An Analysis of the Performance and Security of J2SDK 1.4 JSSE Implementation of SSL/TLS
暫譯: J2SDK 1.4 JSSE 實作 SSL/TLS 的性能與安全性分析
Bias, Danny R.
- 出版商: Hutson Street Press
- 出版日期: 2025-05-22
- 售價: $830
- 貴賓價: 9.5 折 $789
- 語言: 英文
- 頁數: 100
- 裝訂: Quality Paper - also called trade paper
- ISBN: 1025136489
- ISBN-13: 9781025136486
-
相關分類:
資訊安全
海外代購書籍(需單獨結帳)
相關主題
商品描述
The Java SSL/TLS package distributed with the J2SE 1.4.2 runtime is a Java implementation of the SSLv3 and TLSv1 protocols. Java-based web services and other systems deployed by the DoD will depend on this implementation to provide confidentiality, integrity, and authentication. Security and performance assessment of this implementation is critical given the proliferation of web services within DoD channels. This research assessed the performance of the J2SE 1.4.2 SSL and TLS implementations, paying particular attention to identifying performance limitations given a very secure configuration. The performance metrics of this research were CPU utilization, network bandwidth, memory, and maximum number of secure socket that could be created given various factors. This research determined an integral performance relationship between the memory heap size and the encryption algorithm used. By changing the default heap size setting of the Java Virtual Machine from 64 MB to 256 MB and using the symmetric encryption algorithm of AES256, a high performance, highly secure SSL configuration is achievable. This configuration can support over 2000 simultaneous secure sockets with various encrypted data sizes. This yields a 200 percent increase in performance over the default configuration, while providing the additional security of 256-bit symmetric key encryption to the application data.
This work has been selected by scholars as being culturally important, and is part of the knowledge base of civilization as we know it. This work was reproduced from the original artifact, and remains as true to the original work as possible. Therefore, you will see the original copyright references, library stamps (as most of these works have been housed in our most important libraries around the world), and other notations in the work.
This work is in the public domain in the United States of America, and possibly other nations. Within the United States, you may freely copy and distribute this work, as no entity (individual or corporate) has a copyright on the body of the work.
As a reproduction of a historical artifact, this work may contain missing or blurred pages, poor pictures, errant marks, etc. Scholars believe, and we concur, that this work is important enough to be preserved, reproduced, and made generally available to the public. We appreciate your support of the preservation process, and thank you for being an important part of keeping this knowledge alive and relevant.
商品描述(中文翻譯)
Java SSL/TLS 套件隨 J2SE 1.4.2 執行環境發佈,是 SSLv3 和 TLSv1 協議的 Java 實作。由美國國防部(DoD)部署的基於 Java 的網路服務及其他系統將依賴此實作來提供機密性、完整性和身份驗證。考量到網路服務在 DoD 渠道中的普及,對此實作的安全性和性能評估至關重要。本研究評估了 J2SE 1.4.2 的 SSL 和 TLS 實作的性能,特別關注在非常安全的配置下識別性能限制。本研究的性能指標包括 CPU 使用率、網路帶寬、記憶體,以及在各種因素下可以創建的最大安全套接字數量。本研究確定了記憶體堆大小與所使用的加密演算法之間的整體性能關係。通過將 Java 虛擬機的預設堆大小設定從 64 MB 更改為 256 MB,並使用對稱加密演算法 AES256,可以實現高性能、高安全性的 SSL 配置。此配置可以支持超過 2000 個同時的安全套接字,並處理各種加密數據大小。這使得性能比預設配置提高了 200%,同時為應用數據提供了 256 位對稱密鑰加密的額外安全性。
這項工作被學者選為具有文化重要性,並且是我們所知文明知識基礎的一部分。這項工作是從原始文獻複製而來,並儘可能忠實於原作。因此,您將看到原始的版權參考、圖書館印章(因為這些作品大多存放在我們世界上最重要的圖書館中)以及作品中的其他註記。
這項工作在美國是公共領域,並可能在其他國家也是如此。在美國,您可以自由複製和分發這項工作,因為沒有任何實體(個人或公司)對該作品的內容擁有版權。
作為歷史文物的複製品,這項工作可能包含缺失或模糊的頁面、劣質圖片、錯誤的標記等。學者們認為,並且我們同意,這項工作足夠重要,值得被保存、複製並普遍提供給公眾。我們感謝您對保存過程的支持,並感謝您成為保持這些知識活躍和相關的重要一部分。