Business Articles, Internet Resources and Tutorials - Senyum

Titles Titles & descriptions

Increase Your Golf Swing Clubhead Speed with a Golf Fitness Program!
Learn how you can increase your hit the ball farther without buying a new driver or overhauling your swing. Le...

How to Get a Lower Blood Pressure Using Medical Treatment
The treatment for lowering the blood pressure is usually recommend by physicians for patients with a blood pre...

The 99 Percent Rule
It's Friday night, you're sitting at a restaurant, and as your meal arrives, the server says, "Now, don't touc...

Articles Tutorial
Articles on advertising, sales management, business, stock market, hobbies, health, lifestyle, family relationships, online business, money, stock trading and m...


Link Exchange

Exchange links with our website.


Sponsored Links

   

Seecrets on Security: A Gentle Introduction on Cryptography Part 2

Navigation: Main page » Security

 Print this page 

Author: Stan Seecrets

Article source: http://www.hotlib.com/. Used with author's permission.

A slightly longer series of articles "Keeping Your Secrets Secret" will examine practical examples in greater detail and provides useful tips and advice. Of course, these will continue with the theme of making crypto and computer security easily understood.

One-Way Hash

Also known as a one-way function, a message digest, a fingerprint or a checksum, the algorithm creates a fixed-length output that cannot be reversed. One-way hashes provide checksums to validate files, create digital certificates and played a central part in many authentication schemes.

Let us consider this example. For ages, the Chinese have a fortune-telling method that relies on "Ba Ji" (eight characters) which uses the time, day, month and year of birth according to their calendar. There are sixty possibilities (almost equal to 6 bits) for each of the four variables. Since the Chinese use two characters for each variable, the result is always eight characters. This is an example of a nonsecure 24-bit one-way hash.

Obviously, this way of producing a one-way hash is not acceptable for security purposes because of the huge number of collisions (different inputs producing the same output).

The most commonly used hashes are SHA-1 (Secure Hash Algorithm uses 160 bits) and MD5 (Message Digest uses 128 bits). In August 2005, a team of cryptographers led by Xiaoyun Wang of Shandong University, China, presented a paper that found faster ways of finding collisions than the usual brute force method. These exploits (vulnerabilities) may make digital certificates forgery a reality.

The implications to e-commerce may be widespread not to mention the millions of websites which used MD5 to hash the users' passwords in their databases. Any webmaster can tell you that converting these sites to use SHA-256 or SHA-512 will not be a trivial task.

In a recent directive, NIST (National Institute of Standards & Technology, U.S.A.) has advised U.S. governmental agencies to use SHA-256 or SHA-512 (256 and 512 bits respectively) instead.

Biometrics

A biometric device is one that can identify unique characteristics from a finger, eye or voice. Many believe that biometrics should provide a higher level of security than other forms of authentication.

There is a news story in March 2005 of how a Malaysian owner lost his Mercedes car and index finger to car thieves armed with machetes. Obviously the keyless ignition electronics cannot detect whether the finger is still part of the original body nor whether the finger (and by extension the person) is alive or not.

Recent security breaches have heightened concern over depositories of personal information stored on many financial sites. When such breaches occurred, the incidence of identity thefts will thus rise also.

If you lose your credit card, you can always void the card and get a new one. When you lose your fingerprint (stored digitally), or other biometric features, who can replace those?

Passwords

When asked to conjure a random number or characters, most people inevitably used materials that are familiar to them like birthdays, names of family members, pets' names and so forth.

For example, most will choose dates when asked to choose a six-digit number for their ATM Personal Identification Number (PIN). Doing so will reduce the number of possibilities by nine times.

Random Numbers and Generators

Random numbers are central to crypto. To qualify as true random numbers, the output from random number generators (RNG) must pass statistical tests of randomness. Two suites considered as de facto standards are the "diehard" suite developed by Prof. George Marsaglia of State University of Florida and "Statistical Test Suite" from NIST.

Second, the RNG's output must be unpredictable even with complete knowledge of the algorithm or hardware producing the series and all the previous bits produced.

Third, the RNG's output cannot be cloned in a repeat run even with the same input.

The most common approach to producing random numbers is by using an algorithm carried out by a computer program (Yarrow, Tiny, Egads, Mersenne Twister). Such algorithms cannot produce random numbers, hence their names, pseudo-random number generators (PRNG).

Another approach is to use physical events such as entropy produced by the keyboard, mouse, interrupts, white noise from microphones or speakers and disk drive behavior as the seed (initial value).

Some may argue that true random generators are those that can detect quantum behavior in subatomic physics. This is because randomness is inherent in the behavior of subatomic particles - remember the electron cloud from your high school physics.

One-time Pad

The most effective system is often the simplest. A one-time pad (OTP) is a series of random bits that has the same length as the digital object to be encrypted. To encrypt, just use a simple computer operation, exclusive OR (XOR). To decrypt, simply XOR the encrypted result with the same random bits.

The downside of using OTP is that once used, it must be discarded. Second, the OTP and the digital object must have the same number of bits. Lastly, the obvious problem of synchronizing the OTP between the receiver and sender.

[Author's note: The concluding Part 3 will focus on keys management and public key cryptography.]

"In God we trust, others use crypto."

The author, Stan Seecrets, is a veteran software developer with 25+ years experience. © Copyright 2005, Stan Seecrets. All rights reserved. For more of his articles and website promotion, visit http://www.seecrets.biz or http://www.rushprnews.com




Encouraging Behavior That Gets Results
You're the boss, and you have every reason to feel good about your organization. You've built a great team. You've put strong players in every spot. You have cl...

Jesus is Lord: Lets Stop Usurping His Roles
"You are not your own!" says the Apostle Paul. This principle of submission applies to how you spend your time, how your allocate your finances, and how you wil...

Transfer The Digital Camera Images To Your Computer
There are a few very important tasks associated with using the digital camera. The most important is of course capturing a beautiful photograph. The next most i...

Your Online Newsroom: How to Give Reporters a Tip
Most websites are good about posting their latest news and press releases. Reporters come to the site, see what's already been announced, get what they need and...

Debt Elimination Is The Key to Financial Freedom
You can even start budgeting and paying off your debt while you're a student. Just remember, the sooner you start paying your debts, the sooner you'll be comple...

Secured Loans – Making the Most of Your Home as Collateral
Though secured loans require one to keep his/ her home as collateral, this must not deter them from enjoying its benefits. A secured loan is cheaper than the ot...

The Mystery of Enlightenment
What can you do to attain enlightenment?

Fast-Forward to the Year 2010
Let's do a little bit of "Back to the Future" therapy. Let's pretend for a moment that we are now living in the year 2010. You WILL be five years older. You WIL...

Look On Aisle 5
The conspiracy to make us fat extends even to the layout of supermarkets which lead us to focus on the fast, less healthy food rather than the produce we all kn...

Google Traffic Report Card-Does Your Website Pass? Part 1
Check your website against Google's ranking criteria. Part 1 of 7.

Losing Weight - Stop Focusing on the Carrots!
How to properly lose weight without excesses.

Who Said That? Making Dialogue Crystal Clear
Are you sure that your readers know exactly who said what in your scenes of dialogue? Use these examples of what does and doesn't work to make sure your charact...

Learn The Truth About Identity Theft
Identity theft is the fastest growing crime in America, according to a recently released FTC study. Did you know that the term "identity theft" did not exist un...

The One Critical Piece Of Free Software Thats Been Overlooked
The Quickest Way I Know To Secure Your PC-Safety In 7 Easy Steps And Only Using Free Software While Not Missing The One Critical Piece Of Free Software That's B...

New Age Piano and Improvisation
Describes a new attitudinal approach to improvisation.

Esoteric & Occult Secrets
The following article draws on my experiences with magical techniques, principles, and concepts, synthesising traditional magical concepts and modern Psychosynt...

Homes For Sell By Owner – FSBOs and Buyer Brokers
You're selling your home as a FSBO (for sale by owner) and you get annoyed when real estate brokers call you, right? However, when a "buyer broker" calls, you m...

How to Create Your Own Mail Order Products
This article describes how to create your own mail order products.

Cellulite Therapy
What can you do to get great results in your cellulite routine? This article discusses home therapies for getting rid of cellulite that will give you results v...

Mobile Detailing Expansion Considerations
Expanding your business requires you to take a good hard look at your business (checking under the hood). You need to ask yourself. What am I making money at ...

Tranformer
Importance Of Transformer In Field Of Electricity

The Top Seven Marketing Mistakes
In my view, nearly all government statistics about reasons for business failures are nonsense. Undercapitalization, inexperience, or poor management are usually...

Can We Sleep For Three Hours and Still Function Normally?
The polyphasic sleep concept is based upon the fact that we have a 4 hour ultradian rhythm operating alongside our normal 24 hour cycle. This ultradian rhythm m...

The Five Most Commonly Encountered, Off-putting E-commerce Errors
While getting less public handwringing than during holiday season, the "abandoned shopping cart problem" continues to wreak havoc on online sales. Recently I j...

 
Newsletter


Article Categories

Home
Web & Online Business
Affiliate Revenue
Auctions
Blogging RSS
E-Books
E-Commerce
Email Marketing
Ezine Publishing
Internet Marketing
PPC Advertising
SEO
Security
Site Promotion
Spam Blocker
Traffic Building
Web Design
Web Development
Money & Finance
Credit
Currency Trading
Debt Consolidation
Debt Relief
Insurance
Investing
Loans
Mortgage Refinance
Personal Finance
Real Estate
Stocks Mutual Funds
Taxes
Wealth Building
Business
Advertising
Branding
Business Tips
Careers Employment
Copywriting
Customer Service
Entrepreneurialism
Management
Marketing
Networking
Network Marketing
Presentation
Public Relations
Resumes & Cover Letters
Sales
Sales Management
Sales Training
Small Business
Strategic Planning
Team Building
Health & Medicine
Acne
Alternative Medicine
Beauty
Depression
Diabetes
Exercise
Fitness Equipment
Hair Loss
Medicine
Meditation
Men's Issues
Muscle Building
Nutrition
Nutrition Supplements
Weight Loss
Women's Issues
Yoga
Family & Relationships
Babies Toddler
Dating
Holidays
Home Improvement
Interior Decorating
Landscaping & Gardening
Marriage & Wedding
Parenting
Pregnancy
Relationships
Sexuality
Hobbies & Lifestyle
Casinos & Gambling
Cooking Tips
Crafts & Hobbies
Fashion & Style
Golf
Humanities
Mobile Cell Phone
Music
Outdoors
Pets
Photography
Poetry
Politics
Recipes
Science
Vacation Rentals
Writing
Writing Articles
Self-Improvement
Attraction
Coaching
Creativity
Goal Setting
Grief & Loss
Happiness
Innovation
Inspirational
Leadership
Motivation
Organizing
Positive Attitude
Religion
Spirituality
Stress Management
Success
Time Management


www.senyum.net - This website contains articles on wide range of topics. Articles on advertising, sales management, business, stock market, hobbies, health, lifestyle,
family relationships, online business, money, stock trading and many more are available.
www.senyum.net covers USA, UK, Canada, Australia, China and Germany : - complete articles online business - articles tutorial.
Copyright © 2006 SmileMedia Co. All rights reserved.