资源描述:
《端口控制协议.doc》由会员上传分享,免费在线阅读,更多相关内容在工程资料-天天文库。
1、西安邮电大学毕业设计(译文)论文题目:端口接入控制协议院(系):通信与信息工程学院专业:信息安全班级:0801PortAccessControlProtocol1•Introductiontoprotocoloperation1.1OverviewTheoperationoftheauthenticationprocessmakesuseoftheExtensibleAuthenticationProtocol(EAP,specifiedinIETFRFC3748)asthemeansofcommunicatingauthenticationinformationbetweentheS
2、upplicantandtheAuthenticationServe匚EAPisageneralprotocolthatsupportsmultipleauthenticationmechanisms.Forexample,throughtheuseofEAP,supportforanumberofauthenticationschemesmaybeadded,includingsmartcards,Kerberos,PublicKeyEncryption,OneTimePasswords,andothers-Theapproachtakeninthisstandardistodefi
3、neanencapsulationformatthatallowsEAPMessagestobecarrieddirectlybyaLANMACservice.TheencapsulatedformofEARknownasEAPoverLANs,orEAPOL,isusedforallcommunicationbetweentheSupplicantPAEandtheAuthenticatorPAE.EachPAEhastwoseparatecomponents,asetofPACPstatemachines,andahigherlayerwithwhichthesemachinesc
4、ommunicate.InthecaseoftheSupplicantPAE,thehigherlayerconsistsofEAPfunctionality,whileinthecaseoftheAuthenticatorPAE,thehigherlayerisacombinationofEAPandauthentication,authorization,andaccounting(AAA)functionality.ThisstandarddefinesthePACPstatemachinesandtheinterfacebetweenthePACPstatemachinesan
5、dthehigher-layerfunctionality.Theoperationofthehigher-layerfunctionswithwhichthePAEstatemachinescommunicateisoutsidethescopeofthisstandard・EAPprotocolexchangesaredefinedbyIETFEAPstandards,IETFRFC374&andsuccessorstandards.OneexampleofaAAAprotocol,RADIUS,isdefinedbyIETFRADIUSstandards,IETFRFC2865,
6、IETFRFC2866,IETFRFC3579,andsuccessorstandards.Asshown,theportEnabledsignalfromthesystemindicatestoboththehigherlayerandthePACPthataportisactive.ThePACPpassesEAPmessagesbetweenthephysicalportandthehigherlayer.MessageflowontheAuthenticatorsideiscontrolledwithasimilarprocess,withthehigherlayerusing
7、eapReq/eapNoReq,toindicatewhenitisreadytoreceiveanewmessage,andeapResptoindicatethatamessageisavailabletobeprocessedbythehigherlayer.Withinthehigherlayer,EAPandassociatedEAPmethodsdrivetheauthenticationdialog,butoncompletion