10. 参考文献
- 参考文献
本节列出 SSH Protocol Architecture 使用的规范性和资料性参考文献. 规范性参考文献定义 SSH 传输层、用户认证、连接协议、分配编号、需求关键词、IANA 注意事项、语言标签和 UTF-8. 资料性参考文献提供历史远程登录协议、Kerberos、GSS-API、TLS、HMAC、随机性、安全散列、AES、流量分析和 SSH 安全研究等背景.
引用条目中的作者、英文标题、RFC 编号、标准编号和 URL 保持原文, 以便与 RFC Editor、NIST、CERT 和会议论文资料准确核对. 中文括注只用于帮助读者快速理解文献主题.
从实现角度看, SSH 的规范性引用给出了架构文档以外的三个核心子协议和编号注册规则; 资料性引用则解释了 SSH 设计面对的威胁环境, 包括远程登录历史、密钥交换强度、随机性要求、认证加密、流量分析和时序攻击. 这些背景有助于理解为什么 SSH packet protocol、算法协商和认证层必须严格分离.
10.1. 规范性参考文献
[SSH-TRANS] Ylonen, T. and C. Lonvick, Ed., "The Secure Shell (SSH) Transport Layer Protocol" (Secure Shell (SSH) 传输层协议), RFC 4253, January 2006.
[SSH-USERAUTH] Ylonen, T. and C. Lonvick, Ed., "The Secure Shell (SSH) Authentication Protocol" (Secure Shell (SSH) 认证协议), RFC 4252, January 2006.
[SSH-CONNECT] Ylonen, T. and C. Lonvick, Ed., "The Secure Shell (SSH) Connection Protocol" (Secure Shell (SSH) 连接协议), RFC 4254, January 2006.
[SSH-NUMBERS] Lehtinen, S. and C. Lonvick, Ed., "The Secure Shell (SSH) Protocol Assigned Numbers" (Secure Shell (SSH) 协议分配编号), RFC 4250, January 2006.
[RFC2119] Bradner, S., "Key words for use in RFCs to Indicate Requirement Levels" (用于在 RFC 中表示 要求级别的关键词), BCP 14, RFC 2119, March 1997.
[RFC2434] Narten, T. and H. Alvestrand, "Guidelines for Writing an IANA Considerations Section in RFCs" (RFC 中 IANA 考量章节编写指南), BCP 26, RFC 2434, October 1998.
[RFC3066] Alvestrand, H., "Tags for the Identification of Languages" (语言标识标签), BCP 47, RFC 3066, January 2001.
[RFC3629] Yergeau, F., "UTF-8, a transformation format of ISO 10646" (UTF-8, ISO 10646 的转换格式), STD 63, RFC 3629, November 2003.
10.2. 资料性参考文献
[RFC0822] Crocker, D., "Standard for the format of ARPA Internet text messages" (ARPA Internet 文本消息 格式标准), STD 11, RFC 822, August 1982.
[RFC0854] Postel, J. and J. Reynolds, "Telnet Protocol Specification" (Telnet 协议规范), STD 8, RFC 854, May 1983.
[RFC1034] Mockapetris, P., "Domain names - concepts and facilities" (域名 - 概念和设施), STD 13, RFC 1034, November 1987.
RFC 4251 SSH Protocol Architecture January 2006
[RFC1282] Kantor, B., "BSD Rlogin", RFC 1282, December 1991.
[RFC4120] Neuman, C., Yu, T., Hartman, S., and K. Raeburn, "The Kerberos Network Authentication Service (V5)" (Kerberos 网络认证服务 (V5)), RFC 4120, July 2005.
[RFC1964] Linn, J., "The Kerberos Version 5 GSS-API Mechanism" (Kerberos 版本 5 GSS-API 机制), RFC 1964, June 1996.
[RFC2025] Adams, C., "The Simple Public-Key GSS-API Mechanism (SPKM)" (简单公钥 GSS-API 机制), RFC 2025, October 1996.
[RFC2085] Oehler, M. and R. Glenn, "HMAC-MD5 IP Authentication with Replay Prevention" (带重放防护的 HMAC-MD5 IP 认证), RFC 2085, February 1997.
[RFC2104] Krawczyk, H., Bellare, M., and R. Canetti, "HMAC: Keyed-Hashing for Message Authentication" (HMAC: 用于消息认证的密钥散列), RFC 2104, February 1997.
[RFC2246] Dierks, T. and C. Allen, "The TLS Protocol Version 1.0" (TLS 协议版本 1.0), RFC 2246, January 1999.
[RFC2410] Glenn, R. and S. Kent, "The NULL Encryption Algorithm and Its Use With IPsec" (NULL 加密算法及其 在 IPsec 中的使用), RFC 2410, November 1998.
[RFC2743] Linn, J., "Generic Security Service Application Program Interface Version 2, Update 1" (通用安全服务 应用程序接口版本 2, 更新 1), RFC 2743, January 2000.
[RFC3766] Orman, H. and P. Hoffman, "Determining Strengths For Public Keys Used For Exchanging Symmetric Keys" (确定用于交换对称密钥的公钥强度), BCP 86, RFC 3766, April 2004.
[RFC4086] Eastlake, D., 3rd, Schiller, J., and S. Crocker, "Randomness Requirements for Security" (安全所需的 随机性要求), BCP 106, RFC 4086, June 2005.
[FIPS-180-2] US National Institute of Standards and Technology, "Secure Hash Standard (SHS)" (安全散列标准), Federal Information Processing Standards Publication 180-2, August 2002.
[FIPS-186-2] US National Institute of Standards and Technology, "Digital Signature Standard (DSS)" (数字签名标准), Federal Information Processing Standards Publication 186- 2, January 2000.
RFC 4251 SSH Protocol Architecture January 2006
[FIPS-197] US National Institute of Standards and Technology, "Advanced Encryption Standard (AES)" (高级加密标准), Federal Information Processing Standards Publication 197, November 2001.
[ANSI-T1.523-2001] American National Standards Institute, Inc., "Telecom Glossary 2000" (电信术语表 2000), ANSI T1.523-2001, February 2001.
[SCHNEIER] Schneier, B., "Applied Cryptography Second Edition: protocols algorithms and source in code in C" (应用密码学第二版: 协议, 算法和 C 语言源码), John Wiley and Sons, New York, NY, 1996.
[SCHEIFLER] Scheifler, R., "X Window System : The Complete Reference to Xlib, X Protocol, Icccm, Xlfd, 3rd edition." (X Window System: Xlib, X Protocol, ICCCM, XLFD 完全参考, 第三版), Digital Press, ISBN 1555580882, February 1992.
[KAUFMAN] Kaufman, C., Perlman, R., and M. Speciner, "Network Security: PRIVATE Communication in a PUBLIC World" (网络安全: 公共世界中的私密通信), Prentice Hall Publisher, 1995.
[CERT] CERT Coordination Center, The., "http://www.cert.org/nav/index_red.html".
[VENEMA] Venema, W., "Murphy's Law and Computer Security", (墨菲定律与计算机安全), Proceedings of 6th USENIX Security Symposium, San Jose CA http://www.usenix.org/publications/library/ proceedings/sec96/venema.html, July 1996.
[ROGAWAY] Rogaway, P., "Problems with Proposed IP Cryptography" (拟议 IP 密码学的问题), Unpublished paper http://www.cs.ucdavis.edu/~rogaway/ papers/draft- rogaway-ipsec-comments-00.txt, 1996.
[DAI] Dai, W., "An attack against SSH2 protocol" (针对 SSH2 协议的攻击), Email to the SECSH Working Group [email protected] ftp:// ftp.ietf.org/ietf-mail-archive/secsh/2002- 02.mail, Feb 2002.
[BELLARE] Bellaire, M., Kohno, T., and C. Namprempre, "Authenticated Encryption in SSH: Fixing the SSH Binary Packet Protocol" (SSH 中的认证加密: 修复 SSH 二进制分组协议), Proceedings of the 9th ACM Conference on Computer and Communications Security, Sept 2002.
RFC 4251 SSH Protocol Architecture January 2006
[Openwall] Solar Designer and D. Song, "SSH Traffic Analysis Attacks" (SSH 流量分析攻击), Presentation given at HAL2001 and NordU2002 Conferences, Sept 2001.
[USENIX] Song, X.D., Wagner, D., and X. Tian, "Timing Analysis of Keystrokes and SSH Timing Attacks" (按键时序分析和 SSH 时序攻击), Paper given at 10th USENIX Security Symposium, 2001.