标准号:ISO/IEC 9594-2-2005
英文名称:Information technology - Open Systems Interconnection - The Directory: Models
被替代标准:ISO/IEC 9594-2-2008
代替标准:ISO/IEC 9594-2-2001;ISO/IEC FDIS 9594-2-2006
采用标准:ANSI/INCITS/ISO/IEC 9594-2-2008,IDT;GB/T 16264.2-2008,IDT;ITU-T X.501-2005,IDT
起草单位:ISO/IEC JTC 1/SC 6
标准简介:The models defined in this Recommendation | International Standard provide a conceptual and terminological
framework for the other ITU-T X.500-series Recommendations | parts of ISO/IEC 9594 which define various aspects of
the Directory.
The functional and administrative authority models define ways in which the Directory can be distributed, both
functionally and administratively. Generic DSA and DSA information models and an Operational Framework are also
provided to support Directory distribution.
The generic Directory Information Models describe the logical structure of the DIB from the perspective of Directory
and Administrative Users. In these models, the fact that the Directory is distributed, rather than centralized, is not
This Recommendation | International Standard provides a specialization of the generic Directory Information Models to
support Directory Schema administration.
The other ITU-T Recommendations in the X.500 series | parts of ISO/IEC 9594 make use of the concepts defined in this
Recommendation | International Standard to define specializations of the generic information and DSA models to
provide specific information, DSA and operational models supporting particular directory capabilities.
The security model establishes a framework for the specification of access control mechanisms. It provides a
mechanism for identifying the access control scheme in effect in a particular portion of the DIT, and it defines three
flexible, specific access control schemes which are suitable for a wide variety of applications and styles of use. The
security model also provides a framework for protecting the confidentiality and integrity of directory operations using
mechanisms such as encryption and digital signatures. This makes use of the framework for authentication defined in
ITU-T Rec. X.509 | ISO/IEC 9594-8 as well as generic upper layers security tools defined in ITU-T Rec. X.830 |
ISO/IEC 11586-1.
DSA models establish a framework for the specification of the operation of the components of the Directory.
