HTTPS provides secure HTTP channels. HTTPS is HTTP to which SSL is added, and SSL
ensures the security of HTTPS.
2.4.2 Application Security
EG860 application security includes wireless security and OM security.
2.4.2.1 Wireless Security
EG860 wireless security includes authentication, air-interface data encryption, and integrity
protection.
For details, see
Security Feature Manual
.
2.4.2.2 OM Security
OM security includes user authentication, access control, OM system security, and software
digital signature.
2.4.2.2.1 User Authentication and Access Control
User authentication and access control are implemented for users to be served by the EG860.
The objective of authentication is to identify users and grant the users with proper permission.
The objective of access control is to specify and restrict the operations to be performed and the
resources to be accessed by the users.
User Account Management
Local user account management involves modification and query of local user accounts.
Information about a local user account includes user name and user description. To improve
system security, the following security requirements must be satisfied:
l
Password security policies
–
The password must contain 8 to 32 characters
–
The password must contain at least two character types and must not contain three or
more than three consecutively same characters
–
The password must not contain the account name or its reversion
–
Maximum number of failed password attempts
–
Threshold of consecutive password modification failures
–
Duration after which a locked password can be automatically unlocked
l
Password usage rules
–
Users must enter passwords twice when changing passwords, and the passwords entered
cannot be copied.
–
Users can change their own passwords. The old password must be verified when it is
changed.
–
User accounts are locked when the number of consecutive password failures reaches a
specified threshold.
l
Password storage and transmission rules
EG860
User Guide
2 Introduction
Issue 02 (2015-04-10)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
15