Sunday, November 22, 2009
Google  
Web voicendata.com
 RSS | Archive    
• Saarc CEO Conclave 2009 at Dhaka, Bangladesh from October 30 to November 1, 2009
 Home > Top Stories > A Secure E-Business Environment
  TOP STORIES
A Secure E-Business Environment
Continued from page: 2

Shyamanuja Das
Wednesday, December 27, 2000

Authentication

In simple terms, knowing the identity of the person who is trying to do some business with you. Passwords are the most primitive method of doing that. However, passwords can be stolen and misused. Often, stricter authentication like digital certificates, smart cards, etc., are required.

Confidentiality

The Internet is open to all. It is difficult to know the identity of people who use the Net. Keeping information out of the reach of people who are not authorised to have it, is what confidentiality seeks to achieve. Encryption is the most popular method to do that.

Information Integrity

Once a document is created, it needs to be kept intact. Alterations could mean serious financial and legal implications.

Non-repudiation

On The Web

Security Solution Companies

Baltimore Technologies www.baltimore.com 
Celo Communications www.celocom.com 
Checkpoint www.checkpoint.com 
Computer Associates www.ca.com 
Entegrity www.entegrity.com 
Entrust Technologies www.entrust.com 
Globalsign www.globalsign.com 
Rainbow Technologies www.rainbow.com 
RSA Security www.rsasecurity.com 
VeriSign www.verisign.com 
WiseKey www.wisekey.com 
Xcert Software www.xcert.com 

Making sure that a deal is a deal. Non-repudiation means that a party cannot deny having agreed to or sent a document. Just imagine a situation wherein a person buys 1000 shares of a high premium stock and the next day, when the share price crashes, denies having bought that. The loss to the broker could run to lakhs.

Trust Infrastructure: Public Key Cryptography

The TINA factor of e-business is increasing day by day. There is no other option but to make this business as hassle-free and secure as possible. One way of building a high-trust e-business infrastructure that is increasingly getting popular, is what is called the public key cryptography.

Cryptography uses mathematical algorithms to encrypt and decrypt data. Public key cryptography is a method where a pair of large numbers is used as keys to encrypt and decrypt data. One key, with the owner (sender), is called the private key, this is known only to himself; and the other, called public key is distributed to others. This pair of keys is such that a document that has been locked by one can only be unlocked by the other.

A sender uses his private key to encrypt the message and appends this encrypted data to the message. This is called digital signature. The receiver uses the public key of the sender to decrypt the message as well as to verify the identity of the sender. This solves the problem of authentication, message integrity and non-repudiation.

Though this solves a lot of problems, there still remains a major gap. That is, even after being sure about the electronic identity of a person, how do we make sure that the electronic identity of the sender is the same as what he claims to be? This problem is addressed by digital certificates. Based on a popular standard called X.509, digital certificates are issued by a trusted third party called the Certification Authority (CA), and bind the actual identity of a person/company to their/its electronic identity.

The process of digital certificates establishing secure transactions is called public key infrastructure (PKI). Today, PKI is becoming the most preferred security mechanism.

Page(s)   1  2  3  4  

Print Comment Email DiggDigg DeliciousDel.icio.us RedittReddit
Network Security -- Beyond Insurance.
BSNL: Tall Order?
CONVERGENCE: The Search for a Sarkari Approach!
 





 

Current Issue


ZTE:Leading CDMA Technology


Extraordinary Networks:Freedom of Choice





Your Opinion Matters

Does cloud computing cast a cloud on the future of IT professionals?

Is your Accounts Payable Solution working for you? Think Again…


   CIOL Services
IT News | IT Jobs | IT Outsourcing | IT Shopping
 



  For Voice&Data Print Subscription
  [ Magazine Subscription ]  [ Contact Info ]  [ Advertise : Online | Magazine | Advertising Print | Mediakit Print ]

 
Other CyberMedia web sites
[Dataquest]  [PCQuest]  [CIOL]  [Living Digital]  [IDC India]
[DQ Channels]  [The DQweek]  [CyberMedia Events]
[CyberMedia Digital]  [Cyber Astro]  [CyberMedia India]
[Global Services]  [BioSpectrum]  [BioSpectrum Asia]
[Computer Shopper]   [College Buying Guide]   [Voice&DataConnect

CyberMedia India Ltd

 
  Copyright © CMIL. All rights reserved.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.
Usage of this web site is subject to terms and conditions.
Broken links? Problems with site? Send email to
webmaster@ciol.com