UNIT 4: DATA SECURITY
I. FOUNDATIONAL CRYPTOGRAPHIC PRINCIPLES
Symmetric vs. Asymmetric Encryption
| Feature | Symmetric Encryption | Asymmetric Encryption |
|---|---|---|
| Key Usage | Same key for encryption & decryption | Public key (encrypt) & Private key (decrypt) |
| Speed | Fast (hardware efficient) | Slow (computationally intensive) |
| Key Management | Challenge: Secure key distribution | Simpler: Public keys can be shared openly |
| Use Cases | Bulk data encryption (AES) | Key exchange (Diffie-Hellman), digital signatures (RSA) |
| Examples | AES, DES, 3DES, RC4, Caesar Cipher | RSA, ECC, ElGamal |
[!TIP] Exam often asks for comparative analysis. Focus on key distribution problem for symmetric and computational cost for asymmetric.
Digital Signatures
-
Mechanism: Uses sender's private key to sign (encrypt hash of message). Receiver uses sender's public key to verify (decrypt hash and compare).
-
Provides:
-
Authentication: Verifies sender identity.
-
Integrity: Detects any alteration of the signed message.
-
Non-Repudiation: Sender cannot deny sending the message.
-
-
Legal Admissibility: Treated as electronic signature under IT Act (India) and similar laws globally.
Secure Message Authentication
-
Concept: Ensures message integrity and verifies the source (authenticity). Different from encryption (confidentiality).
-
Implementation:
-
Sender computes cryptographic hash (digest) of the message.
-
Sender encrypts the hash with their private key (digital signature) OR shares a symmetric secret key (MAC).
-
Sender transmits:
[Message] + [Authentication Tag]. -
Receiver recomputes hash/MAC and verifies the tag.
-
-
Example (Hash-based): Send
M || H(M)whereHis SHA-256. Receiver checks ifH(M_received) == received_hash.
II. HASH FUNCTIONS & MESSAGE AUTHENTICATION CODES (MACs)
Cryptographic Hash Functions
-
Properties:
-
Pre-image resistance: Given
h, hard to findmsuch thatH(m)=h. -
Second pre-image resistance: Given
m1, hard to findm2 ≠ m1withH(m1)=H(m2). -
Collision resistance: Hard to find any pair
(m1, m2)withH(m1)=H(m2). -
Deterministic: Same input → same output.
-
Fixed output size (e.g., 512 bits for SHA-512).
-
-
Algorithms: SHA-512 (secure, 512-bit output), SHA-1 (deprecated, 160-bit), MD5 (broken, 128-bit).
-
SHA-512 Steps:
-
Pre-processing: Append
'1'bit, pad with'0's, append 128-bit message length. -
Parsing: Break padded message into 1024-bit blocks.
-
Compression: For each block, update 512-bit state via 80 rounds using constants and message schedule.
-
-
Birthday Attack: Exploits collision resistance weakness. Complexity ≈ $$\displaystyle 2^{n/2} $$ for
n-bit hash. Makes finding collisions feasible for smalln(e.g., MD5).
Message Authentication Codes (MACs)
-
Definition:
MAC = C_K(M), whereCis a MAC algorithm,Kis a shared secret key,Mis message. Provides integrity + authentication. -
HMAC Construction (RFC 2104):
HMAC_K(M) = H( (K' ⊕ opad) || H( (K' ⊕ ipad) || M ) )Where
K'is key padded to block size,ipad=0x36,opad=0x5C,||is concatenation.- Security: Based on underlying hash's strength.
-
Comparison with Digital Signatures:
| MAC | Digital Signature | |-----|-------------------| | Uses symmetric key | Uses asymmetric keys | | Provides authentication & integrity | Provides authentication, integrity, non-repudiation | | Faster | Slower |
Parameter Pattern Matching
-
Definition: Monitoring network/system parameters (e.g., packet size, port numbers, header fields) against known malicious patterns (signatures).
-
Application: Used in NIDS (Network IDS) and firewalls to detect anomalies or known attack signatures (e.g., specific TCP flag combinations, unusual payload lengths).
III. SYMMETRIC ENCRYPTION ALGORITHMS & MODES
AES (Advanced Encryption Standard)
-
Structure (for 128-bit block, 10 rounds):
-
SubBytes: Non-linear substitution using S-box.
-
ShiftRows: Cyclic shift of rows in state matrix.
-
MixColumns: Mixing columns via matrix multiplication (diffusion).
-
AddRoundKey: XOR state with round key.
-
-
Process:
Initial AddRoundKey→[Round(SubBytes, ShiftRows, MixColumns, AddRoundKey)]_{9 times}→Final Round(SubBytes, ShiftRows, AddRoundKey). -
Decryption: Inverse operations in reverse order (InvMixColumns is expensive; often use equivalent inverse cipher).
Cipher Block Modes of Operation
| Mode | How it Works | Merits | Demerits | Suitable Application |
|---|---|---|---|---|
| ECB | Encrypt each block independently | Simple, parallelizable | Identical plaintext blocks → identical ciphertext blocks (pattern leakage) | Encrypting single values (e.g., keys) |
| CBC | C_i = E_K(P_i ⊕ C_{i-1}), C_0 = IV |
Hides patterns, widely used | Sequential (no parallel encryption), IV must be unpredictable | General-purpose block encryption (TLS, IPsec) |
| CFB | C_i = P_i ⊕ E_K(C_{i-1}) |
Turns block cipher into stream cipher; no padding needed | Error propagation (1 bit error corrupts next b bits) |
Streaming data (e.g., network links) |
| OFB | O_i = E_K(O_{i-1}), C_i = P_i ⊕ O_i |
Synchronous stream cipher; no error propagation | If keystream repeats → catastrophic break | Stream encryption where error correction is used |
| CTR | `C_i = P_i ⊕ E_K(Nonce | Counter)` | Parallelizable, random access, no padding |
[!TIP] ECB is insecure for multi-block messages. Always use CBC, CTR, or GCM (not in syllabus) for new designs.
RC4 Stream Cipher
-
Key Scheduling Algorithm (KSA):
-
Initialize
S[0..255] = [0,1,...,255]. -
j = 0. -
For
i=0 to 255:j = (j + S[i] + K[i mod keylen]) mod 256; swapS[i]andS[j].
-
-
Pseudo-Random Generation Algorithm (PRGA):
-
i = j = 0. -
i = (i + 1) mod 256. -
j = (j + S[i]) mod 256. -
Swap
S[i]andS[j]. -
Output
K_byte = S[(S[i] + S[j]) mod 256].
-
-
Example (5-bit key
K = [1,2,3,4,5]):-
KSA initializes
S, then scrambles using key bytes. -
PRGA first 3 iterations generate keystream bytes
Z1, Z2, Z3.
-
-
Security Weaknesses:
-
Biased outputs: First few bytes leak key info.
-
Key recovery attacks: Fluhrer, Mantin, Shamir (FMS) attack.
-
Never use RC4 in modern systems (deprecated in TLS, WPA2).
-
Caesar Cipher (Classical)
-
Mechanism:
C = (P + k) mod 26,P = (C - k) mod 26, wherekis shift (0-25). -
Decryption Example (
k=17, ciphertextZICVTWQNGRZGVTWAVZHCQYGLMGJ):-
Map letters to numbers: A=0, B=1, ..., Z=25.
-
Z(25) → (25 - 17) mod 26 = 8 → I -
I(8) → (8 - 17) mod 26 = 17 → R -
Continue for all letters.
Result:
**RUBICSCRYPTOGRAPHYISFUNBUTDONOTUSEIT**(spaces added for clarity: "RUBICS CRYPTOGRAPHY IS FUN BUT DO NOT USE IT"). -
IV. ASYMMETRIC ENCRYPTION ALGORITHMS
RSA Algorithm
-
Mathematical Foundation: Based on Euler's Theorem:
m^φ(n) ≡ 1 mod nforgcd(m,n)=1, whereφ(n)=(p-1)(q-1). -
Key Generation:
-
Choose large primes
p,q. Computen = p*q,φ(n) = (p-1)(q-1). -
Choose
esuch that1 < e < φ(n)andgcd(e, φ(n)) = 1(public exponent). -
Compute
d = e^{-1} mod φ(n)(private exponent). -
Public key:
(e, n), Private key:(d, n).
-
-
Encryption:
c = m^e mod n. -
Decryption:
m = c^d mod n. -
Worked Example (
p=3, q=11):-
n = 33,φ(n) = 2*10 = 20. -
Choose
e=7(gcd(7,20)=1). -
d = 7^{-1} mod 20 = 3(since7*3=21 ≡ 1 mod 20). -
Encrypt
m=2:c = 2^7 mod 33 = 128 mod 33 = 29. -
Decrypt:
m = 29^3 mod 33 = 24389 mod 33 = 2.
-
-
Security: Based on integer factorization problem (hard to factor
nintop,q). Must use largen(≥2048 bits).
V. AUTHENTICATION MECHANISMS
Biometric Authentication
-
Types: Fingerprint, Iris, Facial recognition, Voice, Vein patterns.
-
Process:
-
Enrollment: Capture raw biometric, extract feature vector (template), store in database.
-
Authentication: Capture new sample, extract features, match against stored template using threshold.
-
-
Metrics:
-
FAR (False Acceptance Rate): Unauthorized user accepted.
-
FRR (False Rejection Rate): Authorized user rejected.
-
EER (Equal Error Rate): Point where FAR=FRR (lower is better).
-
-
Advantages: Hard to steal/lose, user-friendly.
-
Limitations: Spoofing (fake fingerprint), non-revocable (cannot change biometric), template security, intra-class variation (same user's biometric changes).
Smart Cards
-
Technology: Chip-based card storing cryptographic keys or performing computations.
-
Operation: Requires card reader. Can be contact (chip inserted) or contactless (RFID/NFC).
-
Comparison with Biometrics:
| Smart Card | Biometrics | |------------|------------| | Something you have | Something you are | | Can be lost/stolen | Cannot be lost (but can be spoofed) | | Revocable (cancel card) | Non-revocable | | PIN often used as second factor | Often used as primary factor |
Multi-Factor Authentication (MFA)
-
Concept: Combine ≥2 factors from:
-
Knowledge (password, PIN)
-
Possession (smart card, OTP token)
-
Inherence (biometric)
-
-
Goal: Increase security beyond single-factor (e.g., password-only).
VI. SECURE EMAIL: PRETTY GOOD PRIVACY (PGP)
PGP Protocol Working (Hybrid Approach)
-
Compression: Optional step (ZIP) before encryption to reduce size & remove patterns.
-
Session Key Generation: PGP generates random symmetric session key (e.g., AES key).
-
Encryption: Message is encrypted with session key using symmetric cipher (e.g., CAST-128, AES).
-
Session Key Encryption: Session key is encrypted with recipient's public key (RSA/ElGamal).
-
Digital Signature (optional): Sender signs the message digest (SHA-256) with sender's private key.
-
Transmission: Send
[Encrypted Session Key] || [Encrypted Message] || [Signature].
PGP Message Format
Services Provided:
-
Confidentiality: Via symmetric encryption of message.
-
Authentication: Via digital signature of sender.
-
Integrity: Via hash in signature.
-
Non-Repudiation: Via sender's private key signature.
VII. WEB & TRANSPORT LAYER SECURITY: SSL/TLS
SSL/TLS Record Protocol Services
-
Confidentiality: Using symmetric encryption (after handshake).
-
Integrity: Using MAC (HMAC) or AEAD (in TLS 1.2+).
-
Authentication: Optional, using digital certificates (X.509) during handshake.
SSL Handshake Protocol (Detailed Steps)
-
Client Hello:
- Client sends
ClientHellowith: TLS version, randomR_C, list of supported cipher suites, compression methods.
- Client sends
-
Server Hello:
-
Server responds
ServerHellowith: chosen TLS version, randomR_S, chosen cipher suite, compression method. -
Server sends its X.509 certificate (contains server's public key & identity).
-
Server sends
ServerHelloDone.
-
-
Client Key Exchange:
-
Client verifies server certificate.
-
Client generates premaster secret
PMS. -
Client encrypts
PMSwith server's public key (from certificate) →EncryptedPMS. -
Client sends
ClientKeyExchange(containsEncryptedPMS). -
Client computes master secret
MS = PRF(PMS, "master secret", R_C || R_S). -
Client sends
ChangeCipherSpec(switch to negotiated cipher suite). -
Client sends
Finished(encrypted hash of all handshake messages so far).
-
-
Server Key Exchange (if needed, e.g., DHE):
-
Server computes
MS = PRF(PMS, "master secret", R_C || R_S). -
Server sends
ChangeCipherSpec. -
Server sends
Finished.
-
SSL Connection vs. SSL Session
| SSL Session | SSL Connection |
|---|---|
| Established during handshake | Short-lived data transfer association |
Stores: MS, cipher suite, compression, peer certs |
Uses session parameters to derive connection keys |
| Can be resumed (session IDs/tickets) | Each connection has unique keys |
| Reduces cost of repeated handshakes | Provides forward secrecy per connection (if using DHE/ECDHE) |
[!TIP] Session resumption avoids full public-key operations, improving performance for repeated connections to same server.
VIII. NETWORK LAYER SECURITY: IPSEC
IPSec Protocols
| AH (Authentication Header) | ESP (Encapsulating Security Payload) |
|---|---|
| Provides: Integrity, Authentication, Anti-replay (no confidentiality) | Provides: Confidentiality, Integrity, Authentication, Anti-replay |
| Transport Mode: AH header after IP header, protects payload (TCP/UDP) but not new IP header. | Transport Mode: ESP header/trailer after IP header, protects payload (TCP/UDP) but not new IP header. |
| Tunnel Mode: Entire original IP packet (header+payload) is encapsulated inside new IP packet with AH. | Tunnel Mode: Entire original IP packet is encrypted & encapsulated inside new IP packet with ESP. |
| Does not protect selective fields of outer IP header (routing info mutable). | Can encrypt only payload (transport) or entire inner packet (tunnel). |
Security Associations (SA)
-
Definition: A unidirectional logical connection providing security services. Identified by SPI (Security Parameter Index).
-
Parameters (stored in SAD - Security Association Database):
-
SPI (32-bit)
-
IP destination address
-
Security protocol (AH/ESP)
-
Encryption/authentication algorithms & keys
-
Lifetime
-
-
Role: For inbound packet, SPI + destination IP → lookup SA → determine how to process (decrypt/verify).
IX. VIRTUAL PRIVATE NETWORKS (VPNs)
Definition & Core Concept
-
VPN: Extends a private network across a public network (Internet) using tunneling and cryptography.
-
Tunneling: Encapsulating original packet inside a new packet with different header.
Types of VPNs
| Classification | Types | Description |
|---|---|---|
| By Access | Remote Access VPN | Individual users connect to corporate network from remote locations (e.g., employee from home). |
| Site-to-Site VPN | Connects entire networks (e.g., branch office to HQ). | |
| By Protocol | PPTP (Point-to-Point Tunneling Protocol) | Old, weak encryption (MPPE), vulnerable. |
| L2TP (Layer 2 Tunneling Protocol) | Often paired with IPsec for encryption (L2TP/IPsec). | |
| IPsec VPN | Operates at Network Layer (IP). Uses AH/ESP. | |
| SSL/TLS VPN | Operates at Application Layer (HTTPS). Uses browser, no client install often. |
VPN vs. Trusted Operating Systems
| Aspect | VPN | Trusted OS |
|---|---|---|
| Security Level | Network-level (secures traffic between endpoints) | OS-level (enforces access control within a single system) |
| Scope | Secures communication channel | Secures resources on a single host |
| Architecture | Tunneling & cryptography over public network | Mandatory Access Control (MAC) via security kernel/reference monitor |
| Use Case | Connect remote users/networks securely | Protect high-security single system (e.g., military, government) |
| Example | IPSec tunnel between offices | SELinux, Trusted Solaris |
X. FIREWALLS
Classification of Firewalls
| Type | OSI Layer | How it Works | Granularity | Performance Impact |
|---|---|---|---|---|
| Packet Filtering | Network (Layer 3) / Transport (Layer 4) | Rules on source/dest IP, port, protocol, flags | Low (per-packet) | Very Low |
| Stateful Inspection | Network/Transport | Tracks connection state (e.g., SYN, ESTABLISHED) | Medium (per-connection) | Low-Medium |
| Circuit-Level Gateway | Session (Layer 5) | Validates TCP/UDP sessions; hides internal IPs | Medium (session) | Low |
| Application-Level Gateway (Proxy) | Application (Layer 7) | Intercepts & inspects application data (e.g., HTTP, FTP); acts as intermediary | High (per-command) | High |
| Next-Gen Firewall (NGFW) | Multiple (L3-7) | Combines stateful inspection + deep packet inspection (DPI), intrusion prevention, app awareness | Very High | High |
Merits and Demerits of Firewalls
-
Merits:
-
Traffic control based on security policy.
-
Logging & monitoring of traffic.
-
Hides internal network structure (NAT).
-
First line of defense against external threats.
-
-
Demerits:
-
Cannot stop internal attacks (insider threats).
-
Cannot inspect encrypted traffic without decryption (SSL/TLS inspection needed).
-
Cannot prevent attacks allowed by policy (e.g., HTTP on port 80).
-
Bypassed by social engineering (phishing).
-
Single point of failure if not redundant.
-
Proxy Firewalls vs. Personal Firewalls
| Proxy Firewall | Personal Firewall |
|---|---|
| Centralized, protects entire network. | Installed on individual host (laptop/desktop). |
| Operates at Application Layer. | Typically packet filter/stateful (L3-4). |
| Requires application-specific proxy (HTTP, FTP). | Controls inbound/outbound traffic for that host. |
| High overhead, but deep inspection. | Low overhead, but limited to host. |
| Example: Web proxy filtering HTTP. | Example: Windows Defender Firewall. |
XI. INTRUSION DETECTION SYSTEMS (IDS)
Host-based IDS (HIDS)
-
Monitoring: Single host/OS activities.
-
System logs (event logs, audit logs).
-
File integrity (checksums of critical files).
-
System calls, process behavior.
-
-
Advantages:
-
Can detect internal threats.
-
Sees encrypted traffic (after decryption at host).
-
Granular view of host activity.
-
-
Deployment: Agent-based software on critical servers/workstations.
Network-based IDS (NIDS)
-
Monitoring: Network traffic via sensors/promiscuous mode.
-
Architecture:
DiagramCANVAS: A simple network diagram. "Network Switch/Hub" in center. "NIDS Sensor" connected to switch port configured as SPAN/mirror port. Sensor sends traffic to "NIDS Management Console" which runs detection engines and alerts. Console connected to "Administrator" workstation. -
Detection Methods:
-
Signature-based: Matches traffic against known attack patterns (e.g., specific byte sequences). Low false positives, but misses zero-day.
-
Anomaly-based: Builds baseline of "normal" traffic; flags deviations. Can detect novel attacks but high false positives.
-
-
Placement: At network perimeter, DMZ, critical subnets.
IDS vs. Firewalls
| Firewall | IDS |
|---|---|
| Preventive (blocks traffic) | Detective (alerts/ logs) |
| Access control (allow/deny) | Monitoring & analysis |
| Works on policy (ports, IPs) | Works on patterns/behavior |
| Can be bypassed by allowed traffic | Sees all traffic on segment (if NIDS) |
Role in Safeguarding Against Malware
-
NIDS: Detects malware command-and-control (C2) traffic, worm propagation patterns (e.g., scanning), known exploit payloads in network packets.
-
HIDS: Detects malware installation (new files, registry changes), process injection, privilege escalation on host.
-
Complementary: Firewalls block known bad IPs/ports; IDS detects what slips through or originates internally.
XII. MALICIOUS SOFTWARE (MALWARE)
Types of Malware
| Type | Key Characteristics | Propagation Mechanism |
|---|---|---|
| Virus | Requires host program; attaches to executable; user action to spread. | Removable media, email attachments, downloads. |
| Worm | Self-replicating, standalone; exploits vulnerabilities to spread automatically. | Network shares, vulnerabilities (e.g., EternalBlue), email. |
| Trojan | Disguised as legitimate software; does not self-replicate. | Social engineering (fake downloads, attachments). |
| Ransomware | Encrypts files; demands ransom (cryptocurrency). | Phishing, exploit kits, RDP brute-forcing. |
| Spyware | Secretly monitors user activity (keystrokes, screens). | Bundled with freeware, drive-by downloads. |
| Rootkit | Hides existence/activities; gains admin/root privileges. | Exploits, trojans, phishing. |
| Botnet | Network of compromised bots/zombies controlled by C2 server. | Worms, trojans, exploits. Used for DDoS, spam. |
Security Considerations & Threats
-
Threat Landscape: Constant evolution; polymorphic (changes code), metamorphic (changes structure) malware evade signature detection.
-
Defense-in-Depth:
-
Prevention: Patch management, least privilege, user education, email filtering.
-
Detection: Antivirus (signature + heuristic), HIDS/NIDS, sandboxing.
-
Response: Isolation, forensics, recovery from backups.
-
XIII. WIRELESS SECURITY (WLAN & WAP)
Wireless LAN (WLAN) Security Challenges
-
Open Medium: Radio waves travel beyond physical boundaries → eavesdropping easy.
-
Rogue Access Points: Unauthorized APs inside corporate network.
-
Weak Encryption: WEP (Wired Equivalent Privacy) flaws:
-
RC4 keystream reuse due to IV collision.
-
FMS attack recovers key in minutes with ~1M packets.
-
-
Authentication Issues: Open system, shared key (WEP), weak PSK (WPA/WPA2 Personal).
-
Denial-of-Service: Jamming, deauthentication attacks.
WLAN Protocol Stack & MPDU Format
Access Point Security in Public Network Environments
-
Risks in Hotspots:
-
Evil Twin: Rogue AP with same SSID.
-
Man-in-the-Middle: Attacker intercepts traffic.
-
Session Hijacking: Stealing cookies/session tokens.
-
-
Mitigation Strategies:
-
Use WPA2/WPA3 (Enterprise with 802.1X) for encryption.
-
Always use VPN (SSL/IPsec) for end-to-end encryption.
-
Captive Portals: Web-based authentication (but does not encrypt traffic).
-
Disable auto-connect to open networks.
-
HTTPS Everywhere (ensure TLS for web).
-
Wireless Application Protocol (WAP) Security
-
WAP Architecture:
DiagramCANVAS: A stack diagram showing devices from top to bottom: 1) Wireless Device (Phone) with "WAE (Wireless Application Environment)" and "WTA (Wireless Telephony Application)". 2) "WAP Gateway" (protocol gateway) with "WAP Stack": WAE, WSP, WTP, WTLS, WDP. 3) "Web Server" with standard HTTP/SSL stack. Arrows show: Device ↔ Gateway (WAP protocol over wireless), Gateway ↔ Web Server (HTTP/HTTPS over Internet). -
End-to-End Security Model:
-
Problem: Wireless links (WSP/WTLS) and Internet (HTTP/SSL) have different security.
-
Solution: WTLS secures wireless leg; SSL/TLS secures Internet leg. Gateway terminates WTLS, may re-encrypt with SSL.
-
Gap: Gateway can see plaintext if not using end-to-end SSL (i.e., WTLS end-to-end is rare).
-
Wireless Transport Layer Security (WTLS)
-
Role: Security layer in WAP stack (equivalent to TLS in TCP/IP). Provides:
-
Confidentiality (encryption)
-
Integrity (MAC)
-
Authentication (certificates)
-
Designed for constrained wireless devices (low bandwidth, high latency).
-
-
Security Issues:
-
Certificate Handling: Limited storage on devices; often bypassed.
-
Downgrade Attacks: Attacker forces use of weak cipher suites.
-
Session Resumption: Vulnerable to hijacking if session ID predictable.
-
Overhead: Adds latency; often disabled for performance.
-
End-to-End Gap: Gateway termination breaks true end-to-end security.
-
XIV. APPLICATION LAYER SECURITY: SECURE ELECTRONIC TRANSACTION (SET)
Main Security Concerns in Online Financial Transactions
-
Confidentiality: Cardholder's payment data (credit card number) must be encrypted.
-
Authentication: Both cardholder and merchant must be authenticated to each other and to banks.
-
Integrity: Order and payment information must not be altered.
-
Non-Repudiation: Cardholder cannot deny order; merchant cannot deny receiving payment.
SET Protocol Detailed Explanation
-
Participants:
-
Cardholder: Customer with payment card.
-
Merchant: Seller of goods/services.
-
Issuer: Bank that issued cardholder's card.
-
Acquirer: Merchant's bank.
-
Payment Gateway: Processes payment messages between merchant & acquirer.
-
Certification Authority (CA): Issues digital certificates to all parties.
-
-
Dual Signature Mechanism (Key Innovation):
-
Cardholder creates two messages:
-
Order Information (OI): What to buy.
-
Payment Information (PI): Card details, amount.
-
-
Cardholder computes:
-
H1 = Hash(OI) -
H2 = Hash(PI) -
H_combined = Hash(H1 || H2)
-
-
Cardholder signs
H_combinedwith private key → Dual Signature. -
Result: Merchant sees
OIandH1(from dual sig) → verifies order integrity. Bank seesPIandH2→ verifies payment integrity. Neither sees the other's data. Cardholder's signature binds both.
-
How SET Addresses Concerns
-
Confidentiality:
PIencrypted with merchant's public key (so only merchant can read), thenPIandOIencrypted with symm. session key (for transmission). -
Authentication: All parties have X.509 certificates issued by CA.
-
Integrity: Hashes (SHA-1) and dual signature.
-
Non-Repudiation: Dual signature + certificates.
Application in Business Environment (Workflow)
-
Cardholder browses merchant site, generates
OI&PI. -
Cardholder creates dual signature, gets certificates from CA.
-
Cardholder sends to merchant:
{OI, PI, DualSig}encrypted appropriately. -
Merchant verifies
OI& dual signature, forwardsPI(withH2) to payment gateway. -
Payment gateway forwards to acquirer/issuer for authorization.
-
Issuer sends authorization response back through gateway to merchant.
-
Merchant confirms order to cardholder.
XV. ADDITIONAL & EMERGING TOPICS
Trusted Operating Systems
-
Trusted Computing Base (TCB): All hardware, firmware, software responsible for enforcing security policy. Must be correct (does what it should) and isolated (cannot be tampered).
-
Security Models:
-
Bell-LaPadula (Confidentiality): "No read up, no write down" (simple security property, *-property). Prevents info flow from high to low.
-
Biba (Integrity): "No read down, no write up" (simple integrity axiom, integrity *-property). Prevents contamination of high-integrity data by low.
-
-
Security Kernel / Reference Monitor: Minimal TCB component that mediates all accesses, verifies authorization, cannot be bypassed. Must be isolated, verifiable, minimal.
Web Traffic Security Approaches
| Approach | Layer | Scope | Typical Use |
|---|---|---|---|
| SSL/TLS | Transport (L4) / Application (L5-7) | End-to-end between client & server | Secure web browsing (HTTPS), email (SMTPS) |
| IPsec | Network (L3) | Gateway-to-gateway or host-to-host | Site-to-site VPN, remote access VPN |
| SET | Application (L7) | End-to-end for cardholder-merchant-bank | Online credit card transactions (rarely deployed now) |
[!TIP] SSL/TLS is most common for web. IPsec for network-level VPNs. SET was ambitious but complex; largely superseded by TLS + payment processors (PayPal, Stripe).
Smart Cards and Biometrics (Integrated in Section V)
- See detailed comparison in Section V.