Discussion 8

profileanithareddy
Week10Lecture.pptx

Fundamentals of Cryptography Week 10

1

Week 10 Agenda

Week 10 Overview

Reading

Discussion Question

Quiz

Public Key Infrastructure (PKI)

Week 11 Pre-view

2

Discussion Question 8

3

Peer Response(s):  Peer Response(s) are due by Sunday, November 5th (11:59:59pm ET)

Primary Task Response:

Primary Task Response:

Primary Response: Primary Discussion Response is due by Wednesday, November 1st (11:59:59pm Eastern Time Zone (ET))

Public Key Infrastructure

Public Key Infrastructure (PKI) is a combination of software, hardware, and policies used to secure communications over an insecure medium. PKI can also provide a system that allows validation of credentials, known as digital signatures, that are the cornerstone of the system.

Please explain the PKI process and identify the PKI structure to include the major roles.

As it relates to certificates in the real world, what is X.509 and why is it important?

What are some issues that we should be aware of when building and using PKI Infrastructure?

Discussion Question 7

4

- Read the responses from your peers and offer a constructive critique or additional information that adds substantively to the discussions.

Peer Response

- Remember, a response that simply states that their post was good or that you liked it is not considered substantive and will not earn credit.

- You should contribute to the learning via your posts and responses.

- Be sure to acknowledge any outside sources you use.

Week 10 Overview

Reading – Chapter 7 in our text

Discussion Question 7 – Public Key Infrastructure

Quiz 6

5

What is PKI?

6

Key Management

7

2

Usage Control

5

6

7

Storage

Recovery

Escrow

8

Zeroization

1

3

Creation

Change and Expiry

4

Distribution

Creation

Automated key generation

Truly random

Suitable length

Key encrypting keys

8

Key Usage Control

Management has a vested interest in what activities or content may be hidden in cryptographically protected communications or files

They may create a policy that allows management to audit or decrypt encrypted data at their discretion

9

Key Change and Expiry

In any environment, plans should be made to update keys periodically

Generating symmetric keys is easy, but delivering them is expensive since you will be delivering [N*(N-1)]/2 keys to N users

Expiry

Expiry ensures that a key is never overused

Expiry based upon:

Amount of traffic

Amount of traffic over time

Time-in-use

10

Distribution

Out of band

Public key encryption

Secret key construction

Secret key delivery

Key Distribution Centers (KDC)

Certificates

11

Storage

Trusted hardware

Smartcards

12

Recovery

13

Split knowledge

Multi-party key recovery (MPR)

Escrow

A process, mechanism, or entity that can recover a lost or destroyed cryptographic key

Key escrow systems are typically made up of three components:

A user component that handles the generation and use of cryptographic keys

An escrow component that saves the keys

A recovery component that provides the restoration services

14

Law Enforcement Issues

15

Commonly available commercial and open source encryption can hinder law enforcement in executing investigations

Many countries have laws concerning the import, export, and use of encryption (Wassenaar Arrangement)

Key Zeroization

Erasure of keys to prevent disclosure — especially when equipment is to be discarded or if stolen

16

Public Key Infrastructure (PKI)

Public Key Infrastructure binds a people/entities to their public keys

Public keys are published and certified by digital signatures

Cross-Certification (Xcert)

Certificate Revocation Lists (CRLs)

X.509 standard

17

Public Key Infrastructure (PKI)

18

Certification

Trust and Trust Models

Certification establishes trustworthiness of public keys

Certification Authority (CA)

Certificate Policy (CP)

Certificate Practice Statement (CPS)

Registration Authority (RA)

Validate Certification Path

19

Applications and Encryption Issues

Third-party CAs:

Allow business partners to trust (to some level) your public key certificates

Have a mutual trust in the CA (e.g., VeriSign)

If we choose to run our own CA, will anyone trust us?

20

21

Week 11 Overview

Residency Weekend!!!!

Nov 10 – 12

Northern Kentucky Campus

22

Questions?

23