Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [CISSP-D] Symmetric Key and authentication. |
|---|---|
| Date: | Mon, 9 May 2005 10:03:53 -0400 |
VJ, My understanding is that symmetric key encryption does not provide MECHANISMS for authentication and non-repudiation. The system is able to provide authentication between users and a level of confidentiality is provided as a result, but it seems to be implied. Witness the following statement: "crucial aspects of confidentiality are user identification, authentication and authorization" (from the Official ISC2 Guide). So it seems, that if authentication is involved, so is confidentiality, and vice-versa. And since two people are sharing a session that is undeniable when the keys are exchanged, it is non-repudiated by default.... Still, it's confusing, and I think it's an interesting discussion. Experience CISSP's, please weigh in? Thanks, Rand On 5/5/05, Vijay Kumar <vijaychhipa@yahoo.com> wrote:
One of the books I read gave example of how symmetric encryption can be used for authenticating to another entity with whom you have a shared secret. Yet, the Shon Harris books says that symmetric encryption only provided Confidentiality and integrity but not auth and non repudiation. Who is right? Thanks ------------------------------ *Yahoo! Groups Links* - To visit your group on the web, go to: http://groups.yahoo.com/group/CISSP-Discuss/ - To unsubscribe from this group, send an email to: CISSP-Discuss-unsubscribe@yahoogroups.com<CISSP-Discuss-unsubscribe@yahoogroups.com?subject=Unsubscribe> - Your use of Yahoo! Groups is subject to the Yahoo! Terms of Service <http://docs.yahoo.com/info/terms/>.
-- ---------------------- Rand ~~~~~~~~~~~ Four wheels move the body. Two wheels move the soul.
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: [CISSP-D] Symmetric Key and authentication., Roshan Mani |
|---|---|
| Next by Date: | Re: [CISSP-D] Symmetric Key and authentication., Manish Bajaj |
| Previous by Thread: | RE: [CISSP-D] Symmetric Key and authentication., Roshan Mani |
| Next by Thread: | Re: [CISSP-D] Symmetric Key and authentication., Manish Bajaj |
| Indexes: | [Date] [Thread] [Top] [All Lists] |