SNMPV 3
SNMPV 3
SNMPV 3
OVERVIEW:
DESIGN DECISIONS
ARCHITECTURE
SECURE COMMUNICATION
USER SECURITY MODEL (USM)
IMPLEMENTATIONS
DESIGN DECISIONS
SNMP ENTITY
SNMP APPLICATIONS
SNMP ENGINE
COMMAND NOTIFICATION
GENERATOR RECEIVER
SNMP ENTITY
OT HE R
SNMP ENGINE
snmpEngineID=1
SNMP ENTITY
O TH ER
SNMP ENGINE
snmpEngineID=2
SNMP ENTITY
SNMP ENTITY
O TH ER
O TH ER
SNMP ENGINE
SNMP ENGINE snmpEngineID=4
snmpEngineID=3
CONCEPTS: Context
contextName=card1 contextName=card2
OTHER
SNMP ENGINE
snmpEngineID=1
APPLICATIONS
• snmpTargetMIB
• snmpNotificationMIB
• snmpProxyMIB
• RFC 2573
SECURITY SUBSYSTEM
• USER BASED SECURITY MODEL
• snmpUsmMIB
• RFC 2574
contextEngineID
contextName
msgSecurityParameters SNMPv1
SNMPv2c
USM
contextEngineID
contextName
PDU
SECURE COMMUNICATION VERSUS ACCESS CONTROL
MANAGER AGENT
MIB
ACCESS CONTROL
MANAGER
APPLICATION PROCESSES
SECURE COMMUNICATION
TRANSPORT SERVICE
USM: SECURITY THREATS
PDU
IDEA BEHIND REPLAY PROTECTION
+ >?
KEY DATA
HASH FUNCTION
MAC
MAC
MAC
=?
DES-KEY DATA
DES ALGORITHM
ENCRYPTED DATA
IDEA BEHIND ENCRYPTION