Showing posts with label digital. Show all posts
Showing posts with label digital. Show all posts

Friday, April 4, 2008

Computers and Privacy part 3

RSA Public Key Cryptography

Several algorithms are used today for public-key asymmetric encryption. The most widely known is called the RSA algorithm, named after its inventors, Ronald Rivest, Adi Shamir, and Len Adleman. This method is based on multiplying two prime numbers to come up with the key pair. Further mathematical functions are performed after the multiplication to create the actual key pair. It's a simple matter to use a computer to come up with a rather large prime number, but it's a difficult computation task to take the result of this multiplication and the subsequent operations performed and determine which two prime numbers were used to generate it.

If you want to learn more about RSA, visit the Web site for the company founded to market this technology: www.rsasecurity . com. The RSA Security Web site is an excellent resource for encryption techniques overall, but also has a lot of information pertaining to the RSA algorithm, which has been licensed to a large number of software and hardware security providers.

Because of the difficulty in cracking RSA-encrypted data, it has been adopted by a large number of vendors, including Sun, Microsoft, and Novell, and is the most widely used cryptosystem today.

Digital Certificates

Digital certificates are used to bind a person's name (or an identity) to a public key. Certificates, then, must come from a trusted authority. The certificate itself is determined to be valid (that is, it was issued by the certificate authority [CA] it claims to represent) by a digital signature. Because the public key of a CA can be known to anyone, it is a simple computational matter to use the CA's public key to determine that the digital signature is valid. After this is done, the certificate itself can be assumed to contain a valid identity (a user, a corporation, or another entity) associated with a public key. Using a digital certificate, you then can obtain the public key for a person and use it to encrypt data to be sent to that person, who then can use his own private key to read your message.

Internet 2010

CAs can be trusted companies on the Internet, or you can act as your own CA in your company. Included with Windows 2000 Advanced Server and the family of Windows 2003 servers, for example, is Microsoft's Certificate Services, which can be used within a company that wants to manage its own digital certificates. If you have branch offices and want to use digital certificates to certify public keys used for communicating over the Internet, you can set up your own certificate servers in your enterprise. Or you can use a commercial company (such as VeriSign) and obtain certificates from a third party.

In practice, it also is possible for a hierarchy of certificate servers to be set up, with a single root server being the most trusted certificate server in your enterprise. Then, child certificate servers are created, which can be validated by the end user because the child certificate server itself has a Certificate from the root server (or another server in the hierarchy leading back to the root server) that validates its certificate. It's all a game of trust, however. If the secret key of the root server's key pair becomes compromised, it's possible to impersonate the certificate server and all security is lost. Most certificates also are issued with an expiration date, which can be used to ensure that new certificates, created using a new key pair, are in use.

For this reason, should you choose to operate your own certificate server(s) in your network, you need to take extreme security precautions to safeguard the private key. Likewise, if you use a third- party commercial certificate service, you need to read the policy of that company to determine how it verifies the identity of the end users that it issues certificates to. For example, a CA might simply verify the email address of the requestor and issue a certificate. For a software publisher, the CA might conduct some kind of background check and require further evidence before it issues certificates to the company. Before you decide to use a commercial service for issuing digital certificates, be sure you investigate the company's policies for both issuing and revoking certificates.

Pretty Good Privacy (PGP)

One of the most popular encryption programs on the Internet for a number of years now has been PGP, originally developed by Phillip Zimmerman. PGP uses public-key cryptography and has been ported to many computer platforms, including Unix, Linux, and, of course, all versions of Windows from Windows NT and Windows 95 onward.

PGP Corporation currently markets the commercial version of PGP. PGP is available in a Universal Series version for network gateways, Whole Disk Encryption for desktop and enterprise systems, command-line for servers and mainframes, and home and professional desktop versions. PGP also maintains a Global Directory of PGP keys, replacing the PGP Keyserver service. A 30-day trial of the home desktop version is available.

PGP has been established as an Internet proposed standard through the Request for Comments (RFC) process. RFC 2440, "OpenPGP Message Format," was written in 1998 and details the specification.

An international site devoted to PGP also can be used to download PGP. Visit the PGPi Project International PGP home page at www pgpi. org/ to learn more about PGP International. The downloads available from this site include support for the following platforms:

Amiga

Atari

BeOS

EPOC (Psion, and so on)

MacOS

Newton

OS/2

PalmOS

Unix

MS-DOS

Windows 3.x

Windows 95/98/NT

Windows Me

Windows 2000

Windows XP

As you can see, various operating systems are supported by the International PGP site, which is working to establish PGP as a standard for encryption on the Internet. In addition to the standard PGP package, which provides for a number of applications, such as document encryption and email, a number of other products also are available, such as PGPdisk (for encrypting disks) and PGPphone (for making secure phone calls on the Internet).

The PGPi Project also is making PGP available in various languages, and also is currently translating the documentation. PGPi is a nonprofit organization dedicated to further developing and distributing PGP technology throughout the world. In addition, for some platforms, the source code is available so that you can examine it before compiling it on your system.

Monday, March 24, 2008

Build Your Digital Command Canter Part 1

The popularity of Star Trek is based, in part, upon our fascination with advanced technology. We're excited when Captain Picardorders his crew to take The Enterprise to another galaxy with the simple command "Make it so." In the distant future, it seems, we'll be able to entertain our merest whim by pushing a button or by telling a computer what we want done. Powerful machines will do the rest.

To succeed at digital marketing, you need to build your own version of The Starship Enterprise. You need to develop a digital command center in your company to communicate on a day-by-day basis with your customers and prospects. Unlike a traditional marketing department — often far removed from direct contact with customers — a digital marketing department must be hardwired to Customers. E-mail messages, for example, must be read and replied to Within hours, if not minutes, and your Web site content may need to be updated and changed daily. In addition, your customer database should be constantly churning with new information uploaded from your salespeople, your customer service representatives, and your customers.

Internet 2010

Integration in the Digital Economy

To gather, store, process, and distribute digital information, you need to integrate your company into the digital economy. In the next three to five years, you will need the following capabilities in your company.

  • Every computer is connected over a network using highspeed cable. This network includes an internal e-mail system that allows for the sending and receiving of Internet e-mail messages.
  • Everyone involved in your company — employees, customers, and suppliers — are able to communicate by e-mail with everyone else in your company. As bandwidth becomes greater, you can upgrade your e-mail capability to include video-mail and live video-conferencing.
  • Employees and contract workers are able to work at home, or at satellite offices, as easily as if they were in the office. Note: In the digital world, you may not have an office; your entire operation may run over a central server that electronically connects your organization.
  • Your internal computer network is connected directly to the Internet over high-speed telephone or cable lines. This means every computer on your network is connected to the Internet at all times. In fact, it means your computer network is actually part of the Internet.
  • You have security measures in place which restrict access to private corporate information on your network. One solution is to set up an Internet fire wall.
  • Your marketing presentations, internal communications, and training courses exist in a multimedia format which combines text, graphics, sound, and video. You have software that allows for the easy development of multimedia content.
  • You have one or many different types of online servers running on your network. This includes one or more Web servers, a BBS network server, and online database servers. Each of these servers are available to selected people within your organization over an Intranet, or outside your organization by way of the Internet.
  • As an alternative to internal online servers, you can lease space with service bureaus. For example, you can rent space on a Web site that is halfway around the world. You can update its content as if the server was in your office. You may use a service bureau to set up and run your online BBS system. Remember, you don't need to buy expensive digital equipment in order to use it — you can rent it as well.
  • Your customers access information about your business using a variety of digital communications tools including the telephone, fax, e-mail, the World Wide Web, interactive kiosks, and CD-ROM, and perhaps also through some sort of virtual reality (VR) device. Ideally, your customers are able to purchase your products and services electronically.
  • You have an extensive database on all your customers and prospects. This database is relational in structure. All your digital communications and your digital marketing promotions are aimed at increasing the size, quality, and complexity of this database.
  • All your computer systems are compatible. In the computer industry, this is known as "Open Systems Architecture." This means all your corporate information is accessible, no matter what type of computer is used. As well, your information should be accessible through all digital devices, not just computer-related ones.
  • Your employees are fully fluent in the ways of basic digital technology. Everyone in your organization knows how to use the three major types of software programs: word processing, spreadsheet, and database. They are comfortable creating and viewing multimedia content. They understand the basic concepts of the Internet, and can find the information they need on it.

In order to succeed at digital marketing over the long term, you need to set up this type of infrastructure within your company. However, man didn't get to the moon in one day. So take it one step at a time. Here's an explanation of how to take the first steps:

Internet Blogosphere