Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security CISSP-Discussion
[Top] [All Lists]

RE: [CISSP-D] Symmetric Key and authentication.

Subject: RE: [CISSP-D] Symmetric Key and authentication.
Date: Mon, 9 May 2005 11:47:53 +0530
Hi,

IMHO and understanding, any form of encryption can be used for
Authentication (i.e. sender identification), provided you are able to use an
enc/dec method that's; 
1. not easy to duplicate by a malicious third-party
2. maintains the value of the message content for the relevant time
3. easy to communicate, securely, to the receiving party

All the above parameters (and others that I haven't mentioned) are easier
and much simpler to achieve practically with Asymmetric encryption rather
than Symmetric encryption and hence the definition by Shon Harris!

Regards,
Roshan Mani

-----Original Message-----
From: CISSP-Discuss@yahoogroups.com [mailto:CISSP-Discuss@yahoogroups.com]
On Behalf Of Vijay Kumar
Sent: 05 May 2005 10:11
To: CISSP-Discuss@yahoogroups.com
Subject: [CISSP-D] Symmetric Key and authentication.

One of the books I read gave example of how symmetric encryption can be used
for authenticating to another entity with whom you have a shared secret. 
 
Yet, the Shon Harris books says that symmetric encryption only provided
Confidentiality and integrity but not auth and non repudiation.
 
Who is right?
 
Thanks





 
Yahoo! Groups Links



 




 
Yahoo! Groups Links

<*> To visit your group on the web, go to:
    http://groups.yahoo.com/group/CISSP-Discuss/

<*> To unsubscribe from this group, send an email to:
    CISSP-Discuss-unsubscribe@yahoogroups.com

<*> Your use of Yahoo! Groups is subject to:
    http://docs.yahoo.com/info/terms/
 


<Prev in Thread] Current Thread [Next in Thread>