Common Data Security Architecture (CDSA) White Paper

What Is CDSA?

Figure 1-2 CDSA Components on HP-UX

Common Security Services Manager (CSSM) APIs

 

 

 

Crypotgraphy

 

 

Certificate

 

 

Data Storage

 

 

Trust Policy

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Services

 

 

Library

 

 

Library

 

 

 

 

 

 

 

 

 

 

 

 

Manager

 

 

 

 

 

Manager

 

 

Manager

 

 

Manager

 

 

 

 

 

 

 

 

 

 

 

 

and

 

 

 

 

 

and

 

 

and

 

 

and

 

 

 

 

 

 

 

 

 

 

 

 

Interface

 

 

 

 

 

Interface

 

 

Interface

 

 

Interface

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Cryptography

Certificate

Data

Trust

 

 

 

Services

Storage

Policy

 

 

 

Library

 

 

 

Provider

Library

Library

 

 

 

(CL)

 

 

 

(CSP)

(DL)

(TP)

 

 

 

 

 

 

CDSA Components in HP-UX

Each component of the HP-UX CDSA infrastructure provides a key element necessary for a unified security architecture.

The Common Security Service Manager (CSSM) provides access to the general security services, such as encryption/decryption, signatures, and so forth. The CSSM’s Core Service APIs:

Provides capability for encryption, decryption, and authentication

Integrate and manage all modular security services,

Provide support for additional add-in security modules.

Provide CSP integrity services.

A Cryptographic Service Provider (CSP) implements the functionality implied by the API functions and services, including:

Bulk encryption and decryption

Digital signing and verification

Cryptographic hash

Key exchange

Key and key-pair generation

Random number generation

Encrypted storage of private keys

Chapter 1

13