Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [CISSP-D] Do Symmetric Key Algorithms provide authenticity? |
|---|---|
| Date: | Thu, 13 Jul 2006 20:24:44 -0700 |
On 13 Jul 2006 at 12:13, bennettwang wrote:
Of course, the symmetric key algorithms can provide authentication. only the user who have the key can open and use the data can provide a authtication function. but it is difficult for the symmertric key algorithms to deploy the key.
The problem with calling this "authentication" is that "the user" is NOT the ONLY possessor of the key. The key is shared amongst AT LEAST two entities AND some kind of key distribution mechanism. (Some particularly poorly implemented symmetric systems don't even bother to create different keys for each session or each user, but rely on a single key to secure the entire *system*. I know of no asymmetric systems that do this, although it is certainly possible to build one.) An asymmetric algorithm is usually implemented to guarantee that each private key really IS private, known only to a single unique entity. Once you start using symmetric keys (which MUST be shared to at least a minimum extent), verifying that they are shared only with appropriate entities who use them only in the prescribed fashion is essentially impossible. David Gillett ------------------------ Yahoo! Groups Sponsor --------------------~--> Yahoo! Groups gets a make over. See the new email design. http://us.click.yahoo.com/XISQkA/lOaOAA/yQLSAA/kgFolB/TM --------------------------------------------------------------------~-> Yahoo! Groups Links <*> To visit your group on the web, go to: http://groups.yahoo.com/group/CISSP-Discuss/ <*> To unsubscribe from this group, send an email to: CISSP-Discuss-unsubscribe@yahoogroups.com <*> Your use of Yahoo! Groups is subject to: http://docs.yahoo.com/info/terms/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [CISSP-D] REVIEW: "The TCP/IP Guide", Charles M. Kozierok, Rob, grandpa of Ryan, Trevor, Devon & Hannah |
|---|---|
| Next by Date: | [CISSP-D] Disaster Recovery and Pandemic Planning, Dave Sims |
| Previous by Thread: | Re: [CISSP-D] Do Symmetric Key Algorithms provide authenticity?, bennettwang |
| Next by Thread: | [CISSP-D] OWASP Mumbai Meeting [31st July 15:00 hrs], Dharmesh |
| Indexes: | [Date] [Thread] [Top] [All Lists] |