD2MD5MD5128 bits1994$10,000,000MD5 24MD5

  • MD5 MD5("12345") = 827ccb0eea8a706c4c34a16891f84e7bMD5("abcde") = ab56b4d92b40713acc5af89985d4b786MD5("") = d41d8cd98f00b204e9800998ecf8427eMD5(" ") = 7215ee9c7d9dc229d2921a40e899ec5fMD5(" ") = 1545e945d5c3e7d9fa642d0a57fc8432

  • ++

  • 4.3Internet

  • InternetInternetSecure Socket Layer)SSL

  • InternetLink EncryptionIPSECSSLSHTTPPEM

  • SSL 1.Client sends ClentHello message2.Server acknowledges with ServerHello message3.Server sends its certificate4.Server requests Clients certificate5.Client sends its certificate6.Client sends ClentKeyExchange message7.Client sends Certificate Verify message8.Both send ChangeCipherSpec messages9.Both send Finished messageClientServer

  • zspswdInternet

  • IP166.111.78.47Internet166.111.78.10166.111.78.15166.111.78.47166.111.78.55...

  • RRRXXSYABSSY

  • ABC

  • (KDC)KDCHost AHost BHost CHost DKaKbKcKdKabKbcKcdKad

  • :1238038::34567546565:2000.12.31:543563546:12380567::64576475675:2000.12.31:546547876Internet(CA)

  • PKI)Root CABrand CABrand CAPersonal CASite CAMerchant CASoftware CA

  • Firewall)

  • Firewall)InternetInternetLANLANFirewall

  • Internet

  • Internet

  • Internet

  • 4.3