← Documents Documentation/netlabel/draft-ietf-cipso-ipsecurity-01.txt GitHub 원문 ↗

Linux 6.18.37 · NetLabel

Commercial IP Security Option (CIPSO 2.2)

1992년 CIPSO option·tag 형식, label·DOI 구성과 packet 처리 규칙을 정의한 IETF 초안입니다.

Source pathDocumentation/netlabel/draft-ietf-cipso-ipsecurity-01.txt
Source versionLinux v6.18.37
TranslationDUJINLABS 전문 번역 + 해설

요약·해설과 원문, 전문 번역을 서로 분리했습니다. API 이름, symbol, source path는 원문 표기를 사용합니다.

1. 요약·해설

원문의 핵심 논리와 kernel programming 관점의 보충 설명입니다. 아래의 전문 번역과는 별도로 작성했습니다.

요약·해설

draft-ietf-cipso-ipsecurity-01.txt:1-791

CIPSO 2.2 초안은 IPv4 option type 134 안에 DOI와 MAC sensitivity tag를 담아 여러 mandatory-access-control 체계가 network label을 교환하게 합니다. Bitmap·enumerated·range category 표현을 정의하고, host·port label 경계 및 DOI mapping, 입력 오류의 ICMP 응답, gateway의 DOI 변환까지 상호 운용에 필요한 최소 규칙을 규범어로 명시합니다.

CIPSO option header
순서Field크기제약
1Type1 octet134
2Option length1 octet전체 길이, 최대 40
3DOI identifier4 octetsUnsigned, 0 금지, unaligned 가능
4Tags가변Datagram당 CIPSO option 한 번

원문 Figure 1의 bit-field ASCII를 field 단위로 구조화했습니다.

표준 CIPSO tag header
Field크기전송 규칙
Tag type1 octet0 예약, 1·2·5 정의
Tag length1 octetType·length 포함
Tag information가변Multi-octet은 network byte order

원문 Figure 2의 공통 tag 형식입니다.

MAC Sensitivity tag 비교
TagCategory 표현최대 표현정렬·순서
Type 1 bitmapBit position0~239MSB→LSB, 최소 encoding
Type 1 optimized10-octet bitmap0~79Trailing zero 채움
Type 2 enumerated2-octet 실제 값15 categories오름차순
Type 5 rangeTop/bottom 2-octet pair7 ranges비중첩 내림차순

원문 Figure 3·5·6의 공통 field와 category encoding을 비교합니다.

Tag type 1 bit 좌표
CategoryOctetBit 위치
00MSB
70LSB
81MSB
151LSB
N`floor(N/8)``7 - (N mod 8)`

원문 Figure 4의 category-to-bit ordering을 보존했습니다.

필수 configuration parameter
ParameterScope역할
`HOST_LABEL_MIN/MAX`HostHost가 처리할 label 범위
`PORT_LABEL_MIN/MAX`Interface portOutbound label 범위
`PORT_DOI`Port해당 port로 나가는 DOI
`NET_DOI`Destination network해당 network용 DOI
`HOST_DOI`Destination host해당 host용 DOI
`NET_LABEL`Single-label host유일한 inbound/outbound label

Label 허용 범위와 DOI 선택 scope를 구분합니다.

Inbound CIPSO 검증
Inbound datagramCIPSO 또는 port label 확보Field·tag 인식Host·port range 검사수락
알 수 없는 fieldDropICMP type 12 code 0Pointer=문제 field
유효하지만 range 밖DropICMP type 3 code 9 또는 10
필수 CIPSO 누락DropICMP type 12 code 1Pointer=134

Label 유무·형식·범위에 따라 수락 또는 ICMP 오류를 결정합니다.

입력 오류별 ICMP 응답
오류ICMP typeCodePointer
인식 불가 CIPSO field12 parameter problem0 bad parameterField 시작
Label range 밖3 destination unreachable9 network 또는 10 host prohibited해당 없음
필수 CIPSO 없음12 parameter problem1 option missing134
ICMP가 오류 원인응답 없음Message drop해당 없음

원문의 type·code·pointer 값을 그대로 정리했습니다.

Outbound label과 DOI 선택
Outbound datagram`PORT_LABEL_MIN <= label <= PORT_LABEL_MAX`truePORT·NET·HOST 중 지원 scope DOICIPSO option 1개전송
Range 검사falseDatagram drop

먼저 label 범위를 검사하고 구성된 scope의 DOI를 적용합니다.

Gateway DOI 변환
Source DOI optionCIPSO gatewaySensitivity·category 의미 해석Destination DOI mapping새 CIPSO optionForward

Network 경계를 넘을 때 destination network의 DOI mapping으로 security 값을 변환합니다.

규범적 최소 지원
대상최소 요구
Tag 생성Non-optimized type 1 MUST
Tag 수신모든 유효 type 1 MUST
DOI최소 1개 MUST, 여러 개 SHOULD
GatewayDOI 간 변환 MUST
Broadcast network공통 DOI 최소 1개 권고
ICMP label원 datagram과 동등 MUST

초안이 MUST와 SHOULD로 요구한 핵심 interoperability 조건입니다.

2. 영어 원문 전체

번역 기준이 된 Linux v6.18.37 원문입니다. 줄 번호는 이 버전의 파일 좌표입니다.

원문 전체 펼치기
1 IETF CIPSO Working Group
2 16 July, 1992
3
4
5
6 COMMERCIAL IP SECURITY OPTION (CIPSO 2.2)
7
8
9
10 1. Status
11
12 This Internet Draft provides the high level specification for a Commercial
13 IP Security Option (CIPSO). This draft reflects the version as approved by
14 the CIPSO IETF Working Group. Distribution of this memo is unlimited.
15
16 This document is an Internet Draft. Internet Drafts are working documents
17 of the Internet Engineering Task Force (IETF), its Areas, and its Working
18 Groups. Note that other groups may also distribute working documents as
19 Internet Drafts.
20
21 Internet Drafts are draft documents valid for a maximum of six months.
22 Internet Drafts may be updated, replaced, or obsoleted by other documents
23 at any time. It is not appropriate to use Internet Drafts as reference
24 material or to cite them other than as a "working draft" or "work in
25 progress."
26
27 Please check the I-D abstract listing contained in each Internet Draft
28 directory to learn the current status of this or any other Internet Draft.
29
30
31
32
33 2. Background
34
35 Currently the Internet Protocol includes two security options. One of
36 these options is the DoD Basic Security Option (BSO) (Type 130) which allows
37 IP datagrams to be labeled with security classifications. This option
38 provides sixteen security classifications and a variable number of handling
39 restrictions. To handle additional security information, such as security
40 categories or compartments, another security option (Type 133) exists and
41 is referred to as the DoD Extended Security Option (ESO). The values for
42 the fixed fields within these two options are administered by the Defense
43 Information Systems Agency (DISA).
44
45 Computer vendors are now building commercial operating systems with
46 mandatory access controls and multi-level security. These systems are
47 no longer built specifically for a particular group in the defense or
48 intelligence communities. They are generally available commercial systems
49 for use in a variety of government and civil sector environments.
50
51 The small number of ESO format codes can not support all the possible
52 applications of a commercial security option. The BSO and ESO were
53 designed to only support the United States DoD. CIPSO has been designed
54 to support multiple security policies. This Internet Draft provides the
55 format and procedures required to support a Mandatory Access Control
56 security policy. Support for additional security policies shall be
57 defined in future RFCs.
58
59
60
61
62 Internet Draft, Expires 15 Jan 93 [PAGE 1]
63
64
65
66 CIPSO INTERNET DRAFT 16 July, 1992
67
68
69
70
71 3. CIPSO Format
72
73 Option type: 134 (Class 0, Number 6, Copy on Fragmentation)
74 Option length: Variable
75
76 This option permits security related information to be passed between
77 systems within a single Domain of Interpretation (DOI). A DOI is a
78 collection of systems which agree on the meaning of particular values
79 in the security option. An authority that has been assigned a DOI
80 identifier will define a mapping between appropriate CIPSO field values
81 and their human readable equivalent. This authority will distribute that
82 mapping to hosts within the authority's domain. These mappings may be
83 sensitive, therefore a DOI authority is not required to make these
84 mappings available to anyone other than the systems that are included in
85 the DOI.
86
87 This option MUST be copied on fragmentation. This option appears at most
88 once in a datagram. All multi-octet fields in the option are defined to be
89 transmitted in network byte order. The format of this option is as follows:
90
91 +----------+----------+------//------+-----------//---------+
92 | 10000110 | LLLLLLLL | DDDDDDDDDDDD | TTTTTTTTTTTTTTTTTTTT |
93 +----------+----------+------//------+-----------//---------+
94
95 TYPE=134 OPTION DOMAIN OF TAGS
96 LENGTH INTERPRETATION
97
98
99 Figure 1. CIPSO Format
100
101
102 3.1 Type
103
104 This field is 1 octet in length. Its value is 134.
105
106
107 3.2 Length
108
109 This field is 1 octet in length. It is the total length of the option
110 including the type and length fields. With the current IP header length
111 restriction of 40 octets the value of this field MUST not exceed 40.
112
113
114 3.3 Domain of Interpretation Identifier
115
116 This field is an unsigned 32 bit integer. The value 0 is reserved and MUST
117 not appear as the DOI identifier in any CIPSO option. Implementations
118 should assume that the DOI identifier field is not aligned on any particular
119 byte boundary.
120
121 To conserve space in the protocol, security levels and categories are
122 represented by numbers rather than their ASCII equivalent. This requires
123 a mapping table within CIPSO hosts to map these numbers to their
124 corresponding ASCII representations. Non-related groups of systems may
125
126
127
128 Internet Draft, Expires 15 Jan 93 [PAGE 2]
129
130
131
132 CIPSO INTERNET DRAFT 16 July, 1992
133
134
135
136 have their own unique mappings. For example, one group of systems may
137 use the number 5 to represent Unclassified while another group may use the
138 number 1 to represent that same security level. The DOI identifier is used
139 to identify which mapping was used for the values within the option.
140
141
142 3.4 Tag Types
143
144 A common format for passing security related information is necessary
145 for interoperability. CIPSO uses sets of "tags" to contain the security
146 information relevant to the data in the IP packet. Each tag begins with
147 a tag type identifier followed by the length of the tag and ends with the
148 actual security information to be passed. All multi-octet fields in a tag
149 are defined to be transmitted in network byte order. Like the DOI
150 identifier field in the CIPSO header, implementations should assume that
151 all tags, as well as fields within a tag, are not aligned on any particular
152 octet boundary. The tag types defined in this document contain alignment
153 bytes to assist alignment of some information, however alignment can not
154 be guaranteed if CIPSO is not the first IP option.
155
156 CIPSO tag types 0 through 127 are reserved for defining standard tag
157 formats. Their definitions will be published in RFCs. Tag types whose
158 identifiers are greater than 127 are defined by the DOI authority and may
159 only be meaningful in certain Domains of Interpretation. For these tag
160 types, implementations will require the DOI identifier as well as the tag
161 number to determine the security policy and the format associated with the
162 tag. Use of tag types above 127 are restricted to closed networks where
163 interoperability with other networks will not be an issue. Implementations
164 that support a tag type greater than 127 MUST support at least one DOI that
165 requires only tag types 1 to 127.
166
167 Tag type 0 is reserved. Tag types 1, 2, and 5 are defined in this
168 Internet Draft. Types 3 and 4 are reserved for work in progress.
169 The standard format for all current and future CIPSO tags is shown below:
170
171 +----------+----------+--------//--------+
172 | TTTTTTTT | LLLLLLLL | IIIIIIIIIIIIIIII |
173 +----------+----------+--------//--------+
174 TAG TAG TAG
175 TYPE LENGTH INFORMATION
176
177 Figure 2: Standard Tag Format
178
179 In the three tag types described in this document, the length and count
180 restrictions are based on the current IP limitation of 40 octets for all
181 IP options. If the IP header is later expanded, then the length and count
182 restrictions specified in this document may increase to use the full area
183 provided for IP options.
184
185
186 3.4.1 Tag Type Classes
187
188 Tag classes consist of tag types that have common processing requirements
189 and support the same security policy. The three tags defined in this
190 Internet Draft belong to the Mandatory Access Control (MAC) Sensitivity
191
192
193
194 Internet Draft, Expires 15 Jan 93 [PAGE 3]
195
196
197
198 CIPSO INTERNET DRAFT 16 July, 1992
199
200
201
202 class and support the MAC Sensitivity security policy.
203
204
205 3.4.2 Tag Type 1
206
207 This is referred to as the "bit-mapped" tag type. Tag type 1 is included
208 in the MAC Sensitivity tag type class. The format of this tag type is as
209 follows:
210
211 +----------+----------+----------+----------+--------//---------+
212 | 00000001 | LLLLLLLL | 00000000 | LLLLLLLL | CCCCCCCCCCCCCCCCC |
213 +----------+----------+----------+----------+--------//---------+
214
215 TAG TAG ALIGNMENT SENSITIVITY BIT MAP OF
216 TYPE LENGTH OCTET LEVEL CATEGORIES
217
218 Figure 3. Tag Type 1 Format
219
220
221 3.4.2.1 Tag Type
222
223 This field is 1 octet in length and has a value of 1.
224
225
226 3.4.2.2 Tag Length
227
228 This field is 1 octet in length. It is the total length of the tag type
229 including the type and length fields. With the current IP header length
230 restriction of 40 bytes the value within this field is between 4 and 34.
231
232
233 3.4.2.3 Alignment Octet
234
235 This field is 1 octet in length and always has the value of 0. Its purpose
236 is to align the category bitmap field on an even octet boundary. This will
237 speed many implementations including router implementations.
238
239
240 3.4.2.4 Sensitivity Level
241
242 This field is 1 octet in length. Its value is from 0 to 255. The values
243 are ordered with 0 being the minimum value and 255 representing the maximum
244 value.
245
246
247 3.4.2.5 Bit Map of Categories
248
249 The length of this field is variable and ranges from 0 to 30 octets. This
250 provides representation of categories 0 to 239. The ordering of the bits
251 is left to right or MSB to LSB. For example category 0 is represented by
252 the most significant bit of the first byte and category 15 is represented
253 by the least significant bit of the second byte. Figure 4 graphically
254 shows this ordering. Bit N is binary 1 if category N is part of the label
255 for the datagram, and bit N is binary 0 if category N is not part of the
256 label. Except for the optimized tag 1 format described in the next section,
257
258
259
260 Internet Draft, Expires 15 Jan 93 [PAGE 4]
261
262
263
264 CIPSO INTERNET DRAFT 16 July, 1992
265
266
267
268 minimal encoding SHOULD be used resulting in no trailing zero octets in the
269 category bitmap.
270
271 octet 0 octet 1 octet 2 octet 3 octet 4 octet 5
272 XXXXXXXX XXXXXXXX XXXXXXXX XXXXXXXX XXXXXXXX XXXXXXXX . . .
273 bit 01234567 89111111 11112222 22222233 33333333 44444444
274 number 012345 67890123 45678901 23456789 01234567
275
276 Figure 4. Ordering of Bits in Tag 1 Bit Map
277
278
279 3.4.2.6 Optimized Tag 1 Format
280
281 Routers work most efficiently when processing fixed length fields. To
282 support these routers there is an optimized form of tag type 1. The format
283 does not change. The only change is to the category bitmap which is set to
284 a constant length of 10 octets. Trailing octets required to fill out the 10
285 octets are zero filled. Ten octets, allowing for 80 categories, was chosen
286 because it makes the total length of the CIPSO option 20 octets. If CIPSO
287 is the only option then the option will be full word aligned and additional
288 filler octets will not be required.
289
290
291 3.4.3 Tag Type 2
292
293 This is referred to as the "enumerated" tag type. It is used to describe
294 large but sparsely populated sets of categories. Tag type 2 is in the MAC
295 Sensitivity tag type class. The format of this tag type is as follows:
296
297 +----------+----------+----------+----------+-------------//-------------+
298 | 00000010 | LLLLLLLL | 00000000 | LLLLLLLL | CCCCCCCCCCCCCCCCCCCCCCCCCC |
299 +----------+----------+----------+----------+-------------//-------------+
300
301 TAG TAG ALIGNMENT SENSITIVITY ENUMERATED
302 TYPE LENGTH OCTET LEVEL CATEGORIES
303
304 Figure 5. Tag Type 2 Format
305
306
307 3.4.3.1 Tag Type
308
309 This field is one octet in length and has a value of 2.
310
311
312 3.4.3.2 Tag Length
313
314 This field is 1 octet in length. It is the total length of the tag type
315 including the type and length fields. With the current IP header length
316 restriction of 40 bytes the value within this field is between 4 and 34.
317
318
319 3.4.3.3 Alignment Octet
320
321 This field is 1 octet in length and always has the value of 0. Its purpose
322 is to align the category field on an even octet boundary. This will
323
324
325
326 Internet Draft, Expires 15 Jan 93 [PAGE 5]
327
328
329
330 CIPSO INTERNET DRAFT 16 July, 1992
331
332
333
334 speed many implementations including router implementations.
335
336
337 3.4.3.4 Sensitivity Level
338
339 This field is 1 octet in length. Its value is from 0 to 255. The values
340 are ordered with 0 being the minimum value and 255 representing the
341 maximum value.
342
343
344 3.4.3.5 Enumerated Categories
345
346 In this tag, categories are represented by their actual value rather than
347 by their position within a bit field. The length of each category is 2
348 octets. Up to 15 categories may be represented by this tag. Valid values
349 for categories are 0 to 65534. Category 65535 is not a valid category
350 value. The categories MUST be listed in ascending order within the tag.
351
352
353 3.4.4 Tag Type 5
354
355 This is referred to as the "range" tag type. It is used to represent
356 labels where all categories in a range, or set of ranges, are included
357 in the sensitivity label. Tag type 5 is in the MAC Sensitivity tag type
358 class. The format of this tag type is as follows:
359
360 +----------+----------+----------+----------+------------//-------------+
361 | 00000101 | LLLLLLLL | 00000000 | LLLLLLLL | Top/Bottom | Top/Bottom |
362 +----------+----------+----------+----------+------------//-------------+
363
364 TAG TAG ALIGNMENT SENSITIVITY CATEGORY RANGES
365 TYPE LENGTH OCTET LEVEL
366
367 Figure 6. Tag Type 5 Format
368
369
370 3.4.4.1 Tag Type
371
372 This field is one octet in length and has a value of 5.
373
374
375 3.4.4.2 Tag Length
376
377 This field is 1 octet in length. It is the total length of the tag type
378 including the type and length fields. With the current IP header length
379 restriction of 40 bytes the value within this field is between 4 and 34.
380
381
382 3.4.4.3 Alignment Octet
383
384 This field is 1 octet in length and always has the value of 0. Its purpose
385 is to align the category range field on an even octet boundary. This will
386 speed many implementations including router implementations.
387
388
389
390
391
392 Internet Draft, Expires 15 Jan 93 [PAGE 6]
393
394
395
396 CIPSO INTERNET DRAFT 16 July, 1992
397
398
399
400 3.4.4.4 Sensitivity Level
401
402 This field is 1 octet in length. Its value is from 0 to 255. The values
403 are ordered with 0 being the minimum value and 255 representing the maximum
404 value.
405
406
407 3.4.4.5 Category Ranges
408
409 A category range is a 4 octet field comprised of the 2 octet index of the
410 highest numbered category followed by the 2 octet index of the lowest
411 numbered category. These range endpoints are inclusive within the range of
412 categories. All categories within a range are included in the sensitivity
413 label. This tag may contain a maximum of 7 category pairs. The bottom
414 category endpoint for the last pair in the tag MAY be omitted and SHOULD be
415 assumed to be 0. The ranges MUST be non-overlapping and be listed in
416 descending order. Valid values for categories are 0 to 65534. Category
417 65535 is not a valid category value.
418
419
420 3.4.5 Minimum Requirements
421
422 A CIPSO implementation MUST be capable of generating at least tag type 1 in
423 the non-optimized form. In addition, a CIPSO implementation MUST be able
424 to receive any valid tag type 1 even those using the optimized tag type 1
425 format.
426
427
428 4. Configuration Parameters
429
430 The configuration parameters defined below are required for all CIPSO hosts,
431 gateways, and routers that support multiple sensitivity labels. A CIPSO
432 host is defined to be the origination or destination system for an IP
433 datagram. A CIPSO gateway provides IP routing services between two or more
434 IP networks and may be required to perform label translations between
435 networks. A CIPSO gateway may be an enhanced CIPSO host or it may just
436 provide gateway services with no end system CIPSO capabilities. A CIPSO
437 router is a dedicated IP router that routes IP datagrams between two or more
438 IP networks.
439
440 An implementation of CIPSO on a host MUST have the capability to reject a
441 datagram for reasons that the information contained can not be adequately
442 protected by the receiving host or if acceptance may result in violation of
443 the host or network security policy. In addition, a CIPSO gateway or router
444 MUST be able to reject datagrams going to networks that can not provide
445 adequate protection or may violate the network's security policy. To
446 provide this capability the following minimal set of configuration
447 parameters are required for CIPSO implementations:
448
449 HOST_LABEL_MAX - This parameter contains the maximum sensitivity label that
450 a CIPSO host is authorized to handle. All datagrams that have a label
451 greater than this maximum MUST be rejected by the CIPSO host. This
452 parameter does not apply to CIPSO gateways or routers. This parameter need
453 not be defined explicitly as it can be implicitly derived from the
454 PORT_LABEL_MAX parameters for the associated interfaces.
455
456
457
458 Internet Draft, Expires 15 Jan 93 [PAGE 7]
459
460
461
462 CIPSO INTERNET DRAFT 16 July, 1992
463
464
465
466
467 HOST_LABEL_MIN - This parameter contains the minimum sensitivity label that
468 a CIPSO host is authorized to handle. All datagrams that have a label less
469 than this minimum MUST be rejected by the CIPSO host. This parameter does
470 not apply to CIPSO gateways or routers. This parameter need not be defined
471 explicitly as it can be implicitly derived from the PORT_LABEL_MIN
472 parameters for the associated interfaces.
473
474 PORT_LABEL_MAX - This parameter contains the maximum sensitivity label for
475 all datagrams that may exit a particular network interface port. All
476 outgoing datagrams that have a label greater than this maximum MUST be
477 rejected by the CIPSO system. The label within this parameter MUST be
478 less than or equal to the label within the HOST_LABEL_MAX parameter. This
479 parameter does not apply to CIPSO hosts that support only one network port.
480
481 PORT_LABEL_MIN - This parameter contains the minimum sensitivity label for
482 all datagrams that may exit a particular network interface port. All
483 outgoing datagrams that have a label less than this minimum MUST be
484 rejected by the CIPSO system. The label within this parameter MUST be
485 greater than or equal to the label within the HOST_LABEL_MIN parameter.
486 This parameter does not apply to CIPSO hosts that support only one network
487 port.
488
489 PORT_DOI - This parameter is used to assign a DOI identifier value to a
490 particular network interface port. All CIPSO labels within datagrams
491 going out this port MUST use the specified DOI identifier. All CIPSO
492 hosts and gateways MUST support either this parameter, the NET_DOI
493 parameter, or the HOST_DOI parameter.
494
495 NET_DOI - This parameter is used to assign a DOI identifier value to a
496 particular IP network address. All CIPSO labels within datagrams destined
497 for the particular IP network MUST use the specified DOI identifier. All
498 CIPSO hosts and gateways MUST support either this parameter, the PORT_DOI
499 parameter, or the HOST_DOI parameter.
500
501 HOST_DOI - This parameter is used to assign a DOI identifier value to a
502 particular IP host address. All CIPSO labels within datagrams destined for
503 the particular IP host will use the specified DOI identifier. All CIPSO
504 hosts and gateways MUST support either this parameter, the PORT_DOI
505 parameter, or the NET_DOI parameter.
506
507 This list represents the minimal set of configuration parameters required
508 to be compliant. Implementors are encouraged to add to this list to
509 provide enhanced functionality and control. For example, many security
510 policies may require both incoming and outgoing datagrams be checked against
511 the port and host label ranges.
512
513
514 4.1 Port Range Parameters
515
516 The labels represented by the PORT_LABEL_MAX and PORT_LABEL_MIN parameters
517 MAY be in CIPSO or local format. Some CIPSO systems, such as routers, may
518 want to have the range parameters expressed in CIPSO format so that incoming
519 labels do not have to be converted to a local format before being compared
520 against the range. If multiple DOIs are supported by one of these CIPSO
521
522
523
524 Internet Draft, Expires 15 Jan 93 [PAGE 8]
525
526
527
528 CIPSO INTERNET DRAFT 16 July, 1992
529
530
531
532 systems then multiple port range parameters would be needed, one set for
533 each DOI supported on a particular port.
534
535 The port range will usually represent the total set of labels that may
536 exist on the logical network accessed through the corresponding network
537 interface. It may, however, represent a subset of these labels that are
538 allowed to enter the CIPSO system.
539
540
541 4.2 Single Label CIPSO Hosts
542
543 CIPSO implementations that support only one label are not required to
544 support the parameters described above. These limited implementations are
545 only required to support a NET_LABEL parameter. This parameter contains
546 the CIPSO label that may be inserted in datagrams that exit the host. In
547 addition, the host MUST reject any incoming datagram that has a label which
548 is not equivalent to the NET_LABEL parameter.
549
550
551 5. Handling Procedures
552
553 This section describes the processing requirements for incoming and
554 outgoing IP datagrams. Just providing the correct CIPSO label format
555 is not enough. Assumptions will be made by one system on how a
556 receiving system will handle the CIPSO label. Wrong assumptions may
557 lead to non-interoperability or even a security incident. The
558 requirements described below represent the minimal set needed for
559 interoperability and that provide users some level of confidence.
560 Many other requirements could be added to increase user confidence,
561 however at the risk of restricting creativity and limiting vendor
562 participation.
563
564
565 5.1 Input Procedures
566
567 All datagrams received through a network port MUST have a security label
568 associated with them, either contained in the datagram or assigned to the
569 receiving port. Without this label the host, gateway, or router will not
570 have the information it needs to make security decisions. This security
571 label will be obtained from the CIPSO if the option is present in the
572 datagram. See section 4.1.2 for handling procedures for unlabeled
573 datagrams. This label will be compared against the PORT (if appropriate)
574 and HOST configuration parameters defined in section 3.
575
576 If any field within the CIPSO option, such as the DOI identifier, is not
577 recognized the IP datagram is discarded and an ICMP "parameter problem"
578 (type 12) is generated and returned. The ICMP code field is set to "bad
579 parameter" (code 0) and the pointer is set to the start of the CIPSO field
580 that is unrecognized.
581
582 If the contents of the CIPSO are valid but the security label is
583 outside of the configured host or port label range, the datagram is
584 discarded and an ICMP "destination unreachable" (type 3) is generated
585 and returned. The code field of the ICMP is set to "communication with
586 destination network administratively prohibited" (code 9) or to
587
588
589
590 Internet Draft, Expires 15 Jan 93 [PAGE 9]
591
592
593
594 CIPSO INTERNET DRAFT 16 July, 1992
595
596
597
598 "communication with destination host administratively prohibited"
599 (code 10). The value of the code field used is dependent upon whether
600 the originator of the ICMP message is acting as a CIPSO host or a CIPSO
601 gateway. The recipient of the ICMP message MUST be able to handle either
602 value. The same procedure is performed if a CIPSO can not be added to an
603 IP packet because it is too large to fit in the IP options area.
604
605 If the error is triggered by receipt of an ICMP message, the message
606 is discarded and no response is permitted (consistent with general ICMP
607 processing rules).
608
609
610 5.1.1 Unrecognized tag types
611
612 The default condition for any CIPSO implementation is that an
613 unrecognized tag type MUST be treated as a "parameter problem" and
614 handled as described in section 4.1. A CIPSO implementation MAY allow
615 the system administrator to identify tag types that may safely be
616 ignored. This capability is an allowable enhancement, not a
617 requirement.
618
619
620 5.1.2 Unlabeled Packets
621
622 A network port may be configured to not require a CIPSO label for all
623 incoming datagrams. For this configuration a CIPSO label must be
624 assigned to that network port and associated with all unlabeled IP
625 datagrams. This capability might be used for single level networks or
626 networks that have CIPSO and non-CIPSO hosts and the non-CIPSO hosts
627 all operate at the same label.
628
629 If a CIPSO option is required and none is found, the datagram is
630 discarded and an ICMP "parameter problem" (type 12) is generated and
631 returned to the originator of the datagram. The code field of the ICMP
632 is set to "option missing" (code 1) and the ICMP pointer is set to 134
633 (the value of the option type for the missing CIPSO option).
634
635
636 5.2 Output Procedures
637
638 A CIPSO option MUST appear only once in a datagram. Only one tag type
639 from the MAC Sensitivity class MAY be included in a CIPSO option. Given
640 the current set of defined tag types, this means that CIPSO labels at
641 first will contain only one tag.
642
643 All datagrams leaving a CIPSO system MUST meet the following condition:
644
645 PORT_LABEL_MIN <= CIPSO label <= PORT_LABEL_MAX
646
647 If this condition is not satisfied the datagram MUST be discarded.
648 If the CIPSO system only supports one port, the HOST_LABEL_MIN and the
649 HOST_LABEL_MAX parameters MAY be substituted for the PORT parameters in
650 the above condition.
651
652 The DOI identifier to be used for all outgoing datagrams is configured by
653
654
655
656 Internet Draft, Expires 15 Jan 93 [PAGE 10]
657
658
659
660 CIPSO INTERNET DRAFT 16 July, 1992
661
662
663
664 the administrator. If port level DOI identifier assignment is used, then
665 the PORT_DOI configuration parameter MUST contain the DOI identifier to
666 use. If network level DOI assignment is used, then the NET_DOI parameter
667 MUST contain the DOI identifier to use. And if host level DOI assignment
668 is employed, then the HOST_DOI parameter MUST contain the DOI identifier
669 to use. A CIPSO implementation need only support one level of DOI
670 assignment.
671
672
673 5.3 DOI Processing Requirements
674
675 A CIPSO implementation MUST support at least one DOI and SHOULD support
676 multiple DOIs. System and network administrators are cautioned to
677 ensure that at least one DOI is common within an IP network to allow for
678 broadcasting of IP datagrams.
679
680 CIPSO gateways MUST be capable of translating a CIPSO option from one
681 DOI to another when forwarding datagrams between networks. For
682 efficiency purposes this capability is only a desired feature for CIPSO
683 routers.
684
685
686 5.4 Label of ICMP Messages
687
688 The CIPSO label to be used on all outgoing ICMP messages MUST be equivalent
689 to the label of the datagram that caused the ICMP message. If the ICMP was
690 generated due to a problem associated with the original CIPSO label then the
691 following responses are allowed:
692
693 a. Use the CIPSO label of the original IP datagram
694 b. Drop the original datagram with no return message generated
695
696 In most cases these options will have the same effect. If you can not
697 interpret the label or if it is outside the label range of your host or
698 interface then an ICMP message with the same label will probably not be
699 able to exit the system.
700
701
702 6. Assignment of DOI Identifier Numbers =
703
704 Requests for assignment of a DOI identifier number should be addressed to
705 the Internet Assigned Numbers Authority (IANA).
706
707
708 7. Acknowledgements
709
710 Much of the material in this RFC is based on (and copied from) work
711 done by Gary Winiger of Sun Microsystems and published as Commercial
712 IP Security Option at the INTEROP 89, Commercial IPSO Workshop.
713
714
715 8. Author's Address
716
717 To submit mail for distribution to members of the IETF CIPSO Working
718 Group, send mail to: cipso@wdl1.wdl.loral.com.
719
720
721
722 Internet Draft, Expires 15 Jan 93 [PAGE 11]
723
724
725
726 CIPSO INTERNET DRAFT 16 July, 1992
727
728
729
730
731 To be added to or deleted from this distribution, send mail to:
732 cipso-request@wdl1.wdl.loral.com.
733
734
735 9. References
736
737 RFC 1038, "Draft Revised IP Security Option", M. St. Johns, IETF, January
738 1988.
739
740 RFC 1108, "U.S. Department of Defense Security Options
741 for the Internet Protocol", Stephen Kent, IAB, 1 March, 1991.
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788 Internet Draft, Expires 15 Jan 93 [PAGE 12]
789
790
791
792

3. 한국어 전문 번역

영어 원문의 문단 순서와 의미를 유지한 전체 번역입니다. 코드, 함수명, symbol과 URL은 원문 표기를 유지합니다.

문서 지위

1-32

IETF CIPSO Working Group

1992년 7월 16일

COMMERCIAL IP SECURITY OPTION (CIPSO 2.2)

1. 지위

이 Internet Draft는 Commercial IP Security Option(CIPSO)의 상위 수준 규격을 제공합니다. CIPSO IETF Working Group이 승인한 version을 반영하며 배포에는 제한이 없습니다.

Internet Draft는 IETF와 그 area·working group의 작업 문서이며 다른 group도 같은 형식으로 배포할 수 있습니다.

Draft는 최대 6개월 동안 유효하고 언제든 갱신·대체·폐기될 수 있습니다. 참고 자료로 쓰거나 `working draft` 또는 `work in progress` 이외의 방식으로 인용하는 것은 적절하지 않습니다. 현재 상태는 각 Internet-Draft directory의 I-D abstract 목록에서 확인해야 합니다.

IETF CIPSO Working Group
16 July, 1992



                 COMMERCIAL IP SECURITY OPTION (CIPSO 2.2)



1.    Status

This Internet Draft provides the high level specification for a Commercial
IP Security Option (CIPSO).  This draft reflects the version as approved by
the CIPSO IETF Working Group.  Distribution of this memo is unlimited.

This document is an Internet Draft.  Internet Drafts are working documents
of the Internet Engineering Task Force (IETF), its Areas, and its Working
Groups. Note that other groups may also distribute working documents as
Internet Drafts.

Internet Drafts are draft documents valid for a maximum of six months.
Internet Drafts may be updated, replaced, or obsoleted by other documents
at any time.  It is not appropriate to use Internet Drafts as reference
material or to cite them other than as a "working draft" or "work in
progress."

Please check the I-D abstract listing contained in each Internet Draft
directory to learn the current status of this or any other Internet Draft.



BSO·ESO에서 CIPSO로

33-70

2. 배경

당시 IP에는 두 security option이 있었습니다. DoD Basic Security Option(BSO, type 130)은 IP datagram에 16개 security classification과 가변 개수의 handling restriction을 표시합니다.

Security category나 compartment 같은 추가 정보에는 DoD Extended Security Option(ESO, type 133)을 사용했습니다. 두 option의 fixed field 값은 Defense Information Systems Agency(DISA)가 관리했습니다.

Mandatory access control과 multi-level security를 갖춘 commercial operating system이 국방·정보기관 전용이 아니라 정부와 민간 환경에 일반 제품으로 보급되면서 ESO의 적은 format code만으로는 모든 commercial security-option 사용 사례를 지원할 수 없었습니다.

BSO·ESO가 미국 DoD만을 위해 설계된 것과 달리 CIPSO는 여러 security policy를 지원하도록 설계되었습니다. 이 draft는 Mandatory Access Control(MAC) policy용 형식과 절차를 정의하며 다른 policy는 향후 RFC에서 정의하도록 했습니다.

Internet Draft, 1993년 1월 15일 만료, 1쪽

2.    Background

Currently the Internet Protocol includes two security options.  One of
these options is the DoD Basic Security Option (BSO) (Type 130) which allows
IP datagrams to be labeled with security classifications.  This option
provides sixteen security classifications and a variable number of handling
restrictions.  To handle additional security information, such as security
categories or compartments, another security option (Type 133) exists and
is referred to as the DoD Extended Security Option (ESO).  The values for
the fixed fields within these two options are administered by the Defense
Information Systems Agency (DISA).

Computer vendors are now building commercial operating systems with
mandatory access controls and multi-level security.  These systems are
no longer built specifically for a particular group in the defense or
intelligence communities.  They are generally available commercial systems
for use in a variety of government and civil sector environments.

The small number of ESO format codes can not support all the possible
applications of a commercial security option.  The BSO and ESO were
designed to only support the United States DoD.  CIPSO has been designed
to support multiple security policies.  This Internet Draft provides the
format and procedures required to support a Mandatory Access Control
security policy.  Support for additional security policies shall be
defined in future RFCs.




Internet Draft, Expires 15 Jan 93                                 [PAGE 1]



CIPSO INTERNET DRAFT                                         16 July, 1992



CIPSO header와 DOI

71-141

3. CIPSO 형식

Option type은 134(class 0, number 6, fragmentation 시 복사)이고 길이는 가변입니다.

이 option은 하나의 Domain of Interpretation(DOI) 안에 있는 system 사이에서 security 정보를 전달합니다. DOI는 security-option 값의 의미에 합의한 system 집합입니다.

DOI identifier를 배정받은 authority는 CIPSO field 값과 사람이 읽는 표현 사이의 mapping을 정의해 domain의 host에 배포합니다. Mapping 자체가 민감할 수 있으므로 DOI 구성원 밖에 공개할 의무는 없습니다.

Option은 fragmentation 시 반드시(MUST) 복사하고 datagram 하나에 최대 한 번만 나타나야 합니다. Multi-octet field는 network byte order로 전송합니다.

CIPSO option header는 1-octet type 134, 1-octet option length, 32-bit DOI identifier, 뒤따르는 tag들로 구성됩니다.

Type field 값은 134입니다. Length는 type·length 자체를 포함한 option 전체 길이이며 당시 IP header option 영역 제한 때문에 40 octet을 초과해서는 안 됩니다(MUST NOT).

DOI identifier는 unsigned 32-bit integer입니다. 0은 예약되어 CIPSO option에 나타나서는 안 됩니다(MUST NOT). 구현은 이 field가 특정 byte boundary에 align되지 않았다고 가정해야 합니다.

공간 절약을 위해 security level과 category를 ASCII 대신 숫자로 전달하므로 host는 숫자와 표현 사이의 mapping table을 가져야 합니다. 서로 무관한 group은 같은 의미에 다른 숫자를 쓸 수 있으며 DOI identifier가 option 값에 적용된 mapping을 식별합니다.

3.    CIPSO Format

Option type: 134 (Class 0, Number 6, Copy on Fragmentation)
Option length: Variable

This option permits security related information to be passed between
systems within a single Domain of Interpretation (DOI).  A DOI is a
collection of systems which agree on the meaning of particular values
in the security option.  An authority that has been assigned a DOI
identifier will define a mapping between appropriate CIPSO field values
and their human readable equivalent.  This authority will distribute that
mapping to hosts within the authority's domain.  These mappings may be
sensitive, therefore a DOI authority is not required to make these
mappings available to anyone other than the systems that are included in
the DOI.

This option MUST be copied on fragmentation.  This option appears at most
once in a datagram.  All multi-octet fields in the option are defined to be
transmitted in network byte order.  The format of this option is as follows:

+----------+----------+------//------+-----------//---------+
| 10000110 | LLLLLLLL | DDDDDDDDDDDD | TTTTTTTTTTTTTTTTTTTT |
+----------+----------+------//------+-----------//---------+

  TYPE=134    OPTION    DOMAIN OF               TAGS
              LENGTH    INTERPRETATION


                Figure 1. CIPSO Format


3.1    Type

This field is 1 octet in length.  Its value is 134.


3.2    Length

This field is 1 octet in length.  It is the total length of the option
including the type and length fields.  With the current IP header length
restriction of 40 octets the value of this field MUST not exceed 40.


3.3    Domain of Interpretation Identifier

This field is an unsigned 32 bit integer.  The value 0 is reserved and MUST
not appear as the DOI identifier in any CIPSO option.  Implementations
should assume that the DOI identifier field is not aligned on any particular
byte boundary.

To conserve space in the protocol, security levels and categories are
represented by numbers rather than their ASCII equivalent.  This requires
a mapping table within CIPSO hosts to map these numbers to their
corresponding ASCII representations.  Non-related groups of systems may



Internet Draft, Expires 15 Jan 93                                 [PAGE 2]



CIPSO INTERNET DRAFT                                         16 July, 1992



have their own unique mappings.  For example, one group of systems may
use the number 5 to represent Unclassified while another group may use the
number 1 to represent that same security level.  The DOI identifier is used
to identify which mapping was used for the values within the option.

표준 tag 형식과 class

142-204

3.4 Tag type

Interoperability를 위해 공통 형식이 필요합니다. CIPSO는 IP packet data와 관련된 security 정보를 tag 집합에 담습니다. 각 tag는 type identifier, tag length, 실제 security information 순서입니다.

Tag의 multi-octet field도 network byte order를 사용합니다. CIPSO header의 DOI처럼 tag와 내부 field도 임의 octet boundary에 놓일 수 있다고 가정해야 합니다. Alignment octet이 일부 field를 돕지만 CIPSO가 첫 IP option이 아니면 정렬을 보장할 수 없습니다.

Tag type 0~127은 RFC로 정의할 표준 형식용입니다. 127보다 큰 type은 DOI authority가 정의하며 특정 DOI에서만 의미가 있을 수 있습니다. Policy와 format을 정하려면 DOI identifier와 tag number가 모두 필요합니다.

127보다 큰 type은 외부 network와 interoperability가 필요 없는 closed network에서만 사용합니다. 이를 지원하는 구현은 type 1~127만 요구하는 DOI도 최소 하나 지원해야 합니다(MUST).

Type 0은 예약되어 있고 type 1·2·5를 이 draft가 정의합니다. Type 3·4는 진행 중 작업을 위해 예약했습니다.

모든 CIPSO tag의 표준 header는 1-octet tag type, 1-octet tag length, 가변 tag information으로 구성됩니다. 현재 tag 길이와 개수 제한은 IP option 전체 40-octet 제한에서 나온 것이므로 IP header가 확장되면 함께 늘어날 수 있습니다.

공통 처리 요구와 같은 security policy를 지원하는 tag type을 tag class로 묶습니다. 이 draft의 세 tag는 모두 MAC Sensitivity class에 속해 같은 policy를 지원합니다.

3.4    Tag Types

A common format for passing security related information is necessary
for interoperability.  CIPSO uses sets of "tags" to contain the security
information relevant to the data in the IP packet.  Each tag begins with
a tag type identifier followed by the length of the tag and ends with the
actual security information to be passed.  All multi-octet fields in a tag
are defined to be transmitted in network byte order.  Like the DOI
identifier field in the CIPSO header, implementations should assume that
all tags, as well as fields within a tag, are not aligned on any particular
octet boundary.   The tag types defined in this document contain alignment
bytes to assist alignment of some information, however alignment can not
be guaranteed if CIPSO is not the first IP option.

CIPSO tag types 0 through 127 are reserved for defining standard tag
formats.  Their definitions will be published in RFCs.  Tag types whose
identifiers are greater than 127 are defined by the DOI authority and may
only be meaningful in certain Domains of Interpretation.  For these tag
types, implementations will require the DOI identifier as well as the tag
number to determine the security policy and the format associated with the
tag.  Use of tag types above 127 are restricted to closed networks where
interoperability with other networks will not be an issue.  Implementations
that support a tag type greater than 127 MUST support at least one DOI that
requires only tag types 1 to 127.

Tag type 0 is reserved. Tag types 1, 2, and 5 are defined in this
Internet Draft.  Types 3 and 4 are reserved for work in progress.
The standard format for all current and future CIPSO tags is shown below:

+----------+----------+--------//--------+
| TTTTTTTT | LLLLLLLL | IIIIIIIIIIIIIIII |
+----------+----------+--------//--------+
    TAG       TAG         TAG
    TYPE      LENGTH      INFORMATION

    Figure 2:  Standard Tag Format

In the three tag types described in this document, the length and count
restrictions are based on the current IP limitation of 40 octets for all
IP options.  If the IP header is later expanded, then the length and count
restrictions specified in this document may increase to use the full area
provided for IP options.


3.4.1    Tag Type Classes

Tag classes consist of tag types that have common processing requirements
and support the same security policy.  The three tags defined in this
Internet Draft belong to the Mandatory Access Control (MAC) Sensitivity



Internet Draft, Expires 15 Jan 93                                 [PAGE 3]



CIPSO INTERNET DRAFT                                         16 July, 1992



class and support the MAC Sensitivity security policy.

Tag type 1: bitmap category

205-290

3.4.2 Tag type 1

Type 1은 `bit-mapped` tag이며 MAC Sensitivity class에 속합니다. Field 순서는 type, length, alignment octet, sensitivity level, category bitmap입니다.

  • Tag type은 1 octet이며 값은 1입니다.
  • Tag length는 type·length를 포함한 전체 길이로 4~34입니다.
  • Alignment octet은 1 octet이고 항상 0입니다. Category bitmap을 짝수 octet boundary에 맞춰 router를 포함한 구현을 빠르게 합니다.
  • Sensitivity level은 1 octet, 값 0~255이며 0이 최소, 255가 최대입니다.

Category bitmap은 0~30 octet으로 category 0~239를 표현합니다. Bit 순서는 왼쪽에서 오른쪽, MSB에서 LSB입니다. Category 0은 첫 byte의 MSB, category 15는 두 번째 byte의 LSB입니다.

Bit N이 1이면 category N이 datagram label에 포함되고 0이면 포함되지 않습니다. 다음 optimized 형식을 제외하면 trailing zero octet이 없도록 최소 encoding을 사용해야 합니다(SHOULD).

Router가 fixed-length field를 효율적으로 처리하도록 optimized type 1은 형식은 유지한 채 bitmap을 10 octet으로 고정하고 남는 trailing octet을 0으로 채웁니다. 80 category를 표현하며 CIPSO option 전체 길이가 20 octet이 되어 CIPSO가 유일한 option일 때 word alignment를 이루고 filler가 필요 없습니다.

3.4.2    Tag Type 1

This is referred to as the "bit-mapped" tag type.  Tag type 1 is included
in the MAC Sensitivity tag type class.  The format of this tag type is as
follows:

+----------+----------+----------+----------+--------//---------+
| 00000001 | LLLLLLLL | 00000000 | LLLLLLLL | CCCCCCCCCCCCCCCCC |
+----------+----------+----------+----------+--------//---------+

    TAG       TAG      ALIGNMENT  SENSITIVITY    BIT MAP OF
    TYPE      LENGTH   OCTET      LEVEL          CATEGORIES

            Figure 3. Tag Type 1 Format


3.4.2.1    Tag Type

This field is 1 octet in length and has a value of 1.


3.4.2.2    Tag Length

This field is 1 octet in length.  It is the total length of the tag type
including the type and length fields.  With the current IP header length
restriction of 40 bytes the value within this field is between 4 and 34.


3.4.2.3    Alignment Octet

This field is 1 octet in length and always has the value of 0.  Its purpose
is to align the category bitmap field on an even octet boundary.  This will
speed many implementations including router implementations.


3.4.2.4    Sensitivity Level

This field is 1 octet in length.  Its value is from 0 to 255.  The values
are ordered with 0 being the minimum value and 255 representing the maximum
value.


3.4.2.5    Bit Map of Categories

The length of this field is variable and ranges from 0 to 30 octets.  This
provides representation of categories 0 to 239.  The ordering of the bits
is left to right or MSB to LSB.  For example category 0 is represented by
the most significant bit of the first byte and category 15 is represented
by the least significant bit of the second byte.  Figure 4 graphically
shows this ordering.  Bit N is binary 1 if category N is part of the label
for the datagram, and bit N is binary 0 if category N is not part of the
label.  Except for the optimized tag 1 format described in the next section,



Internet Draft, Expires 15 Jan 93                                 [PAGE 4]



CIPSO INTERNET DRAFT                                         16 July, 1992



minimal encoding SHOULD be used resulting in no trailing zero octets in the
category bitmap.

        octet 0  octet 1  octet 2  octet 3  octet 4  octet 5
        XXXXXXXX XXXXXXXX XXXXXXXX XXXXXXXX XXXXXXXX XXXXXXXX . . .
bit     01234567 89111111 11112222 22222233 33333333 44444444
number             012345 67890123 45678901 23456789 01234567

            Figure 4. Ordering of Bits in Tag 1 Bit Map


3.4.2.6    Optimized Tag 1 Format

Routers work most efficiently when processing fixed length fields.  To
support these routers there is an optimized form of tag type 1.  The format
does not change.  The only change is to the category bitmap which is set to
a constant length of 10 octets.  Trailing octets required to fill out the 10
octets are zero filled.  Ten octets, allowing for 80 categories, was chosen
because it makes the total length of the CIPSO option 20 octets.  If CIPSO
is the only option then the option will be full word aligned and additional
filler octets will not be required.

Tag type 2: 열거 category

291-352

3.4.3 Tag type 2

Type 2는 `enumerated` tag로 크지만 sparse한 category 집합을 표현하며 MAC Sensitivity class에 속합니다. Field 순서는 type, length, alignment, sensitivity, 열거 category입니다.

  • Tag type은 1 octet이며 값은 2입니다.
  • Tag length는 전체 4~34 octet입니다.
  • Alignment octet은 항상 0이며 category field를 짝수 octet boundary에 맞춥니다.
  • Sensitivity level은 1 octet의 0~255 값이며 0이 최소, 255가 최대입니다.

Category는 bitmap 위치가 아니라 실제 값으로 표현하고 각각 2 octet입니다. Tag 하나에 최대 15개를 담을 수 있습니다. 유효 값은 0~65,534이고 65,535는 유효하지 않습니다. Tag 안에서는 반드시(MUST) 오름차순으로 나열합니다.

3.4.3    Tag Type 2

This is referred to as the "enumerated" tag type.  It is used to describe
large but sparsely populated sets of categories.  Tag type 2 is in the MAC
Sensitivity tag type class.  The format of this tag type is as follows:

+----------+----------+----------+----------+-------------//-------------+
| 00000010 | LLLLLLLL | 00000000 | LLLLLLLL | CCCCCCCCCCCCCCCCCCCCCCCCCC |
+----------+----------+----------+----------+-------------//-------------+

    TAG       TAG      ALIGNMENT  SENSITIVITY         ENUMERATED
    TYPE      LENGTH   OCTET      LEVEL               CATEGORIES

                Figure 5. Tag Type 2 Format


3.4.3.1     Tag Type

This field is one octet in length and has a value of 2.


3.4.3.2    Tag Length

This field is 1 octet in length. It is the total length of the tag type
including the type and length fields.  With the current IP header length
restriction of 40 bytes the value within this field is between 4 and 34.


3.4.3.3    Alignment Octet

This field is 1 octet in length and always has the value of 0.  Its purpose
is to align the category field on an even octet boundary.  This will



Internet Draft, Expires 15 Jan 93                                 [PAGE 5]



CIPSO INTERNET DRAFT                                         16 July, 1992



speed many implementations including router implementations.


3.4.3.4    Sensitivity Level

This field is 1 octet in length. Its value is from 0 to 255.  The values
are ordered with 0 being the minimum value and 255 representing the
maximum value.


3.4.3.5    Enumerated Categories

In this tag, categories are represented by their actual value rather than
by their position within a bit field.  The length of each category is 2
octets.  Up to 15 categories may be represented by this tag.  Valid values
for categories are 0 to 65534.  Category 65535 is not a valid category
value.  The categories MUST be listed in ascending order within the tag.

Tag type 5: category 범위

353-427

3.4.4 Tag type 5

Type 5는 `range` tag로, sensitivity label에 범위 하나 또는 여러 범위의 모든 category가 포함될 때 사용합니다. MAC Sensitivity class에 속합니다.

Field 순서는 type 5, 전체 길이 4~34, 값 0인 alignment octet, 0~255 sensitivity level, category range들입니다.

Category range 하나는 4 octet으로, 2-octet 최고 category index 다음에 2-octet 최저 index를 둡니다. 양 끝값을 모두 포함하고 범위 안 모든 category가 sensitivity label에 들어갑니다.

Tag 하나에 최대 7개 pair를 담습니다. 마지막 pair의 bottom endpoint는 생략할 수 있으며(MAY) 생략 시 0으로 보아야 합니다(SHOULD). 범위는 겹치면 안 되고 반드시(MUST) 내림차순으로 나열합니다. Category 유효 값은 0~65,534이고 65,535는 무효입니다.

3.4.5 최소 요구 사항

CIPSO 구현은 최소한 non-optimized tag type 1을 생성할 수 있어야 하고(MUST), optimized 형식을 포함한 모든 유효 type 1을 수신할 수 있어야 합니다(MUST).

3.4.4    Tag Type 5

This is referred to as the "range" tag type.  It is used to represent
labels where all categories in a range, or set of ranges, are included
in the sensitivity label.  Tag type 5 is in the MAC Sensitivity tag type
class.  The format of this tag type is as follows:

+----------+----------+----------+----------+------------//-------------+
| 00000101 | LLLLLLLL | 00000000 | LLLLLLLL |  Top/Bottom | Top/Bottom  |
+----------+----------+----------+----------+------------//-------------+

    TAG       TAG      ALIGNMENT  SENSITIVITY        CATEGORY RANGES
    TYPE      LENGTH   OCTET      LEVEL

                     Figure 6. Tag Type 5 Format


3.4.4.1     Tag Type

This field is one octet in length and has a value of 5.


3.4.4.2    Tag Length

This field is 1 octet in length. It is the total length of the tag type
including the type and length fields.  With the current IP header length
restriction of 40 bytes the value within this field is between 4 and 34.


3.4.4.3    Alignment Octet

This field is 1 octet in length and always has the value of 0.  Its purpose
is to align the category range field on an even octet boundary.  This will
speed many implementations including router implementations.





Internet Draft, Expires 15 Jan 93                                 [PAGE 6]



CIPSO INTERNET DRAFT                                         16 July, 1992



3.4.4.4    Sensitivity Level

This field is 1 octet in length. Its value is from 0 to 255.  The values
are ordered with 0 being the minimum value and 255 representing the maximum
value.


3.4.4.5    Category Ranges

A category range is a 4 octet field comprised of the 2 octet index of the
highest numbered category followed by the 2 octet index of the lowest
numbered category.  These range endpoints are inclusive within the range of
categories.  All categories within a range are included in the sensitivity
label.  This tag may contain a maximum of 7 category pairs.  The bottom
category endpoint for the last pair in the tag MAY be omitted and SHOULD be
assumed to be 0.  The ranges MUST be non-overlapping and be listed in
descending order.  Valid values for categories are 0 to 65534.  Category
65535 is not a valid category value.


3.4.5     Minimum Requirements

A CIPSO implementation MUST be capable of generating at least tag type 1 in
the non-optimized form.  In addition, a CIPSO implementation MUST be able
to receive any valid tag type 1 even those using the optimized tag type 1
format.

Host·port label과 DOI 구성

428-513

4. 구성 parameter

아래 parameter는 여러 sensitivity label을 지원하는 모든 CIPSO host·gateway·router에 필요합니다. Host는 datagram의 출발·도착 end system, gateway는 둘 이상 IP network 사이를 route하고 필요하면 label을 변환하는 system, router는 전용 IP router입니다.

Host는 포함 정보를 충분히 보호할 수 없거나 수락 시 security policy를 위반하는 datagram을 거부할 수 있어야 합니다(MUST). Gateway와 router도 적절한 보호를 제공하지 못하거나 network policy를 위반하는 destination으로 가는 datagram을 거부해야 합니다(MUST).

  • `HOST_LABEL_MAX`: host가 처리하도록 허가된 최고 sensitivity label입니다. 더 높은 datagram은 거부해야 합니다. Gateway·router에는 적용하지 않으며 interface의 `PORT_LABEL_MAX`에서 암묵적으로 구할 수 있습니다.
  • `HOST_LABEL_MIN`: host가 처리할 수 있는 최저 label입니다. 더 낮은 datagram은 거부하며 `PORT_LABEL_MIN`에서 구할 수 있습니다.
  • `PORT_LABEL_MAX`: 특정 interface port로 나갈 수 있는 최고 label입니다. 이를 넘는 outbound datagram은 거부하며 값은 `HOST_LABEL_MAX` 이하여야 합니다. Port 하나뿐인 host에는 적용하지 않습니다.
  • `PORT_LABEL_MIN`: 특정 port로 나갈 수 있는 최저 label입니다. 이보다 낮은 datagram은 거부하며 값은 `HOST_LABEL_MIN` 이상이어야 합니다.
  • `PORT_DOI`: 특정 interface port로 나가는 CIPSO label의 DOI입니다.
  • `NET_DOI`: 특정 IP network로 가는 CIPSO label의 DOI입니다.
  • `HOST_DOI`: 특정 IP host로 가는 CIPSO label의 DOI입니다.

모든 CIPSO host와 gateway는 `PORT_DOI`, `NET_DOI`, `HOST_DOI` 중 하나를 지원해야 합니다(MUST). 이 목록은 compliance 최소 집합이며 구현은 양방향 datagram을 port·host range와 모두 비교하는 등 더 많은 제어를 추가하도록 권장됩니다.

4.    Configuration Parameters

The configuration parameters defined below are required for all CIPSO hosts,
gateways, and routers that support multiple sensitivity labels.  A CIPSO
host is defined to be the origination or destination system for an IP
datagram.  A CIPSO gateway provides IP routing services between two or more
IP networks and may be required to perform label translations between
networks.  A CIPSO gateway may be an enhanced CIPSO host or it may just
provide gateway services with no end system CIPSO capabilities.  A CIPSO
router is a dedicated IP router that routes IP datagrams between two or more
IP networks.

An implementation of CIPSO on a host MUST have the capability to reject a
datagram for reasons that the information contained can not be adequately
protected by the receiving host or if acceptance may result in violation of
the host or network security policy.  In addition, a CIPSO gateway or router
MUST be able to reject datagrams going to networks that can not provide
adequate protection or may violate the network's security policy.  To
provide this capability the following minimal set of configuration
parameters are required for CIPSO implementations:

HOST_LABEL_MAX - This parameter contains the maximum sensitivity label that
a CIPSO host is authorized to handle.  All datagrams that have a label
greater than this maximum MUST be rejected by the CIPSO host.  This
parameter does not apply to CIPSO gateways or routers.  This parameter need
not be defined explicitly as it can be implicitly derived from the
PORT_LABEL_MAX parameters for the associated interfaces.



Internet Draft, Expires 15 Jan 93                                 [PAGE 7]



CIPSO INTERNET DRAFT                                         16 July, 1992




HOST_LABEL_MIN - This parameter contains the minimum sensitivity label that
a CIPSO host is authorized to handle.  All datagrams that have a label less
than this minimum MUST be rejected by the CIPSO host.  This parameter does
not apply to CIPSO gateways or routers.  This parameter need not be defined
explicitly as it can be implicitly derived from the PORT_LABEL_MIN
parameters for the associated interfaces.

PORT_LABEL_MAX - This parameter contains the maximum sensitivity label for
all datagrams that may exit a particular network interface port.  All
outgoing datagrams that have a label greater than this maximum MUST be
rejected by the CIPSO system.  The label within this parameter MUST be
less than or equal to the label within the HOST_LABEL_MAX parameter.  This
parameter does not apply to CIPSO hosts that support only one network port.

PORT_LABEL_MIN - This parameter contains the minimum sensitivity label for
all datagrams that may exit a particular network interface port.  All
outgoing datagrams that have a label less than this minimum MUST be
rejected by the CIPSO system.  The label within this parameter MUST be
greater than or equal to the label within the HOST_LABEL_MIN parameter.
This parameter does not apply to CIPSO hosts that support only one network
port.

PORT_DOI - This parameter is used to assign a DOI identifier value to a
particular network interface port.  All CIPSO labels within datagrams
going out this port MUST use the specified DOI identifier.  All CIPSO
hosts and gateways MUST support either this parameter, the NET_DOI
parameter, or the HOST_DOI parameter.

NET_DOI - This parameter is used to assign a DOI identifier value to a
particular IP network address.  All CIPSO labels within datagrams destined
for the particular IP network MUST use the specified DOI identifier.  All
CIPSO hosts and gateways MUST support either this parameter, the PORT_DOI
parameter, or the HOST_DOI parameter.

HOST_DOI - This parameter is used to assign a DOI identifier value to a
particular IP host address.  All CIPSO labels within datagrams destined for
the particular IP host will use the specified DOI identifier.  All CIPSO
hosts and gateways MUST support either this parameter, the PORT_DOI
parameter, or the NET_DOI parameter.

This list represents the minimal set of configuration parameters required
to be compliant.  Implementors are encouraged to add to this list to
provide enhanced functionality and control.  For example, many security
policies may require both incoming and outgoing datagrams be checked against
the port and host label ranges.

Port range와 single-label host

514-550

4.1 Port range parameter

`PORT_LABEL_MAX`와 `PORT_LABEL_MIN`의 label은 CIPSO 형식 또는 local 형식일 수 있습니다(MAY). Router는 inbound label을 비교 전에 local 형식으로 바꾸지 않도록 CIPSO 형식을 선호할 수 있습니다.

System이 여러 DOI를 지원하면 port 하나에도 DOI마다 range parameter set이 필요합니다. Port range는 보통 interface가 연결한 logical network에 존재할 수 있는 전체 label 집합이지만, CIPSO system에 들어올 수 있는 부분 집합만 나타낼 수도 있습니다.

4.2 Single-label CIPSO host

Label 하나만 지원하는 구현은 앞의 parameter를 지원하지 않아도 되며 `NET_LABEL`만 필요합니다. 이 값은 host에서 나가는 datagram에 넣을 CIPSO label입니다. Host는 `NET_LABEL`과 동등하지 않은 label의 inbound datagram을 반드시 거부해야 합니다(MUST).

4.1    Port Range Parameters

The labels represented by the PORT_LABEL_MAX and PORT_LABEL_MIN parameters
MAY be in CIPSO or local format.  Some CIPSO systems, such as routers, may
want to have the range parameters expressed in CIPSO format so that incoming
labels do not have to be converted to a local format before being compared
against the range.  If multiple DOIs are supported by one of these CIPSO



Internet Draft, Expires 15 Jan 93                                 [PAGE 8]



CIPSO INTERNET DRAFT                                         16 July, 1992



systems then multiple port range parameters would be needed, one set for
each DOI supported on a particular port.

The port range will usually represent the total set of labels that may
exist on the logical network accessed through the corresponding network
interface.  It may, however, represent a subset of these labels that are
allowed to enter the CIPSO system.


4.2    Single Label CIPSO Hosts

CIPSO implementations that support only one label are not required to
support the parameters described above.  These limited implementations are
only required to support a NET_LABEL parameter.  This parameter contains
the CIPSO label that may be inserted in datagrams that exit the host.  In
addition, the host MUST reject any incoming datagram that has a label which
is not equivalent to the NET_LABEL parameter.

입력 검증과 ICMP 오류

551-609

5. 처리 절차

올바른 label 형식만으로는 충분하지 않습니다. 송신 system은 수신 system이 label을 어떻게 처리할지 가정하며 잘못된 가정은 interoperability 실패나 security incident로 이어질 수 있습니다. 이 요구 사항은 상호 운용성과 기본 신뢰를 위한 최소 집합입니다.

5.1 입력 절차

Network port가 받은 모든 datagram에는 packet 내부 또는 수신 port에서 부여한 security label이 반드시 있어야 합니다(MUST). CIPSO option이 있으면 그 label을 사용하고 port·host configuration range와 비교합니다.

DOI identifier 등 CIPSO field를 인식하지 못하면 datagram을 버리고 ICMP `parameter problem` type 12를 반환합니다. Code는 `bad parameter` 0이고 pointer는 인식하지 못한 CIPSO field 시작을 가리킵니다.

CIPSO 내용은 유효하지만 label이 host·port range 밖이면 datagram을 버리고 ICMP `destination unreachable` type 3을 반환합니다. Host인지 gateway인지에 따라 `destination network administratively prohibited` code 9 또는 `destination host administratively prohibited` code 10을 사용하며 수신자는 둘 다 처리할 수 있어야 합니다(MUST).

IP option 영역에 들어가지 않을 만큼 커서 CIPSO를 추가할 수 없을 때도 같은 절차를 사용합니다. 오류 원인이 ICMP message 수신이면 일반 ICMP 규칙에 따라 message를 버리고 응답하지 않습니다.

5.    Handling Procedures

This section describes the processing requirements for incoming and
outgoing IP datagrams.  Just providing the correct CIPSO label format
is not enough.  Assumptions will be made by one system on how a
receiving system will handle the CIPSO label.  Wrong assumptions may
lead to non-interoperability or even a security incident.  The
requirements described below represent the minimal set needed for
interoperability and that provide users some level of confidence.
Many other requirements could be added to increase user confidence,
however at the risk of restricting creativity and limiting vendor
participation.


5.1    Input Procedures

All datagrams received through a network port MUST have a security label
associated with them, either contained in the datagram or assigned to the
receiving port.  Without this label the host, gateway, or router will not
have the information it needs to make security decisions.  This security
label will be obtained from the CIPSO if the option is present in the
datagram.  See section 4.1.2 for handling procedures for unlabeled
datagrams.  This label will be compared against the PORT (if appropriate)
and HOST configuration parameters defined in section 3.

If any field within the CIPSO option, such as the DOI identifier, is not
recognized the IP datagram is discarded and an ICMP "parameter problem"
(type 12) is generated and returned.  The ICMP code field is set to "bad
parameter" (code 0) and the pointer is set to the start of the CIPSO field
that is unrecognized.

If the contents of the CIPSO are valid but the security label is
outside of the configured host or port label range, the datagram is
discarded and an ICMP "destination unreachable" (type 3) is generated
and returned.  The code field of the ICMP is set to "communication with
destination network administratively prohibited" (code 9) or to



Internet Draft, Expires 15 Jan 93                                 [PAGE 9]



CIPSO INTERNET DRAFT                                         16 July, 1992



"communication with destination host administratively prohibited"
(code 10).  The value of the code field used is dependent upon whether
the originator of the ICMP message is acting as a CIPSO host or a CIPSO
gateway.  The recipient of the ICMP message MUST be able to handle either
value.  The same procedure is performed if a CIPSO can not be added to an
IP packet because it is too large to fit in the IP options area.

If the error is triggered by receipt of an ICMP message, the message
is discarded and no response is permitted (consistent with general ICMP
processing rules).

알 수 없는 tag와 unlabeled packet

610-635

5.1.1 인식하지 못한 tag type

기본적으로 알 수 없는 tag type은 `parameter problem`으로 처리해야 합니다(MUST). Administrator가 안전하게 무시할 수 있는 tag type을 지정하게 할 수 있지만(MAY), 이는 선택적 확장입니다.

5.1.2 Unlabeled packet

Network port가 모든 inbound datagram에 CIPSO를 요구하지 않도록 구성할 수 있습니다. 이 경우 port에 CIPSO label을 지정해 모든 unlabeled IP datagram과 연결해야 합니다. Single-level network나 non-CIPSO host가 모두 같은 label로 동작하는 혼합 network에 사용할 수 있습니다.

CIPSO option이 필수인데 없으면 datagram을 버리고 ICMP `parameter problem` type 12를 반환합니다. Code는 `option missing` 1이고 pointer는 빠진 option type 값인 134로 설정합니다.

5.1.1    Unrecognized tag types

The default condition for any CIPSO implementation is that an
unrecognized tag type MUST be treated as a "parameter problem" and
handled as described in section 4.1.  A CIPSO implementation MAY allow
the system administrator to identify tag types that may safely be
ignored.  This capability is an allowable enhancement, not a
requirement.


5.1.2    Unlabeled Packets

A network port may be configured to not require a CIPSO label for all
incoming  datagrams.  For this configuration a CIPSO label must be
assigned to that network port and associated with all unlabeled IP
datagrams.  This capability might be used for single level networks or
networks that have CIPSO and non-CIPSO hosts and the non-CIPSO hosts
all operate at the same label.

If a CIPSO option is required and none is found, the datagram is
discarded and an ICMP "parameter problem" (type 12) is generated and
returned to the originator of the datagram.  The code field of the ICMP
is set to "option missing" (code 1) and the ICMP pointer is set to 134
(the value of the option type for the missing CIPSO option).

출력 label 범위와 DOI 선택

636-672

5.2 출력 절차

CIPSO option은 datagram 하나에 한 번만 나타나야 합니다(MUST). MAC Sensitivity class의 tag type은 한 CIPSO option에 하나만 넣을 수 있습니다(MAY). 당시 정의된 type 집합에서는 사실상 label 하나에 tag 하나만 들어갑니다.

모든 outbound datagram은 다음 조건을 만족해야 합니다.

PORT_LABEL_MIN <= CIPSO label <= PORT_LABEL_MAX

조건을 만족하지 않으면 datagram을 반드시 버립니다. Port가 하나뿐이면 `HOST_LABEL_MIN/MAX`로 대체할 수 있습니다.

Administrator가 outbound DOI를 구성합니다. Port-level이면 `PORT_DOI`, network-level이면 `NET_DOI`, host-level이면 `HOST_DOI`의 값을 사용해야 합니다. 구현은 DOI assignment level 하나만 지원해도 됩니다.

5.2    Output Procedures

A CIPSO option MUST appear only once in a datagram.  Only one tag type
from the MAC Sensitivity class MAY be included in a CIPSO option.  Given
the current set of defined tag types, this means that CIPSO labels at
first will contain only one tag.

All datagrams leaving a CIPSO system MUST meet the following condition:

        PORT_LABEL_MIN <= CIPSO label <= PORT_LABEL_MAX

If this condition is not satisfied the datagram MUST be discarded.
If the CIPSO system only supports one port, the HOST_LABEL_MIN and the
HOST_LABEL_MAX parameters MAY be substituted for the PORT parameters in
the above condition.

The DOI identifier to be used for all outgoing datagrams is configured by



Internet Draft, Expires 15 Jan 93                                 [PAGE 10]



CIPSO INTERNET DRAFT                                         16 July, 1992



the administrator.  If port level DOI identifier assignment is used, then
the PORT_DOI configuration parameter MUST contain the DOI identifier to
use.  If network level DOI assignment is used, then the NET_DOI parameter
MUST contain the DOI identifier to use.  And if host level DOI assignment
is employed, then the HOST_DOI parameter MUST contain the DOI identifier
to use.  A CIPSO implementation need only support one level of DOI
assignment.

DOI 변환과 ICMP label

673-701

5.3 DOI 처리 요구 사항

CIPSO 구현은 DOI를 최소 하나 지원해야 하며(MUST) 여러 DOI 지원이 권장됩니다(SHOULD). IP broadcast가 가능하도록 network 안에 공통 DOI가 최소 하나 있는지 administrator가 확인해야 합니다.

CIPSO gateway는 network 사이에서 datagram을 forward할 때 option을 한 DOI에서 다른 DOI로 변환할 수 있어야 합니다(MUST). 전용 router에는 효율을 위해 바람직한 기능일 뿐입니다.

5.4 ICMP message의 label

Outbound ICMP의 CIPSO label은 원인을 만든 datagram의 label과 동등해야 합니다(MUST). 원래 CIPSO label 문제로 ICMP가 생성됐다면 원래 label을 쓰거나, 응답 없이 원 datagram을 drop하는 두 방식이 허용됩니다.

해석할 수 없거나 local range 밖인 label을 그대로 쓴 ICMP는 system 밖으로 나갈 수 없을 가능성이 커서 대부분 두 선택의 결과가 같습니다.

5.3    DOI Processing Requirements

A CIPSO implementation MUST support at least one DOI and SHOULD support
multiple DOIs.  System and network administrators are cautioned to
ensure that at least one DOI is common within an IP network to allow for
broadcasting of IP datagrams.

CIPSO gateways MUST be capable of translating a CIPSO option from one
DOI to another when forwarding datagrams between networks.  For
efficiency purposes this capability is only a desired feature for CIPSO
routers.


5.4    Label of ICMP Messages

The CIPSO label to be used on all outgoing ICMP messages MUST be equivalent
to the label of the datagram that caused the ICMP message.  If the ICMP was
generated due to a problem associated with the original CIPSO label then the
following responses are allowed:

  a.  Use the CIPSO label of the original IP datagram
  b.  Drop the original datagram with no return message generated

In most cases these options will have the same effect.  If you can not
interpret the label or if it is outside the label range of your host or
interface then an ICMP message with the same label will probably not be
able to exit the system.

DOI 배정·감사·연락처

702-734

6. DOI identifier number 배정

DOI identifier number 배정 요청은 Internet Assigned Numbers Authority(IANA)에 제출합니다.

7. 감사의 말

이 RFC의 많은 내용은 Sun Microsystems의 Gary Winiger가 수행하고 INTEROP 89 Commercial IPSO Workshop에서 `Commercial IP Security Option`으로 발표한 작업을 바탕으로 하며 일부는 그대로 가져왔습니다.

8. 저자 주소

IETF CIPSO Working Group 구성원에게 배포할 mail은 `cipso@wdl1.wdl.loral.com`, 배포 목록 추가·삭제 요청은 `cipso-request@wdl1.wdl.loral.com`으로 보내도록 기록되어 있습니다.

Internet Draft, 1993년 1월 15일 만료, 11쪽

6.    Assignment of DOI Identifier Numbers                                   =

Requests for assignment of a DOI identifier number should be addressed to
the Internet Assigned Numbers Authority (IANA).


7.    Acknowledgements

Much of the material in this RFC is based on (and copied from) work
done by Gary Winiger of Sun Microsystems and published as Commercial
IP Security Option at the INTEROP 89, Commercial IPSO Workshop.


8.    Author's Address

To submit mail for distribution to members of the IETF CIPSO Working
Group, send mail to: cipso@wdl1.wdl.loral.com.



Internet Draft, Expires 15 Jan 93                                 [PAGE 11]



CIPSO INTERNET DRAFT                                         16 July, 1992




To be added to or deleted from this distribution, send mail to:
cipso-request@wdl1.wdl.loral.com.

참고 문헌과 마지막 page

735-791

9. 참고 문헌

  • RFC 1038, `Draft Revised IP Security Option`, M. St. Johns, IETF, 1988년 1월
  • RFC 1108, `U.S. Department of Defense Security Options for the Internet Protocol`, Stephen Kent, IAB, 1991년 3월 1일

원문의 나머지 빈 줄과 12쪽 footer인 `Internet Draft, Expires 15 Jan 93`도 아래 영어 원문 block에 줄 좌표 그대로 보존했습니다.

9.    References

RFC 1038, "Draft Revised IP Security Option", M. St. Johns, IETF, January
1988.

RFC 1108, "U.S. Department of Defense Security Options
for the Internet Protocol", Stephen Kent, IAB, 1 March, 1991.














































Internet Draft, Expires 15 Jan 93                                 [PAGE 12]