PGP
PGP
Email Security
email is one of the most widely used and
authentication
of sender of message
message integrity
non-repudiation of origin
mail Extension)
building block
Integrated these algorithms into a generalpurpose application
on Unix, PC, Macintosh and other systems
provides a confidentiality and authentication
service that can be used for electronic mail
and file storage applications
PGP Operations
Authentication
Confidentiality
Confidentiality & Authentication
Compression
Compatibility
Authentication
digital signature service provided by PGP
Confidentiality
1.
2.
3.
4.
5.
Compression
by default PGP compresses message
Compatibility
S/MIME (Secure/Multipurpose
Internet Mail Extensions)
security enhancement to MIME email
MIME specification
includes the following elements:
Five new message header fields are defined. These
fields provide information about the body of the
message.
MIME-Version
Content-Type
Content-Transfer-Encoding
Content-ID
Content-Description
S/MIME Functionality
S/MIME provides the following functions
enveloped data
signed data
clear-signed data
S/MIME Cryptographic
Algorithms
digital signatures: DSS & RSA
hash functions: SHA-1 & MD5
session key encryption: ElGamal & RSA
message encryption: AES, Triple-DES,
S/MIME Messages
S/MIME secures
enveloped data
signed data
clear-signed data
registration request
certificate only message
Key generation
Registration
Certificate storage and retrieval
VeriSign Certificates
VeriSign provides three levels, or classes, of security for
public-key certificates
For Class 1 Digital IDs, VeriSign confirms the user's e-mail
address by sending a PIN and Digital ID pick-up
information to the e-mail address provided in the
application.
Certificate Authorities
have several well-known CAs
Verisign one of most widely used
Verisign issues several types of Digital IDs
increasing levels of checks & hence trust
Class
1
2
3
Identity Checks
name/email check
+ enroll/addr check
+ ID documents
Usage
web browsing/email
email, subs, s/w validate
e-banking/service access
Summary
have considered:
secure email
PGP
S/MIME