cryptography and pki february 12, 2001 february 12, 2001 abn amro

20
Cryptography and PKI February 12, 2001 February 12, 2001 ABN AMRO

Upload: dwayne-richards

Post on 17-Jan-2018

219 views

Category:

Documents


0 download

DESCRIPTION

Cryptography Today - accountability, - fairness, - accuracy, and confidentiality. - accountability, - fairness, - accuracy, and confidentiality.

TRANSCRIPT

Page 1: Cryptography and PKI February 12, 2001 February 12, 2001 ABN AMRO

Cryptography and PKI

February 12, 2001February 12, 2001

ABN AMRO

Page 2: Cryptography and PKI February 12, 2001 February 12, 2001 ABN AMRO

Agenda

Cryptography Today PKI Algorithms PKC Considerations Strengths and Limitations

Page 3: Cryptography and PKI February 12, 2001 February 12, 2001 ABN AMRO

Cryptography Today

•-         accountability,

•-         fairness,

•-         accuracy, and

•confidentiality.

Page 4: Cryptography and PKI February 12, 2001 February 12, 2001 ABN AMRO

Cryptography Today

Primary Prevention

From Conception to Installation

Page 5: Cryptography and PKI February 12, 2001 February 12, 2001 ABN AMRO

Cryptography Today

Possibility Acceptability

Page 6: Cryptography and PKI February 12, 2001 February 12, 2001 ABN AMRO

Cryptography Today

THREAT MODEL•What the system is designed to protect

•For whom

•How long

Page 7: Cryptography and PKI February 12, 2001 February 12, 2001 ABN AMRO

System Design

number theory, complexity theory, Information theory, probability theory, abstract algebra,

and formal analysis, among others.

Page 8: Cryptography and PKI February 12, 2001 February 12, 2001 ABN AMRO

System Design

•security and accessibility,

•anonymity and accountability,

•privacy and availability

Page 9: Cryptography and PKI February 12, 2001 February 12, 2001 ABN AMRO

Implementation Problems

bad random-number generators,

don't check properly for error conditions,

and leave secret information in swap files.

Page 10: Cryptography and PKI February 12, 2001 February 12, 2001 ABN AMRO

Cryptography for people

Users want simplicity, convenience, and compatibility with existing (insecure) systems

Page 11: Cryptography and PKI February 12, 2001 February 12, 2001 ABN AMRO

State of Security

Assume the WORSTAssume your adversaries are better than they are. Assume science and technology will soon be able to do things they cannot yet. Give yourself a margin for error. Give yourself more security than you need today.

Page 12: Cryptography and PKI February 12, 2001 February 12, 2001 ABN AMRO

Symmetric Key

Plain Text Cipher Text

Page 13: Cryptography and PKI February 12, 2001 February 12, 2001 ABN AMRO

Cryptography and PKI

Page 14: Cryptography and PKI February 12, 2001 February 12, 2001 ABN AMRO

Things To Consider

Does the organization have enough resources/personnel to deploy and maintain the framework?

If so, do they possess the proper skill sets? Will the security management model be

centralized or decentralized? What are the necessary components? What vendors provide the necessary

components? do the components work together?

Page 15: Cryptography and PKI February 12, 2001 February 12, 2001 ABN AMRO

Public Key Infrastructure

Algorithms:

RSA, Diffie-Hellman, El Gamal, DSS.

Page 16: Cryptography and PKI February 12, 2001 February 12, 2001 ABN AMRO

RSA

Key Generation

Encryption

Decryption

Page 17: Cryptography and PKI February 12, 2001 February 12, 2001 ABN AMRO

DSS

Page 18: Cryptography and PKI February 12, 2001 February 12, 2001 ABN AMRO

PKC Considerations

Page 19: Cryptography and PKI February 12, 2001 February 12, 2001 ABN AMRO

Strengths & Limitations

PKI

Strengths

Enables organizations to streamline security Ease of manageability and maintenance Address security issues at the enterprise level Total cost of ownership is reduced

Limitations

Interoperability between vendors and products Interpretation of standards Initial cost of implementation

Page 20: Cryptography and PKI February 12, 2001 February 12, 2001 ABN AMRO

Popular VENDORS

Baltimore Tech.

Entrust

Verisign

Valicert

DSS: iPlanet, Siemens, Critical Path, Oracle