USA India
Home Articles UserTV Press Releases Dictionary Books Education Careers B-Channels Resources Forums Blogs Classifieds
Tuesday 18 Nov, 2008 eNewsletter Register Login
Archives
Articles By Date
Articles By Category
 
 
 Archives >> Details
Making an Unbreakable Code
As the the internet gets more crowded, encryption becomes more crucial
Posted by : Don Fitzwater

The Internet has grown from a resource used only by academic and research organizations to a global network that plays an increasingly important role in personal and corporate communications. Sensitive information of all kinds is increasingly finding its way into electronic form and then onto the Internet.

Unfortunately, because this information is sent over the Internet (which is an open network), valuable data can be easily intercepted and exploited. Obviously, there could be disastrous consequences for individuals and businesses if this information fell into the wrong hands. Enter cryptography and encryption software.

Why encrypt?

Before we delve into the how, we should look at why you might want to encrypt your most sensitive information before sending it to the Internet.

Most people know little about computer security. They don't realize that their e-mail messages are not sent point-to-point. Instead, they are sent from one computer to another. In fact, e-mail is like sending a postcard--anyone who comes across it can read it.

So without the knowledge of either the sender or the recipient, e-mail can easily be intercepted and copied. To remedy this problem, there are quite a few systems for encrypting e-mail on the market today.

And then there is e-commerce. Today, Internet transactions are primarily credit card-based. Steps have to be taken to safeguard credit-card information from prying eyes.

The first step is to have the browser connecting to the e-commerce site's server in secure mode. This is accomplished by using Secure Sockets Layer technology (SSL) to encrypt everything sent back and forth between the browser and the server. If an e-commerce site is going to be secure, then the credit-card info, once collected, needs to be stored in encrypted form--preferably off the server rather than in plain text, as is the case with far too many e-commerce applications. Encryption is mostly needed to help protect against credit-card thieves.

Another component of e-commerce is digital cash. Cryptographer and computer scientist David Chaum developed a set of techniques using digital signatures that makes digital cash possible. Digital signatures can help prove the origin of data (a process called authentication). The technology can also be used to ensure the privacy of the user, permitting payments that do not reveal the customer's identity. Again, encryption plays a key role in making the whole process work.

And while considering these two points (e-mail security and e-commerce transactions) alone ought to give pause to most users before they send information over the Internet, there remain more sinister and compelling reasons to consider encrypting your information.

Today, if the government wants to violate the privacy of ordinary citizens, it has to expend a certain amount of expense and effort to intercept, open, and read paper mail, or listen to and transcribe a spoken telephone conversation. This kind of labor-intensive monitoring is not usually practical on a large scale. And it is only supposed to be done in cases where it seems absolutely necessary.

But more and more of our private communications are being routed through electronic channels. Channels like e-mail are simply too easy to intercept and scan for interesting keywords. This can be done routinely, automatically, and imperceptibly on a very large scale. And as some chilling recent news stories can attest, the National Security Agency, through its project Echelon, already scans international and foreign communications in this way.

Imagine a global spying network that can eavesdrop on every single phone call, fax, or e-mail, anywhere on the planet. It sounds like something out of a Tom Clancy novel, but it exists. According to a BBC report from November 1999, a Cold War­era electronic intelligence-gathering resource has been turned to other purposes--including commercial spying on foreign competitors to American and English businesses.

Powerful computers capable of voice recognition can listen to every international telephone call, fax, e-mail, or radio transmission. They home in on a long list of keywords, or patterns of messages. They are supposed to be looking for evidence of international crime, like terrorism. But there appear to be other, less savory purposes for Echelon than the intelligence, antiterrorism and crime-fighting missions it was originally built to fulfill.

The BBC report cites information from journalist Duncan Campbell, who has spent much of his career investigating Echelon. In a report commissioned by the European Parliament, he produced evidence that the NSA listened in on phone calls from a French firm bidding for a contract in Brazil. It passed the information to an American competitor, which won the contract. Big Brother not only exists; he may already be watching you.

Public-key Cryptography to the Rescue

Now that you're convinced that you don't want other people reading your e-mail without your knowledge or stealing your credit card information, just how are you to go about preventing it?

You need to investigate some of the products available for encrypting your sensitive information. As strange as it may seem, you are in the market to find the same kind (and level) of cryptography technology that governments, multinational corporations and major drug and arms dealers already employ to secure their most sensitive information.

Cryptography is the science of scrambling text so that no one but the intended recipient can read it. The goal is to transform text, called plaintext, into a form that is meaningless to anyone who might intercept it. The coded text is called ciphertext. The process of transforming plaintext into ciphertext is called encryption; the reverse process of transforming ciphertext into plaintext is called decryption.

If you want to encrypt a plaintext or decrypt ciphertext, you need an algorithm and a key. The algorithm usually consists of two parts: The encryption algorithm and the decryption algorithm. Only those who know the key and the respective algorithm can encrypt plaintext or decrypt ciphertext.

This kind of cryptography is known as private-key cryptography, and is also called symmetric cryptography. It uses a single key--the private key--for both encryption and decryption. In this scheme, the communicating parties have to agree on a secret key in advance. The disadvantage is that they have to find a secure way to exchange this key.

In conventional cryptosystems, such as the U.S. Federal Data Encryption Standard (DES), a single key is used for both encryption and decryption. This means that a key must be initially transmitted via secure channels so that both parties can know it before encrypted messages can be sent over insecure channels. This may be inconvenient. It also begs the question that if you already have a secure enough channel for exchanging keys, then why do you need cryptography in the first place?

Public-key cryptography solves this problem by using two keys instead. In public-key cryptosystems, everyone has two related complementary keys, a publicly revealed key and a secret key (frequently called a private key). Each key unlocks the code that the other key makes. Knowing the public key does not help you deduce the corresponding secret key. The public key can be published and widely disseminated across a communications network. This protocol provides privacy without the need for the same secure channels that a conventional cryptosystem requires.

Anyone can use a recipient's public key to encrypt a message to that person, and that recipient uses her own corresponding secret key to decrypt that message. No one but the recipient can decrypt it, because no one else has access to that secret key. Not even the person who encrypted the message can decrypt it.

Message authentication is also provided. The sender's own secret key can be used to encrypt a message, thereby signing it. This creates a digital signature of a message, which the recipient (or anyone else) can check by using the sender's public key to decrypt it. This proves that the sender was the true originator of the message, and that the message has not been subsequently altered by anyone else, because the sender alone possesses the secret key that made the signature. Forgery of a signed message is not feasible, and the sender cannot later disavow his signature.

These two processes can provide both privacy and authentication by first signing a message with your own secret key, then encrypting the signed message with the recipient's public key. The recipient reverses these steps by decrypting the message with her own secret key, then checking the enclosed signature with a public key. These steps are taken automatically by the recipient's software.

To protect e-mail and files, you should look into PGP (Pretty Good Privacy) software in a version that runs on the platform of your choice (Mac, Windows, Unix, etc.) PGP-based products are available in freeware and commercial-grade products. PGP is the world's de facto standard for e-mail encryption and authentication, with more than 6 million users.

PGP 6.5.1 MIT freeware supports RSA, PGP e-mail, and secure client-to-client connections using PGP certificates. It is available for non-commercial use only. You can download freeware versions of PGP for various platforms from MIT.

If you need to use PGP in a commercial environment, the commercial PGP VPN Client, available from Network Associates, supports certificates from industry leaders such as VeriSign, Entrust and Net Tools. PGP VPN can be used to create encrypted network connections to your company for secure remote access. The commercial client also includes PGPdisk for fast disk, file, and directory encryption and authentication, in addition to technical support.

For those more interested in protecting their whole enterprise versus just individual desktops, PGP technology has been extended to the enterprise back office. The PGP E-Business Server (again from Network Associates) enables automated e-commerce applications to leverage the powerful encryption and authentication PGP technologies on Solaris, Windows NT, Linux, AIX, HP-UX, and MVS platforms.This allows corporations to apply the ease of use, strength, and confidence of the PGP technology to protect corporate data in virtually any setting.

E-commerce Encryption

For Web-based e-commerce transactions, make sure that anytime you are exchanging sensitive information, you are connected to the host in secure mode using SSL. You should also do some research before you make a purchase to see if you can determine whether or not the merchant stores your credit-card info on the Web server and if it does, is it stored in plain text or encrypted format? Obviously, you are interested in doing business with the vendors who encrypt your sensitive information while it is in their possession.

And last but not least, consider the source. Today's technology allows almost anybody to easily set up shop on the Internet, where things aren't always what they seem. Make sure you do some checking before you give out vital information like credit-card numbers to complete strangers.

In today's information society, ensuring the security and privacy of its advanced communications has become critically important. Cryptography is a crucial technology to protect these communications.

Contributing Editor Don Fitzwater is a principal partner in Interface Solutions, a Minneapolis consulting firm.

 
 
Archives by Date
 
 
 
 
 
Copyright © 1994-2008 ComputerUser, Inc., All Rights Reserved All marks are trademarks of ComputerUser Media. Reproduction in whole or in part in any form or medium without express written permission of ComputerUser, Inc. is prohibited.
About us | Terms of use | Privacy Policy | Legal | Trademark/Copyright | Awards | Advertise | Writer guidelines | Sitemap | Contact | FAQ's | Feedback  | Link to us

Here are the topics we cover computer certification computer careers computer training computer games consulting data recovery data security digital entertainment emerging technology gadget reviews handheld computers hardware reviews home automation home networks home office how-to advice internet linux local companies local news local profiles macintosh mp3 players network security online music online security open-source small-business technology soho software reviews technology books technology dictionary vpn web site reviews wi-fi windows wireless technology tech articles tech news press releases tech dictionary education resources career solutions create your personal blog upload your videos become a writer usergroups special interest group SIG 3com cipts adobe adobe certified expert apc ncpi apple achds acpt acsa actc avaya bea 8.1 certified administrator 8.1 certified architect 8.1 certified developer 9 certified administrator bicsi rcdd checkpoint ccmse ccsa ccsa ngx ccse ccse ng plus with ai ccse ngx cisco access routing and lan switching ccda ccdp ccie ccip ccna ccnp ccnp old ccsp ccvp crmam ip communications optical proctored exams for validating knowledge sales specialist storage networking vpn and security wireless lan citrix cca 3.0 cca 4.0 cca 4.5 cca xp ccea 3.0 ccea 4.0 ccea xp ccia ciw ciw associate ciw certified instructor master ciw admin master ciw designer master ciw enterprise developer security analyst comptia a+ network+ security+ server+ computer associates ca cusa cuse cwna cwna cwsp dell eccouncil cea cep certified ethical hacker chfi e-commerce architect emc emc specialist implemenation technology foundations enterasys ese eta exam express exin exin itil extreme networks ena ens filemaker f7cd f8cd fortinet fortigate foundry cne fujitsu fujitsu guidance software ence hdi css hda hdm hdsa hitachi hitachi certified professional hp ais apc app aps ase certified systems developer csa cse master ase huawei hcne hyperion hcp ibm advanced deployment professional advanced technical expert application developer business process analyst certified administrator certified advanced system administrator certified advanced technical expert certified associate developer certified enterprise developer certified solution designer certified specialist certified systems expert database administrator db2 deployment professional enterprise developer eserver certified specialist ibm on demand business solution advisor solution designer solutions developer solutions expert storage administrator system administator iisfa cifi intel isaca cisa isc cissp sscp iseb itil ism cpm juniper jncia jncis legato lcaa lcea lotus clp lpi lpic level 1 lpic level 2 lpic level 3 macromedia mcafee mcdata csnd microsoft crm mbs mcad .net mcdba mcdst mcitp mcp mcpd mcsa longhorn mcsa 2003 mcsa 2008 mcsd .net mcse mcse 2000 security mcse 2000 to mcse 2003 upgrade mcse 2003 mcse 2003 messaging mcse 2003 security mcse 2008 mcts microsoft business solutions microsoft partner competency mile2 cnsa network appliance nac-na nac-nie naca nace nacp network general sniffer certified professional nokia nokia security administrator nortel ncde ncds ncse ncss ncts novell5 cna 5 cne 6 cna 6 cne 6.5 cne cne upgrade omg ocup oracle 10g dba 10g oca 11i 8i dba 9i dba 9i internet application developer oca ocp8 to ocp8i dba upgrade exam pmi project management professional polycom pcve redhat rhce rhct sair sas institute sas scp saas scp snia snia certified architect snia certified professional snia certified systems engineer snia storage networking certification program administrator professional associate symantec scse scsp scta scts teradata tca v2r5 tcad v2r5 tcda v2r5 tcis v2r5 tcm v2r5 tcp v2r5 tia ccnt ctp tibco tcp trusecure ticsa veritas infraguard chamber of commerce vcp vmware certified professional webex linkedin facebook myspace Professional page layout, image editing, vector illustration, and print production Website design, development, prototyping, and blogging Creation of rich interactive content Industry-standard visual effects and motion graphics Video capture, editing, and production; DVD titling; and digital audio, Adobe Photoshop CS3 extended, Adobe illustrator CS3,Adobe indesign CS3,Adobe Acrobat 8 Professional, Adobe Flash CS3 Professional, Adobe Dreamweaver CS3,Adobe Contribute CS3,Adobe Fireworks CS3,Adobe After Effects CS3 Professional, Adobe Premiere Pro CS3,Adobe Soundbooth CS3,Adobe Encore CS3,Adobe OnLocation,Adobe Bridge CS3,Adobe Version Cue CS3,Adobe Device Central CS3,Adobe Stock Photos, Intel Pentium 4 (1.4GHz processor for DV; 3.4GHz processor for HDV), Intel Centrino, Intel Xeon, (dual 2.8GHz processors for HD), or Intel Core, Duo (or compatible) processor; SSE2-enabled processor required for AMD systems Microsoft Windows XP with Service Pack 2 or Microsoft Windows Vista Home Premium, Business, Ultimate, or Enterprise (certified for 32-bit editions) 1GB of RAM for DV; 2GB of RAM for HDV and HD; more RAM recommended when running multiple components 10GB of available hard-disk space (additional free space required during installation) Dedicated 7,200 RPM hard drive for DV and HDV editing; striped disk array storage (RAID 0) for HD; SCSI disk subsystem preferred Microsoft DirectX compatible sound card (multichannel ASIO-compatible sound card recommended),1,280x1,024 monitor resolution with 32-bit color adapter Blu-ray burner required for Blu-ray Disc creation OHCI compatible IEEE 1394 port for DV and HDV capture, export to tape, and transmit to DV device QuickTime 7.1.2 software required to use QuickTime features Broadband Internet connection required for Adobe Stock Photos* and other services

3PAR, Accellion, Acronis, Actional, Active Endpoints, ActiveGrid, activePDF, ActiveServers, ActiveState, Actuate, Adaptec, Agile Software, AGiLiENCE, Agilysys, Akorri, AlachiSoft, Alter Logic, Altor Networks, Altova, AMD, AMDAHL, Amentra, Amyuni, anacubis, Apani, APC, Appcelerator, AppSense, AppStream, Array Networks, Ascential, Astaro, Attune Systems, Autodesk, AutoVirt, Availl, Avanade, Azul Systems, Barracuda Networks, BEA Systems, B-hive, Black Duck Software, Blackbaud, Blade Network Technologies, Blue Coat, Blue Lane, BlueArc, BlueNote Networks, BluePheonix Solutions, BMC Software, Borland, Bristol Technology, Brix Networks, BroadVision, Brocade, Burton Group, Business Objects, CA, CalAmp, Cassatt, Cast Iron Systems, Catbird, Cayenne Technologies, Ceedo Technologies, Cenzic, Certeon, CiRBA, Cisco Systems, Cision, Citrix Systems, ClearApp, ClearCube Technology, CollabNet, Compass America, Composite Software, Compugen, Compuware, Configuresoft, Continuity Software, Coraid, Courion, Coyote Point Systems, Crescendo Networks, CSC, DataCore, DataSynapse, Dell, Desktone, Digipede Technologies, Double-Take Software, Ecora Software, EDS, eG Innovations, Egenera, Elastra Corporation, Electric Cloud, Embotics, EMC Corporation, Emulex, Endeavors Technology, Enigmatic Corporation, Enterprise Management Associates, Entuity, EqualLogic, Ericom Software, ESRI, EVault, eXludus Technologies, F5 Networks, FalconStor, FastScale Technology, Foedus, Force10 Networks, Fortisphere, Forum Systems, Fujitsu, GemStone Systems, Getronics, GlassHouse, Green Hills Software, Grid Dynamics, GridGain Systems, GT Software, Hitachi, HP, Hyper9, Hyperic, IBM, ICEsoft, IGEL Technology, Illumita, ILOG, IMEX Research, Information Builders, Ingres, InstallFree, Integrien, Intel, Intellium, International Computerware, iTKO LISA, JBoss, Juniper, KACE, Kidaro, LeftHand Networks, Leostream, Lifeboat Distribution, Liquid Computing Corporation, Liquid Technology, Lynux Works, Mainline, ManageIQ, Managed Methods, ManageSoft, Marathon Technologies, McAfee, Mellanox Technologies, Microsoft, Mid-Atlantic Computers, Mindbridge Software, Mindreef, MKS, MonoSphere, Motorola, MQSoftware, mySoftIT, NASTEL, Ncomputing, NEC, Neocleus, NeoPath Networks, Neoware, NetApp, Netegrity, Neterion, Netuitive, Neverfail, Nexaweb, NextAxiom, Nimbus, Nimsoft, Niyuta, NoMachine, Novell, ONStor, Opalis Software, Open Kernel Labs, OpenSpan, OPNET Technologies, Optaros, OpTier, Oracle, Pano Logic, Parallels, Parasoft, Perforce Software, PHD Technologies, Phoenix Technologies, Phurnace Software, Pillar Data Systems, PlateSpin/Novell, Progress Software, Prolifics, ProSync Technology, Provision Networks, QLogic, Quest Software, Racemi, Raritan, Raxco Software, Red Hat, Reflex Security, Resolution Enterprises, RingCube Technologies, Riverbed Technology, Rogue Wave Software, RSA Security, Sagnet Solutions, SanDisk Corporation, SAP, SAVVIS, ScaleMP, Scalent Systems, Seanodes, Secure Command, Secure Computing, Sentillion, Shavlik Technologies, ServInt Internet Services, Silpion IT Solutions, SIMtone, Skytap, Skyway Software, Software AG, Sonasoft, SourceGear, Splunk, StackSafe, SteelEye Technology, StillSecure, StoneFly, Stonesoft, Stoneware, StoreVault, StrikeIron, STT WebOS, Sun Microsystems, SunGard, Supermicro Computer, Surgient, SWsoft, Sybase, Symantec, Systar, TBD Networks, Tenfold, TheInfoPro, Thinstall, Third Brigade, TIBCO Software, Tidal Software, Tideway Systems, TOA Solutions, TRANGO Virtual Processors, Trend Micro, Tresys Technology, Trigence, Tripwire, Ulteo, Unisys, United Devices, VaST Systems, VDIworks, VeeAm Software, Verari Systems, Verio, VeriSign, Vicom Computer Services, VirtenSys, Virtera, Virtual Iron, VirtualLogix, Virtugo Software, Virtutech, VisionCore, Vizioncore, VKernel, VMLogix, vmSight, VMware, Vordel, vThere-Sentillion, Vyatta, WaveMaker, Web Age Solutions, WSO2, Wyse Technology, XDS, XenoCode, Xiotech, xkoto, Xsigo Systems, Zenith Optemedia, Zeus Technology.