magazine resources subscribe about advertising

New Architect Daily
Commentary and updates on current events and technologies

CMP Media E-Book

Download your copy today.

Research
Search for reports and white papers from industry vendors and analysts.

This Week at NewArchitect.com Subscribe now to our free email newsletter and get notified when the site is updated with new articles







Day of Defeat Online Gaming

 New Architect > Archives > 1997 > 11 > Features  

Internet Security, The Next Generation

When Software Encryption is not Enough

By Jonny Goldman

Most Webmasters secure their site's transactions by configuring and running a secure server using Verisign's digital certificates and the secure sockets layer (SSL). This scheme authenticates the server to the user and encrypts the data sent following the initial negotiation; however, it does not provide an end-to-end framework that automatically authenticates both client and server. Thus, user names and passwords are still the norm, so users must maintain long lists of passwords for various sites, lest they be compromised and used elsewhere, and Webmasters must maintain and protect huge, unwieldy password files and devise schemes for supporting lost or forgotten passwords. This may be the reason that electronic commerce has taken off so slowly. Happily, the tide may be turning -- smart-card technology is rapidly becoming a viable option for securing systems.

Is It Safe?

Secure systems have four basic requirements: authentication, confidentiality, integrity, and nonrepudiation. Protocols like SSL and S/MIME support the first three, but electronic-commerce systems require all four. Traditionally, the Internet has used usernames and passwords to identify, and hence authenticate users, but what if someone steals or guesses your password? A relatively simple solution is digital identities, or "certificates," used mostly for Web servers: A certifying authority provides you with the X 509 certificate you need to run SSL on your server.




  Day of Defeat Online Gaming

home | daily | current issue | archives | features | critical decisions | case studies | expert opinion | reviews | access | industry events | newsletter | research | careers | info centers | advertising | subscribe | subscriber service | editorial calendar | press | contacts


Copyright © 2006 CMP Media, LLC Read our privacy policy, your California privacy rights, terms of service.
SDMG Web sites: BYTE.com, C/C++ Users Journal, Developer Pipeline, Dr. Dobb's Journal, DotNetJunkies, MSDN Magazine, Sys Admin,
SD Expo, SD Magazine, SqlJunkies, The Perl Journal, Unixreview, Windows Developer Network, New Architect

web2