USE OF ENCRYPTION

Encryption has long been used by militaries and governments to facilitate secret communication. It is now commonly used in protecting information within many kinds of civilian systems. For example, the Computer Security Institute reported that in 2007, 71% of companies surveyed utilized encryption for some of their data in transit, and 53% utilized encryption for some of their data in storage.Encryption can be used to protect data "at rest", such as files on computers and storage devices (e.g. USB flash drives). In recent years there have been numerous reports of confidential data such as customers' personal records being exposed through loss or theft of laptops or backup drives. Encrypting such files at rest helps protect them should physical security measures fail. Digital rights management systems, which prevent unauthorized use or reproduction of copyrighted material and protect software against reverse engineering (see also copy protection), is another somewhat different example of using encryption on data at rest. Encryption is also used to protect data in transit, for example data being transferred via networks (e.g. the Internet, e-commerce), mobile telephones, wireless microphones,wireless intercom systems, Bluetooth devices and bank automatic teller machines. There have been numerous reports of data in transit being intercepted in recent years.Encrypting data in transit also helps to secure it as it is often difficult to physically secure all access to networks. 

Message verification Encryption

 by itself, can protect the confidentiality of messages, but other techniques are still needed to protect the integrity and authenticity of a message; for example, verification of a message authentication code (MAC) or a digital signature. Standards for cryptographic software and hardware to perform encryption are widely available, but successfully using encryption to ensure security may be a challenging problem. A single error in system design or execution can allow successful attacks. Sometimes an adversary can obtain unencrypted information without directly undoing the encryption. See, e.g., traffic analysis, TEMPEST, or Trojan horse. 

To view or add a comment, sign in

More articles by Faisal Paray

  • Telephony vs The Internet

    At its bottom level—metal wires, optical fibers, microwave relays, and satellite channels—the public switched telephone…

  • The impact of cyber security… does it matter

    In the end, how does all this affect organizations? Does it matter what the ideological background is of someone who…

  • CISCO CLOUD COMPUTING

    Cloud computing is based on the premise that services can not only be provisioned, but also de-provisioned in a highly…

  • Cloud Computing: Virtual Clusters

    There are several differences and similarities between physical and virtual clusters, and different benefits conveyed…

  • Virtual private network (VPN)

    A virtual private network (VPN) extends a private network across a public network, such as the Internet. It enables…

  • Network layer or packet filters

    Network layer firewalls, also called packet filters, operate at a relatively low level of the TCP/IP protocol stack…

  • Hardware protection mechanisms

    While hardware may be a source of insecurity, such as with microchip vulnerabilities maliciously introduced during the…

  • Denial-of-service attack

    Denial of service attacks are designed to make a machine or network resource unavailable to its intended users…

  • Network Security

    SEC503: Intrusion Detection In-Depth This is the most advanced program in network intrusion detection where you will…

Explore content categories