Overview
ISO/IEC 11577:1995 specifies the Network Layer Security Protocol (NLSP) for the OSI Network layer. The standard defines a protocol to be used by End Systems and Intermediate Systems to provide network‑layer security services referenced to CCITT Rec. X.213, ISO/IEC 8348 and ISO 8648. NLSP covers both connectionless (NLSP‑CL) and connection‑oriented (NLSP‑CO) operation, protection functions, security associations, and protocol data unit (PDU) encoding.
Keywords: ISO/IEC 11577, Network Layer Security Protocol, NLSP, OSI, network layer security, NLSP‑CL, NLSP‑CO.
Key Topics
- Scope & Definitions: Terminology aligned with OSI Reference Model, network service conventions and security architecture definitions.
- Security Associations (SA): Attributes, rules and lifecycle management for SAs used to protect network traffic.
- NLSP Modes: Functional separation and procedures for connectionless (NLSP‑CL) and connection‑oriented (NLSP‑CO) security.
- Protocol Functions: Processing for NLSP‑UNITDATA, NLSP‑CONNECT, NLSP‑DATA, expedited data, RESET, DISCONNECT and ACK procedures.
- Encapsulation Functions: SDT‑PDU based encapsulation and no‑header encapsulation for NLSP‑CO.
- PDU Structure & Encoding: Content field formats, protected data fields, SA and connection control PDUs.
- Peer Authentication & SA Protocols: Mechanisms for peer entity authentication and an SA protocol example using Key Token Exchange (KTE) and digital signatures (Annex C).
- Conformance & Interoperability: Static and dynamic conformance requirements, Protocol Implementation Conformance Statement (PICS), and mappings to CCITT/ISO primitives (e.g., X.213, X.25).
Applications
ISO/IEC 11577 (NLSP) is intended for:
- Network equipment vendors implementing OSI stack features in routers, switches and intermediate systems.
- Protocol implementers developing secure network layer stacks for end systems and gateways.
- Security architects designing network‑layer protection (confidentiality, integrity, authentication) across heterogeneous networks.
- Interoperability and test laboratories validating conformance, PDU encoding and SA behavior.
- Standards bodies and system integrators mapping NLSP behavior to existing CCITT/ISO recommendations.
Practical benefits include standardized network‑layer security mechanisms, improved interoperability between vendors, and formal conformance criteria to support secure internetworking.
Related Standards
- CCITT Rec. X.213 / ISO 8324 (Network layer service conventions)
- ISO/IEC 8348 (Network service)
- ISO 8648 and X.25 (mappings and interoperability references)
For implementers and architects seeking network layer security standards, ISO/IEC 11577:1995 provides the NLSP protocol blueprint, SA model, PDU formats and conformance guidance required to deploy interoperable OSI network layer protection.