Saturday, April 21, 2012

A Brief Comparison between Apple iPad 3(new iPad) and Samsung Galaxy Tab 10.1

• Apple iPad 3(new iPad) is powered by Apple A5X dual core processor and quad core GPU while Samsung Galaxy Tab 10.1 is powered by 1GHz dual core processor and 8 cores GPU on top of Nvidia Tegra 2 chipset.

• Apple iPad 3(new iPad) runs on Apple iOS 5.1 while Samsung Galaxy Tab 10.1 runs on Android OS v3.2 Honeycomb.

• Apple iPad 3(new iPad) has 9.7 inches HD IPS capacitive touchscreen featuring a monster resolution of 2048 x 1536 pixels at a pixel density of 264ppi while Samsung Galaxy Tab 10.1 has 10.1 inches PLS TFT touchscreen featuring a resolution of 1280 x 800 pixels at a pixel density of 149ppi.

• Apple iPad 3(new iPad) has 5MP camera that can capture 1080p HD videos @ 30 fps while Samsung Galaxy Tab 10.1 has 3.15MP camera that can capture 720p videos @ 30 fps.

• Apple iPad 3(new iPad) offers super-fast 4G LTE connectivity while Samsung Galaxy Tab 10.1 only offers HSDPA connectivity. However, currently 4G LTE is supported only on AT&T and Verizon networks in the U.S. and Bell, Rogers, and Telus networks in Canada.

Summary of IPV6 addresses and difference between IPV4 and IPV6




Internet Protocol Version 6 (IPv6) is a network layer protocol that enables data communications over a packet switched network. Packet switching involves the sending and receiving of data in packets between two nodes in a network. The working standard for the IPv6 protocol was published by the Internet Engineering Task Force (IETF) in 1998. The IETF specification for IPv6 is RFC 2460. IPv6 was intended to replace the widely used Internet Protocol Version 4 (IPv4) that is considered the backbone of the modern Internet. IPv6 is often referred to as the "next generation Internet" because of it's expanded capabilities and it's growth through recent large scale deployments. In 2004, Japan and Korea were acknowledged as having the first public deployments of IPv6.

The explosive growth in mobile devices including mobile phones, notebook computers, and wireless handheld devices has created a need for additional blocks of IP addresses. IPv4 currently supports a maximum of approximately 4.3 billion unique IP addresses. IPv6 supports a theoretical maximum of 2128 addresses (340,282,366,920,938,463,463,374,607,431,768,211,456 to be exact!). Recent advancements in network technology including Network Address Translation (NAT) have temporarily lessened the urgency for new IP addresses, however, recent estimates indicate that IPv4 addresses could be exhausted as soon as 2012.

IPv6 and IPv4 share a similar architecture. The majority of transport layer protocols that function with IPv4 will also function with the IPv6 protocol. Most application layer protocols are expected to be interoperable with IPv6 as well, with the notable exception of File Transfer Protocol (FTP). FTP uses embedded network layer addresses to facilitate data transmission. An IPv6 address consists of eight groups of four hexadecimal digits. If a group consists of four zeros, the notation can be shortened using a colon to replace the zeros.

A main advantage of IPv6 is increased address space. The 128-bit length of IPv6 addresses is a significant gain over the 32-bit length of IPv4 addresses, allowing for an almost limitless number of unique IP addresses. The size of the IPv6 address space makes it less vulnerable to malicious activities such as IP scanning. IPv6 packets can support a larger payload than IPv4 packets resulting in increased throughput and transport efficiency.

A key enhancement over IPv4 is native support for mobile devices. IPv6 supports the Mobile IPv6 (MIPv6) protocol which enables mobile devices to switch between networks and receive a roaming notification regardless of physical location. MIPv6 is a hallmark of the protocol and was specified as a firm requirement during the design of IPv6. The IETF has separate specifications for MIPv6 that detail data structure, messaging, and security requirements.

Auto-configuration is another IPv6 enhancement that is considered a great benefit to network administrators. IPv6 devices can independently auto-configure themselves when connected with other IPv6 devices. Configuration tasks that can be carried out automatically include IP address assignment and device numbering. An IPv6 router has the ability to determine its own IPv6 address using data link layer addressing parameters. The IETF has issued RFC 2462 to set guidelines for IPv6 auto-configuration.

The IPv6 protocol improves upon IPv4 with increased authentication and privacy measures. IPSec security is embedded into the IPv6 specification to manage encryption and authentication between hosts. This built in security framework enables secure data traffic between hosts that is independent of any applications on either host. In this way, IPv6 provides an efficient end to end security framework for data transfer at the host or the network level.

The deployment of IPv6 networks is growing worldwide. Full replacement of IPv4 is expected to take some time, as it remains the most widely used Internet Protocol. The United States, China, and India are leading recent deployments of the IPv6 protocol and have large investments in IPv6 network infrastructure. The United States government has mandated that federal agencies must complete the transition to an IPv6 infrastructure no later than 2008. Software companies are also releasing operating systems that support the IPv6 standard. In 1997, IBM became the first commercial vendor to support IPv6 through its AIX 4.3 operating system. The latest version of Microsoft's Windows operating system, Windows Vista, has full IPv6 support enabled by default.

Wednesday, April 11, 2012

Basic things in Encryption


Goal of Encryption of Internet Traffic

  • conveys confidentiality to messages while in transit
  • changes readable text messages into something that cannot be read
  • discourages anyone from reading or copying the messages

Related Problem

  • if header information is not encrypted, traffic analysis is possible
  • traffic analysis - the analysis of header information in order to derive useful information from the headers

Encryption Components

  • an algorithm
  • a key

Encryption Algorithms

  • a series of steps that mathematically transforms plain-text or other readable information into unintelligible cipher text.
  • Cipher text - Data that has been encrypted. Cipher text is unreadable until it has been converted into plain text (decrypted) with a key.

Decryption

  • The inverse mathematical transformation, which transforms the encrypted cipher text back into something readable, is called decryption.

Encryption Algorithm - Input and Output

  • a key and plain text are input into an encryption algorithm
  • cipher text is output from the encryption algorithm

Encryption Keys

  • a bit string consisting of x number of bits. A 40 bit key is a string consisting of 40 bits
  • an encryption algorithm can use one of a large number of possible keys
  • the number of possible keys each algorithm can support depends on the number of bits in the key. The longer the key, the more the possible number of keys

Encryption Key Example

  • example - if the key length is 40, then 2 to the n, where n is the number of bits in the key, results in 1,000,000,000,000 possible key combinations, with each different key causing the algorithm to produce slightly d ifferent cipher output

Security and Encryption

  • encryption algorithms are considered secure if the security depends on only one factor - key length
  • security does not depend on secrecy, inaccessibility, or anything else, only on the key length
  • if this factor is true, then the only possible attack against the algorithm is a brute force attack

Brute Force Attacks and Security

  • all key combinations must be tried in order to find the correct key
  • the length of the key determines the possible number of keys available for selection
  • the longer the key length the longer it takes to discover which key will actually decrypt
  • specifying a long enough key length makes a brute-force attack non-feasible

Symmetric Encryption

  • identical keys are used to encrypt and decrypt the message
  • a message encrypted by one specific symmetric key can only be decrypted by using the same key, it can be decrypted with a different key

Symmetric Keys

  • a random bit string, n bits long
  • most often generated on the source computer

Advantages of Using Symmetric Encryption

  • the encryption process is simple
  • each trading partner can use the same publicly known encryption algorithm - no need to develop and exchange secret algorithms
  • security is dependent on the length of the key

Drawbacks of Using Symmetric Encryption

  • a shared secret key must be agreed upon by both parties
  • if a user has n trading partners, then n secret keys must be maintained, one for each trading partner
  • authenticity of origin or receipt cannot be proved because the secret key is shared
  • management of the symmetric keys becomes problematic

Problems with Management of Symmetric Keys

  • trading partners must always use the exact same key to decrypt the encrypted message
  • key exchange is difficult because the exchange itself must be secure with no intervening compromise of the key
  • management of keys is difficult as numbers of trading partners increases, especially when multiple keys exist for each trading partner

Public Key Cryptography as a Solution for Managing Symmetric Keys

  • public key cryptography simplifies the management of symmetric keys to the point whereby a symmetric key can be used not only for each trading partner, but for each exchange between trading partners
  • additionally, public key cryptography can be used to unambiguously establish non-repudiation of origin and receipt

Asymmetric Encryption - (Public Key Cryptography)

  • based on the concept of a key pair
  • each half of the pair (one key) can encrypt information that only the other half (one key) can decrypt
  • the key pair is designated and associated to one, and only one, trading partner

Asymmetric Key Pairs

  • consists of two keys - one private and one public
  • private key is secret and only known by the designated trading partner it belongs to
  • public key is published widely but still associated only with the designated trading partner

Asymmetric Key Uses

  • confidentiality
  • digital signatures
  • both uses depend on the association of a key pair with one, and only one owner of the keys
  • both uses depend on one of the keys in the key pair being secret from everyone but the owner of the key


Confidentiality Using Asymmetric Key Pairs (Encryption)

  • Trading Partner A desires to send a confidential message to Trading Partner B
  • Trading Partner A retrieves Trading Partner B's public key and encrypts the message with it

Confidentiality Using Asymmetric Key Pairs (Decryption)

  • Trading Partner B receives the message and decrypts the message with the secretly held, private key
  • The only key that can possibly decrypt a message that is encrypted with Trading Partner B's public key is Trading Partner B's private key

Digital Signatures Using Asymmetric Key Pairs (Encryption)

  • Trading Partner A desires to send a digitally signed message to Trading Partner B
  • Trading Partner A uses their own private key to encrypt a part of the message
  • Trading Partner A sends the encrypted part of the message to B

Digital Signatures Using Asymmetric Key Pairs (Decryption)

  • Trading Partner B receives Trading Partner A's message and obtains A's public key
  • Trading Partner B tries to decrypt the encrypted portion of Trading Partner A's message
  • If it decrypts, Then Trading Partner B knows it has to be from A because the only thing A's public key will decrypt is something encrypted with A's private key and only A has access to that private key

Real World Usage of Asymmetric Encryption

  • public key encryption algorithms are considerably slower than symmetric key algorithms
  • rarely used as encryption methodology for bulk messages or parts of messages
  • normally used in conjunction with a Message Integrity Check (MIC) or to encrypt a symmetric key, where the MIC or symmetric key is what is encrypted using public key encryption algorithms


Speed Comparison - Symmetric vs Asymmetric

  • software encryption using DES (symmetric key algorithm) is 100 times faster than software encryption using RSA (asymmetric key algorithm) - estimate provided by RSA Data Securities
  • hardware encryption using DES (symmetric key algorithm) is anywhere from 1,000 to 10,000 times faster than hardware encryption using RSA (asymmetric key algorithm)

Encryption Needs for Confidential Commercial Exchanges

  • for interoperability between two trading partners
  • standard encryption algorithm(s)
  • standard key length(s)
  • agreed upon beforehand or within an individual transaction

Issues

  • how secure is the algorithm?
  • how fast are current implementations of the algorithm?
  • availability of APIs and/or tools to implement the algorithm
  • frequency of use of algorithm with other trading partners
  • sufficient key length to discourage brute force attacks

Common Symmetric Key Algorithms

  • Data Encryption Standard - DES
  • Triple DES
  • RC2 and RC5
  • IDEA

Block Ciphers vs Stream Ciphers

  • block ciphers - take a set number of bits, typically 64 bits, and encrypts the them as a single block
  • stream ciphers - take and encrypt one bit at a time
  • Most ciphers belong to the block cipher class.

Data Encryption Standard - DES

  • most widely used commercial encryption algorithm
  • in the public domain, available to all
  • a U. S. government encryption standard
  • security is known and is dependent solely on the key length
  • data sequenced into 64 bit blocks prior to encryption, each block encrypted

Cipher Block Chaining (CBC)

  • recommended mode for using DES
  • each 64 bit block of data is exclusively OR'd with the previous block before encryption
  • gives added protection by making each cipher-text block depend on each other
  • changes in the cipher text can be detected

Brute Force Attacks against DES

  • DES specifies a 56 bit key, so there are 2 to the 56th possible keys
  • brute force attack means trying every single key (10,000,000,000,000,000) to decrypt 8 bytes of known cipher text into the corresponding plain text


Resources Required to Break DES Key

  • $1 million dollar hardware based, brute-force attack on DES takes approximately 3.6 hours to recover the DES key
  • $1 million dollar software based, brute force attack on DES takes approximately 3 years to recover the DES key
  • above figures attributed to B. Schneier, "E-Mail Security", John Wiley & Sons, 1995


Triple DES

  • variant on DES which encrypts message 3 times with 2 independent 56 bit keys
  • effective key length is 112 bits
  • brute force attack on Triple DES is not feasible

RC2 and RC5

  • RSA owned proprietary symmetric key algorithms
  • variable key length makes security configurable
  • RC2 is a block cipher (similar to DES) and should be used in CBC mode, RC5 is also a block cipher and should be used in CVC Pad mode
  • Both use 128 bit key but support key masking for configuration of key length

International Data Encryption Algorithm (IDEA)

  • a block cipher, in the mold of DES
  • uses a 64-bit block size and a 128-bit key
  • IDEA in CBC mode is the bulk encryption algorithm used by Pretty Good Privacy (PGP) which makes it the most widely used encryption algorithm for

Key Lengths and Secure Transactions

  • Algorithms that make a brute force attack not feasible
  • Triple DES with 2 56 bit keys
  • RC2 and RC5 with 128 bit keys
  • IDEA with 128 bit key

Recommendations on Key Lengths

  • Transactions of minimal or small value - 40 bit RC2 or 56 bit DES
  • Most commercial applications need a key length of 75 bits
  • High value transactions Triple-DES, IDEA or 128 bit RC2 or RC5

Conclusions

  • Encryption is the correct method to implement confidentiality for Internet traffic
  • Symmetric key algorithms should be chosen for encryption of confidential data
  • The more bits in the symmetric key, the less probable the compromise of the encrypted data