Cryptographic Terminology 101 £¨ÃÜÂëÊõÓï101£©[·Òë]
[color=blue][size=6]Cryptographic Terminology 101£¨ÃÜÂëÊõÓï101£©[·Òë][/size][/color]
[color=green]ÔÎÄ£º
[url]http://www.onlamp.com/pub/ct/15[/url]
×÷ÕߣºDru Lavigne
·Ò룺 rainren
±¾ÈËÄÜÁ¦ÓÐÏÞ£¬ ºÜ¶àµØ·½×ÔÎҸоõ¶¼·ÒëµÄ²»¶Ô£¬ Çë´ó¼ÒÖ¸³ö£¬ ÎÒÂýÂýÐ޸ġ£[/color]
ÔÚ½ÓÏÂÀ´µÄ¼¸ÆªÎÄÕÂÖУ¬ÎÒ½«½éÉÜÔõÑùÔÚÍøÂçÖа²È«µÄ´«ËÍÊý¾Ý¡£Èç¹ûÄ㻹¼ÇµÃIPÊý¾Ý°üϵÁУ¨²é¿´ ץȡTCP°ü -- ÔÎÄ£º see Capturing TCP Packets£©´ó²¿·ÖÍøÂç´«Êä¶¼ÊÇʹÓÃÃ÷ÎÄ´«Ê䣬 Óкܶàpacket sniffing¹¤¾ßÄܽ«ËüÃǽ⿪²é¿´ÐÅÏ¢¡£Èç¹ûÊý¾Ý°üÖк¬ÓÐusernames, passwords»òÆäËüһЩÃô¸ÐÊý¾Ý£¬ Õ⽫·Ç³£Ôã¸â¡£ÐÒÔ˵أ¬ ÓÐһЩ¹¤¾ß¿ÉÒÔ¼ÓÃÜÄãµÄÍøÂç´«Êä¡£
ÔÚÅäÖÃ֮ǰ£¬ ÄãÐèÒªÁ˽â¼ÓÃܵÄÌõ¼þºÍËü½«ÒªÊ¹ÓõÄËã·¨¡£ÕâһƪÊÇÃÜÂëÊõÓï101£¬ ½ÓÏÂÀ´µÄÎÄÕ½«ÊµÖ¤½éÉÜÈçºÎÔÚFreeBSDÉÏÅäÖÃʹÓá£
ʲôÊǼÓÃÜ£¬ ÄãΪʲôҪʹÓÃËü£¿¼ÓÃܹ¤¾ßʹÓÃ×éºÏËã·¨£¬ ËüÓÉÏÂÃæÈý¸ö²¿·Ö¹¹³É£ºprivacy, integrity, authenticity¡£²»Í¬µÄ¼ÓÃܹ¤¾ßʹÓò»Í¬µÄËã·¨£¬ µ«ËùÓÐÕâЩ¼ÓÃܹ¤¾ß¶¼ÐèÒªÕâÈý¸ö²¿·Ö¡£Ã¿Ò»¸ö¶¼ºÜÖØÒª£¬ ÈÃÎÒÃǷֱ𿴿´Ã¿Ò»²¿·Ö£º
[color=blue][size=4]Privacy[/size][/color]
Privacy±£Ö¤Ö»ÓнÓÊÕÕß²ÅÄÜÃ÷°×ÍøÂç´«ÊäµÄÄÚÈÝ¡£¼´Ê¹ÊÇÊý¾Ý°ü±»²¶»ñ£¬ ËüÒ²²»Äܽ«ÐÅÏ¢½â¿ªÔĶÁ¡£ÃÜÂëϵͳʹÓÃÒ»ÖÖ¼ÓÃÜËã·¨£¬ »òÃÜÂ룬 ÔÚ´«ÊäǰËü»á½«Ã÷ÎļÓÃܳÉÃÜÎÄ¡£Ö»ÓÐÌØ¶¨µÄ½ÓÊÕ¶¼²ÅÄÜʹÓÃÒ»¸ökey½«ÃÜÎĽâÃܳÉÃ÷ÎÄ¡£Õâ¸ökey´æÔÚÓÚ·¢ËÍÕߺͽÓÊÕÕßÖ®¼ä£¬ÓÃËüÀ´¼ÓÃܽâÃÜÎļþ¡£ÏÔÈ»£¬ÕâÖ»ÄÜÔÊÐí½ÓÊÕÕß²ÅÄÜÓÐÕâ¸ökey£¬ ·ñÔòÈκÎÈ˶¼¿ÉÒÔ½âÃÜÎļþÁË¡£
ÓÐЩÈËûÓÐkeyËû¿ÉÄÜ»áʹÓ÷ֽâ»ò²Â²â¼ÓÃÜÎļþµÄkeyÀ´½â¿ªÕâ¸öÃÜÂë¡£ Ò»¸öǿ׳µÄ¼ÓÃÜËã·¨Ó¦¸ÃÓÐÒ»¸öÔõÑù½â¿ªÃÜÂëµÄÄÑÒ×¶È¡£Í¨³££¬ ǿ׳µÄÌõ¼þʹÓÃbitsizeÀ´±íʾ¡£ÀýÈ磺½â¿ªÊ¹ÓÃ56λµÄ¼ÓÃÜËã·¨µÄʱ¼ä±ÈʹÓÃ256λ¼ÓÃÜËã·¨µÄʱ¼äÒªÉÙ¡£
ÕâÊÇ·ñ¾ÍÊÇ˵ÎÒÃÇÓ¦¸ÃʹÓþ¡¿ÉÄܶàµÄλµÄ¼ÓÃÜËã·¨ÄØ£¿²¢²»Ò»¶¨¡£ºÜÓдú±íÐԵأ¬ Ëæ×Åbit sizeµÄÔö¼Ó£¬ ¼ÓÃܽâÃÜÊý¾ÝÐèÒªµÄʱ¼ä»áÔ½À´Ô½³¤¡£ÔÚÏÖʵÖУ¬ Õâ¸öת»¯»á·¢·Ñ´óÁ¿CPUµÄ¹¤×÷ʱ¼äºÍÔö´óÍøÂçÁ÷Á¿¡£¸ù¾ÝÄãµÄÓ²¼þºÍÍøÂçÇé¿öÑ¡ÔñÊʵ±µÄ¼ÓÃÜbit size¡£½ü¼¸Ä꣬ CPUµÄ¹¤×÷ƵÂÊÔö¼ÓµÄºÜ¿ì¡£Õâ¾ÍÔÊÐíÎÒÃÇ¿ÉÒÔÑ¡ÔñʹÓýÏǿ׳µÄËã·¨¡£ÕâÑù£¬ ÄãÓ¦¸Ã¹ý¶Îʱ¼ä¾Í±ä¸ÄÄãµÄÃÜÂë¡£ºÜ¶à¼ÓÃÜϵͳ¿ÉÒÔ×Ô¶¯µÄ×öÕâÏ×÷¡£
»¹ÓÐһЩ±ðµÄÒòËØÓ°Ïìµ½ÈçºÎÑ¡Ôñ¼ÓÃÜËã·¨¡£ÓÐЩË㷨ʹÓÃÐèÒªlicenses»òרÀû£» ÓÐЩËã·¨ºÜÈÝÒ×±»ÆÆ½â£»ÓÐЩËã·¨±ÈʹÓÃͬÑùbit sizeµÄËã·¨¿ì»òÂý¡£È磺DESºÍ3DES¶¼ºÜÂý£¬¶øBlowfish¾¡¹ÜʹÓÃÁ˺ܴóµÄbit size£¬ µ«Ëü»¹ÊǺܿìËÙ¡£
ÿ¸ö¹ú¼ÒµÄ·¨Âɲ»Í¬£¬ һЩ¹ú¼Ò»áÇ¿ÐÐÏÞÖÆÊ¹Óá£Ò²¾ÍÊÇ˵Äã¿ÉÒÔÔÚ¹úÄÚʹÓÃÒ»¸öºÜǿ׳µÄ¼ÓÃÜËã·¨¼ÓÃÜÃô¸ÐÊý¾Ýµ«È´²»ÔÊÐí½«Ëü·¢Ë͸ø¹úÍâµÄ½ÓÊÕÕß¡£The United StatesÏÞÖÆÊ¹ÓÃ40λ¼ÓÃÜËã·¨¼ÓÃܵÄÊý¾Ý·¢Ë͵½¹úÍ⣬ Õâ¾ÍÊÇΪºÎÓÐЩË㷨ʹÓÃÉÙÓÚ40λ¼ÓÃܵÄÔÒò¡£
Èç¹ûÄ㲻ȷ¶¨ÄãËùÔڵĹú¼Ò¶ÔÕâ·½ÃæµÄÏÞÖÆ£¬ÔÚ¼ÓÃÜÄãµÄFreeBSDϵͳǰÏÈÕÒÕÒÏà¹ØµÄ×ÊÁÏ¡£
ÏÂÃæÏÔʾһЩËã·¨µÄʹÓÃÇé¿ö£º
Algorithm: DES Bit Size: 56 comment: slow, easily cracked
Algorithm: 3DES Bit Size: 168 comment: slow
Algorithm: Blowfish Bit Size: 32- 448 Patented: no Comment: extremely fast
Algorithm: IDEA Bit Size: 128 Patented: yes
Algorithm: CAST Bit Size: 40-128 Patented: yes
Algorithm: Arcfour Bit Size: 40, 128
Algorithm: AES(Rijndael) Bit Size: 128, 192, 256 Patented: no Comment: fast
Algorithm: Twofish Bit Size: 128, 256 Patended: no Comment: fast
ÔʼÊý¾Ý°üÔÚʹÓÃencryptionģʽʱÓÐÄÄЩÄÚÈݻᱻ¼ÓÃÜÄØ¡£Èç¹û¼ÓÃÜϵͳʹÓõÄÊÇ´«Êäģʽ£¬ ÔʼÊý¾Ý°üµÄ±¨Í·½«ÊÇÃ÷ÎÄ£¬ Ö»ÓÐÒ»²¿·ÖÊý¾Ý±»¼ÓÃÜ¡£Õâ¾ÍÊÇ˵£¬ ÍøÂçÐá̽Æ÷½Ø»ñµÄÊý¾Ý°üËäÈ»²»ÄÜ¿´µ½Êý¾Ý°üÀïµÄÄÚÈݵ«È´¿ÉÒÔÖªµÀ·¢ËÍÕߺͽÓÊÕÕßµÄIPµØÖ·ºÍ·¢ËͽÓÊÕʹÓõĶ˿ڡ£
Èç¹ûʹÓÃtunnelģʽ£¬ Õû¸öÊý¾Ý°ü°üÀ¨±¨Í·ºÍÄÚÈݶ¼½«±»¼ÓÃÜ¡£Êý¾Ý°ü»¹ÐèÒªµ½Ä¿µÄµØµÄ·ÓÉ£¬ ÏÖÔÚ3²ãеı¨Í·±»´´½¨¡£Ðµı¨Í·»á°üº¬ËùÓе½Ä¿µÄµØµÄIPµØÖ·¡££¨This is known as encapsulation, and it is quite possible that the new header contains totally different IP addresses than the original IP header£©¡£ÎÒÃǽ«ÔÚÏÂһƪΪFreeBSDϵͳÅäÖÃIPSECʱ¿´µ½ÎªÊ²Ã´»áÕâÑù¡£
[size=18][color=blue]Integrity[/color][/size]
IntegrityÊǼÓÃÜϵͳµÄµÚ¶þ²¿·Ö¡£Õⲿ·Ö±£Ö¤½ÓÊÕµ½µÄÊý¾Ý°üÔÚ´«Êä¹ý³ÌÖдæÔÚÍêÕûûÓжªÊ§¡£ÕâÐèÒªÒ»¸ö²»Í¬µÄËã·¨£¬È磺cryptographic checksums »ò cryptographic hashes¡£ÄãÓ¦¸ÃÊìϤʹÓÃchecksums¼ì²é¶Ô·½·¢Ë͹ýÀ´µÄÊý¾Ý°üµÄ˳Ðò¡£ËäÈ»frameºÍheader checksumsʹÓõÄËã·¨ºÜ¼òµ¥£¬ËüÃÇÖ»ÊǼòµ¥µÄÐÞ¸Äbits²¢ÇÒʹÓõÄÊÇÏàͬµÄËã·¨¡£Cryptographic checksums need to be more tamper-resistant¡£
ͬ¼ÓÃÜËã·¨Ò»Ñù£¬ Cryptographic checksumsÓв»Í¬µÄÓÃ;¡£Ô½³¤µÄЧÑéºÍÔ½ÄÑÒԸıäÊý¾ÝºÍÖÆ×÷ͬÑùµÄЧÑéºÍ¡£µ±È»£¬ÓÐһЩchecksumsÎÒÃÇÒÑÖªµÀËüµÄȱÏÝÁË¡£ÈçÏÂÃæËùʾ£º
Cryptographic checksum: MD4 Checksum Length: 128 Known Flaws: yes
Cryptographic checksum: MD5 Checksum Length: 128 Known Flaws: theoretical
Cryptographic checksum: SHA Checksum Length: 160 Known Flaws: theoretical
Cryptographic checksum: SHA-1 Checksum Length: 160 Known Flaws: not yet
ÉÏÃæÊÇÓÐÒâÅÅÁеġ£ÕýÈçËüËùʾ£ºMD4ÊÇ×î²»°²È«µÄ¶øSHA-1ÊÇ×ȫµÄ¡£Í¨³£Ó¦ÄÜΪÄãµÄ¼ÓÃÜϵͳѡÔñ¾¡¿ÉÄܸߵÄchecksum¼¶±ð¡£
ÔÚcryptographic ÀﻹÓÐÁíÍâÒ»ÖÖchecksum£ºHMAC»òHash-based Message Authentication Code¡£¼òҪ˵Ã÷£ºchecksum algorith £¨Ð§ÑéËã·¨£©Ê¹ÓÃchecksumЧÑéÖµ×÷ΪËã·¨µÄkey¡£ Good, Èç¹û²»ÄÜ·ÃÎÊÕâ¸ökeyÄ㽫ºÜÄѸıä checksum£¨Ð§ÑéÖµ£©¡£Èç¹ûÓÐCryptographic checksumʹÓÃHMAC£¬ Ëü½«»áÔÚchecksumÃû×ÖÇ°ÃæÏÔʾ³öÀ´¡£ÀýÈ磺HMAC-MD4±ÈMD4 °²È«£» HMAC-SHA±ÈSHA°²È«¡£Èç¹ûÎÒÃǶÔchecksum algorithm£¨Ð§ÑéËã·¨£©ÅÅÐò£¬ËüÈçÏÂËùʾ£º
? MD4
? MD5
? SHA
? SHA-1
? HMAC-MD4
? HMAC-MD5
? HMAC-SHA
? HMAC-SHA-1
[color=blue][size=4]Authenticity[/size][/color]
ÏÖÔÚ£¬ ÎÒÃDZ£Ö¤ÁËÊý¾ÝµÄ¼ÓÃܺÍËüÔÚ´«Êä¹ý³ÌÖÐûÓб»¸Ä±ä¡£µ«ÊÇÈç¹ûÎÒÃǵÄÊý¾Ý£¬ key±»´íÎóµÄ´«Ë͸ø´íÎóµÄ½ÓÊÕÕß½«Ôõô°ì£¿ Õâ¾ÍÊÇÎÒÃǵÚÈý²¿·ÖËùÒªÃèÊöµÄ£ºauthenticity¡£
ÔÚһЩ¼ÓÃÜË㷨ʹÓÃǰ£¬ key¿ÉÄÜÒÑ´´½¨ºÍ¸Ä±ä¡£ÔÚÒ»¸ösessionÖÐʹÓÃͬÑùµÄkey¼ÓÃܽâÃÜÊý¾Ý£¬Ëü»áÖªµÀÈçºÎ¶Ô³Æ»òsession key¡£ÎÒÃÇÓ¦ÔõÑù°²È«µÄ¸Ä±äÕâ¸ökeyÄØ£¿ÎÒÃÇÔõôÄÜÈ·¶¨ÎÒÃÇËù¸Ä±äµÄÕâ¸öKEYÖ»ÓнÓÊÕÕßÔÚʹÓöø²»»áÊÇÁíÍâµÄÈËÄØ£¿
Õâ¾ÍÐèÒª±ðµÄËã·¨ÀàÐÍÀ´Á˽ⲻ¶Ô³ÆÐÔ»ò¹«¹²Ãܳ×Ëã·¨¡£ÕâЩËã·¨¾ßÓв»¶Ô³ÆÐÔÊÇÒòΪËüÃÇÔÚ·¢ËÍÕߺͽÓÊÕÕßÖ®¼ä²¢²»Ê¹ÓÃͬÑùµÄKEY¡£Instead£¬ ·¢ËÍÕߺͽÓÊÕÕßÖ®¼ä·Ö±ð´´½¨Ãܳ׶ÔÀ´½øÐй¤×÷¡£½ÓÊÕÕß´Ó·¢ËÍÕßÄÇÀïÈ¡µÃÒ»·Ý¹«¹²Ãܳס£±ðµÄÃܳף¬ Èç˽³×£¬ ±ØÐë±£³ÖÒþÃÜ¡£Èç¹ûÓû§µÄ˽³×ÒѹýÆÚ£¬ ËûÓ¦¸ÃÁ¢¼´³·»ØÒÔǰµÄkey²¢ÖØÐ´´½¨ÐµÄÃܳ׶ԡ£
µ±Ãܳ׶Դ´½¨Ê±£¬ Ëü½«ÓÐÒ»¸ö¶ÀÌØµÄstring of short nonsense×÷Ϊfingerprint£¨Ö¸ÎÆ£©¡£Õâ¸öfingerprint£¨Ö¸ÎÆ£©¸øÄãÓÃÀ´¼ì²é¹«¹²Ãܳס£ÔÚУÑé½ÓÊÕÕßǰ£¬ ËüÃÇÊ×ÏÈÒª´«ÊäÒ»¸ö¹«¹²Ãܳ׸øÄã¡£ÄãÐèÒªdouble-check the fingerprint£¨Ö¸ÎÆ£©ÒÔÈñðÈËÖªµÀÄãÒÑÈ¡µÃÁ˹«¹²Ãܳס£ÔÚÏÂһƪÎÄÕÂÖÐÎÒÃÇ´´½¨Ãܳ׶ԣ¬ ÈÃÄã¿´×Ô¼ºµÄfingerprintʱ»áÓиü¶àµÄÁ˽⡣
´ó¶àÊýÃܳ״´½¨Ëã·¨ÊÇRSA¡£ÄãÆ½³£ÔÚÊý×ÖÖ¤Êé»òÈÏÖ¤ÖÐÐÄÓ¦¸Ã¿´µ½¹ýRSA¡£Êý×ÖÖ¤Êé°üº¬Á˽ÓÊÕÕßʹÓõĹ«¹²ÃÜ³×ºÍÆäËüһЩÐÅÏ¢£¬ »¹ÓÐÖÕÖ¹ÈÕÆÚ¡£The X.509 or PKCS #9 standard dictates the information found in a digital certificate. You can read the standard for yourself at [url]http://www.rsasecurity.com/rsalabs/pkcs[/url] or [url]http://ftp.isi.edu/in-notes/rfc2985.txt.¡£[/url]
Êý×ÖÖ¤Êéͨ³£×÷ΪCertificate Authority´æ´¢ÔÚ¼ÆËã»úÀï¡£Õâ¾ÍÊÇ˵×÷Ϊһ¸ö½ÓÊÕÕßÄã²¢²»ÐèÒªÊÖ¶¯Ð޸Ĺ«¹²Ãܳס£Instead£¬ÄãµÄϵͳ½«»áѯÎÊCNºÎʱcopyÒ»¸ö½ÓÊÕÕßʹÓõĹ«¹²Ãܳס£ÕâÐèÒªÒ»¸ö¿ÉÒÔÉý¼¶Ö¤ÊéµÄϵͳ¡£CAΪÐí¶à½ÓÊÕÕß´¢±¸ÁËÊý×ÖÖ¤Ê飬ÕâЩ½ÓÊÕÕß¿ÉÒÔÊÇÓû§»òµçÄÔ¡£
ͬÑù¿ÉÒÔʹÓÃDSAËã·¨À´²úÉúÊý×ÖÖ¤Êé¡£µ«Õâ¸öËã·¨ÐèҪרÀû²¢ÇÒ±ÈRSAÂý¡£Here is a FAQ on the difference between RSA and DSA. (The entire RSA Laboratories' FAQ is very good reading if you would like a more in depth understanding of cryptography.)
Êý×ÖÖ¤Êé°üº¬ÁËÖÕÖ¹ÈÕÆÚ£¬ÔÚÄÇÈÕÆÚǰ֤Êé²»»á´ÓCAɾ³ý¡£Èç¹ûÔÚÄǸöÈÕÆÚǰa private key±äµÃ²»°²È«Ôõô°ì£¿ ÄãÏÔÈ»ÒªÖØÐÂÈÏÖ¤Ò»¸öеÄpublic key¡£È»¶øÔÚ¹ýÆÚǰÄã²»ÄÜɾ³ý¾ÉµÄÈÏÖ¤¡£È·¶¨Ö¤Êé»áÔÚ²»×¢Òâʱȥǩ±ðÒ»¸ö½ÓÊÕÕߣ¬Äã¿ÉÒÔ½«Ëü·ÅÔÚCRL»òCertificate Revocation List¡£µ±Ö¤Êé±»ÇëÇóʱ£¬CRL»á±£ÕýÖ¤ÊéÈÔÈ»ÓÐЧ¡£
ÈÏÖ¤½ÓÊÕÕßÊÇauthenticity ²¿·ÖÒ»°ë¡£ÁíÒ»°ëÉæ¼°µ½ÔÚ¼ÓÃܽâÃÜÊý¾Ýʱµ±´´½¨Ò»¸ösession key ʱµÄ²úÉúºÍ¸Ä±äÐÅÏ¢¡£ÕâÀïͬÑùÐèÒªÒ»¸ö²»¶Ô³ÆËã·¨£¬ ÔÚÕâÀï½Ð Diffie Hellman»òDH¡£
ÈÏʶµ½Diffie Hellman Ëü×Ô¼º²¢²»²úÉúʵ¼ÊµÄsession keyÊÇÖØÒªµÄ£¬µ«ÊÇkeying informationÓÃÀ´²úÉúÄǸökey¡£This involves a fair bit of fancy math which isn't for the faint of heart. The best explanation I've come across, in understandable language with diagrams, is Diffie-Hellman Key Exchange - A Non-Mathematician's Explanation by Keith Palmgren¡£
It is important that the keying information is kept as secure as possible£¬ËùÒÔËüÔ½´óÔ½ºÃ¡£The possible Diffie Hellman bit sizes have been divided into groups. The following chart summarizes the possible Diffie Hellman Groups:
Group Name Bit Size
1 768
2 1024
5 1536
µ±ÅäÖÃÒ»¸ö¼ÓÃÜϵͳʱ£¬ÄãÓ¦¸ÃʹÓÃDiffie Hellman GroupÄÜÖ§³ÖµÄ×î´óλÊý¡£
ÁíÒ»¸öÓëkeying information£¨·¢±¨ÐÅÏ¢£©ÔÚÒ»ÆðµÄÊõÓïÊÇPFS£¬»òPerfect Forward Secrecy, Diffie HellmanÖ§³ÖËü¡£ PFS ensures that the new keying information is not mathematically related to the old keying information. PFSÄܱ£Ö¤ÐµÄkeying information²»»á±»ÁªÏµµ½ÔçµÄkeying informationÉÏ¡£Õâ¾ÍÊÇ˵Èç¹ûÍøÂçÐá̽Æ÷²¶»ñÁ˾ɵÄsession key£¬ ËüÒ²²»ÄÜ´ÓÉÏÃæ²Â²â³öеÄsession key¡£ PFSÊǷdz£°ôµÄ£¬ ÄãÓ¦¸ÃʹÄãµÄ¼ÓÃÜϵͳ֧³ÖËü¡£
[size=4][color=blue]Putting It All Together[/color][/size]
ÏÖÔÚÈÃÎÒÃǶԼÓÃÜϵͳÈçºÎ¶ÔÍøÂç´«ÊäÊý¾Ý½øÐмÓÃÜ×ö¸ö»Ø¹ËºÍ×ܽᡣ
1¡¢ Ê×ÏÈ£¬µ±Ç°½ÓÊÕÕßʹÓù«¹²Ãܳ×À´ÑéÖ¤Äã´«Ë͸øËûµÄÊý¾Ý¡£Õâ¸ö¹«¹²Ãܳ×ÊÇʹÓÃRSAËã·¨´´½¨£¬²¢×÷Ϊһ¸öÊý×ÖÖ¤Êé´æ´¢ÔÚCAÉÏ¡£
2¡¢ Ò»µ©½ÓÊÕÕß¾¹ýÑéÖ¤ºó£¬DHËã·¨½«Îª´´½¨session key´´½¨ÐÅÏ¢¡£
3¡¢ Ò»µ©keying informationµÃµ½ºó£¬×÷Ϊһ¸ö¶ÀÌØµÄkeyµÄsession±»´´½¨¡£Õâ¸öKEYÓÃÓÚ·¢ËÍÕߺͽÓÊÕÕßÖ®¼äµÄÊý¾Ý´«Ë͵ļÓÃܺͽâÃÜ¡£ÓÉÓÚÕâ¸ökeyºÜÖØÒª£¬ ËùÒÔËü»áʱ³£±ä¸ü¡£
4¡¢ ÔÚÊý¾Ý¼ÓÃÜǰ£¬»á½øÐÐÊʵ±µÄУÑé¡£µ±Êý¾Ý½øÐнâÃÜʱ£¬Ð£Ñé³ÌÐò»áÖØÐ¶ÔÊý¾Ý½øÐÐУÑ飬 ÒÔ±£Ö¤½ÓÊÕµ½µÄÊý¾ÝÊÇ·¢ËÍ·½·¢Ë͹ýÀ´µÄÔʼÊý¾Ý¡£
ÔÚÏÂһƪÎÄÕÂÖУ¬ ÔÚΪfreebsdϵͳÅäÖÃsshʱÄã»á¿´µ½ºÜ¶àÕâ·½ÃæµÄÐÅÏ¢¡£
[size=4][color=blue]ÕâÁ½ÌìÓеãÉϻ𣬠ÐÄÇé²»ºÃ£¬¶øÇÒ¶Ô¼ÓÃܽâÃÜ·½ÃæµÄÁ˽ⲻ¶à£¬ ·ÒëÖдæÔںܶà´íÎó£¬ Çë´ó¼ÒÖ¸³öÀ´£¬ ÎÒ»á¸ÄÕý£¡ лл£¡[/color][/size]
Ò³:
[1]