Abstract:
Based on the analysis of secure protocols ( e.g. IPSec. TLSP, etc. ) and secure systems ( e.g. Kerberos, SESAME, etc. ), the concept of generic security service primitives (GSSP) is proposed. Oriented to callers of various protocol layers, GSSP hides the implementation details of the underlying mechanisms. Some terms related to GSSP are defined, and a minimum set of primitives of GSSP is proposed, which includes security context management, security association management, and message encapsulation. Formal specification languages, SDL and MSC, are employed to describe the reference model of GSSP. Finally, an implementation instance of GSSP based on X509 framework is specified with SDL.