Search DominoPower's 11,437 Lotus-related article archive 
Home
EasyPrint
News details Click here for the RSS feed's XML code. This is not a browser URL.
Articles-only Click here for the RSS feed's XML code. This is not a browser URL.
Twitter Feed Click here for the Twitter feed.
ENCRYPTION POLICY
Email and the encryption conundrum
By Victor Woodward

The US has had its share of debates surrounding encryption. Should cryptographic methods include a "spare key" that allows law enforcement officials to read the scrambled data? Should the best, most powerful encryption tools be sold overseas? What is the line between personal privacy and corporate or national security?

The increased use of email to transport sensitive information, the rapid growth of e-commerce, and the rise of computer-based crime are all factors driving the strong market demand for robust cryptographic solutions. The problem (outside of the troubling issue of government meddling) lies in finding a solution that fits the needs of your organization. There are policy issues, standards issues and usage issues. This article takes a brief look at the issues that are relevant to Notes and Domino administrators. Specifically, it addresses the issue of how encryption fits into a comprehensive content security solution.

An encryption primer
Encryption involves the conversion of data into a secret code for transmission over a public network. The original text, or "plaintext", is converted into a coded equivalent called "ciphertext" via an encryption algorithm. The ciphertext is decoded (decrypted) at the receiving end and turned back into plaintext.

The encryption algorithm uses a key, which is a binary number that is typically from 40 to 128 bits in length. The data is "locked" for sending by combining the bits in the key mathematically with the data bits. At the receiving end, the key is used to "unlock" the code, restoring it to its original binary form.

Secret versus public key
There are two cryptographic methods. The traditional method uses a secret key, such as the DES standard. Both sender and receiver use the same key to encrypt and decrypt. This is the fastest method, but transmitting the secret key to the recipient in the first place is not as secure.

The second method is public-key cryptography, such as RSA, which uses both a private and a public key. Each recipient has a private key that is kept secret and a public key that is published for everyone. The sender looks up the recipient's public key and uses it to encrypt the message. The recipient uses the private key to decrypt the message. Owners never have a need to transmit their private keys to anyone in order to have their messages decrypted, thus the private keys are not in transit and are not vulnerable.

Sometimes, both DES (Data Encryption Standard) and RSA (a form of encryption named after its authors: by Ron Rivest, Adi Shamir, and Leonard Adleman) are used together. DES provides the fastest decryption, and RSA provides a convenient method for transmitting the secret key. Both the DES-encrypted text message and the secret key needed to decrypt it are sent via the RSA method. This is called a digital envelope.


1  ·  2  ·  3  ·  Next »
Other articles you might like
Home > Strategies > Legal Issues (12 articles)
   Analysis: Spying Chinese temptress steals senior Brit's BlackBerry
   U.S. government agencies' cyber-security and record-keeping worse than previously thought
   When the email flood inundates the Domino Server
Home > Strategies > Email Management (60 articles)
   Using the Notes Client with Gmail
   Using the Notes client with Hotmail (or not)
   Is English-only a viable mail management strategy?
Get Weekly Email Updates
Subscribe to our regular weekly email newsletter. It's packed with tips, reviews, deep analysis, and the latest news.
 
Recent DominoPower Articles
Application development, William Shatner, and the origin of the universe
Learn Domino Designer 8.5 for free
The (near) future of Sametime, Quickr, Connections, and Symphony
Inside the IBM Innovations lab
Lotusphere 2010: Hot fixes and cool news for Notes, Domino, and LotusLive
Lotusphere 2010: mobility and collaboration
2010: A Lotusphere of change
Latest Lotus Headlines
SNTT : XPages onclick Ghosts in the machine
Ports used by Lotus Sametime 8.5 servers
Exploring a Domino Date Bug
Adding Quick Highlighter support to IBM Lotus Notes Domino Wiki, Weblog, or Webpage
Remember Young Admins...there are 2 files
WebSphere Portal 6.1.0.2 and Lotus Domino 8.5
The CKEditor - with Domino
>> Read all the news
More from the ZATZ journals
Computing Unplugged: The iPad defenders have spoken
David Gewirtz Online: CNN commentary and analysis
OutlookPower: More about disappearing text
-- Advertisement --

Sophisticated Meets Simple For Document Management
Share. Control. Manage.
Documents, emails, and content in the context of how work is done. Native to Lotus Domino. The User Experience unseen for Lotus Domino. Do more with less. Really.

See the possibilities Docova unleashes for Lotus Domino.
-- Advertisement --

Mark your calendar for in-depth Lotus training, May 12-14, Boston
Join experts and peers May 12-14 in Boston for educational and networking events that deliver real-world Lotus training so you can increase productivity and efficiency in your company, advance your skills, and squeeze the most from your current environment. One registration gets you into THE VIEW's Admin2010 and Lotus Developer2010.

Register by April 10 to save $200.
ZATZ Home  ·  News  ·  Back Issues  ·  Credits/Trademarks ·  Link To Us
Copyright © 1998-2010, ZATZ Publishing. All rights reserved worldwide.
Editor's Login