Security Park, the leading online news site for security professionals
Home | About us | Contact us | Submit an article | Advertise | Sales leads | Newsletter | RSS Newsfeed | SEARCH




Develop an ISO 27001-compliant Information Security Management System
This useful guide clarifies the steps you have to follow to develop an ISO 27001-compliant ISMS. Each step is integral in how secure your information security system is.

Need a
reference book?
Find it on Amazon:
Security books and magazines in association with Amazon.co.uk

SecurityPark Research Library

Help | Advanced Search
What's New?
What's Popular?
Transport Layer Security Solves $100 Billion Dollar Riddle
sponsored by Fast Lane
Posted:  03 Apr 2008
Published:  03 Apr 2008
Format:  PDF
Length:  11   Page(s)
Type:  White Paper
Language:  English


ABSTRACT:
This paper allows you to gain a better understanding of what is actually occurring when you use SSL, which much more likely than not, is not really SSL at all but is, rather, Transport Layer Security (TLS). The TLS Record Protocol provides connection security with two basic properties: The connection is private. This privacy, or confidentiality, is provided using symmetric cryptography. Messages are encrypted and decrypted using the same key, with either a block or stream cipher. The keys used by the chosen cipher are generated uniquely for each connection, and are based on a secret established by the TLS Handshake Protocol. The connection is reliable. Each message exchange includes an integrity check using a keyed MAC, or, Message Authentication Code. This is a secure digest of some data protected by a secret. Forging the MAC is infeasible without knowledge of the MAC secret, which is also unique per connection and based on a secret established by the TLS Handshake Protocol.


Author

David Garneau



BROWSE RELATED RESOURCES
Cryptography | MAC | Password Authentication Protocol | Security | SSL | SSL VPN | TCP

View All Resources sponsored by Fast Lane

Library Home | Advertise with Us | Product Library
A Service of Bitpipe