Security Architecture for Sensitive Information Systems
Xianping Wu, Phu Dung, Balasubramaniam Srinivas · InTech eBooks · 2010
Convergence and Hybrid Information Technologies 240 potential targets for adversaries wanting to benefit from security weaknesses.Therefore, in following sections, existing approaches, main issues and limitations relating to sensitive information protection are investigated. Related work and limitationsAccording to the process of sensitive information retrieving, several security aspects need to be studied.Firstly, securing communication channel, it applies cryptography and security tunnels to protect message between entities.Secondly, securing user interface, it uses authentication mechanisms to prevent unauthorized access to sensitive information.Thirdly, securing sensitive information storage, it uses cryptographic keys to encrypt all sensitive information before storing it. Securing communication channelIn cryptography, a confidential channel is a way of transferring data that is resistant to interception, but not necessarily resistant to tampering.Conversely, an authentic channel is a way of transferring data that is resistant to tampering but not necessarily resistant to interception (Tienari & Khakhar, 1992).Interception and tampering resistance is best developed through communication channel.In order to reach the interception resistance goal, all communication is scrambled into ciphered text with a predetermined key known to both entities to prevent an eavesdropper from obtaining any useful information.In order to achieve the tampering resistance goal, a message in a communication is assembled using a credential such as an integrity-check to prevent an adversary from tampering with the message.In this section, the different approaches of securing communication channel are investigated, and their pros and cons are evaluated.The investigation is conducted by subdividing communication channel into unicast channel and multicast channel Secure Communication in Unicast Channels: With the recent development of modern security tools to secure bidirectional communication between two entities, many protocols, such as Internet Protocol Security (IPsec) (Atkinson, 1995), Secure Sockets Layer (SSL), Transport Layer Security (TLS) (Dierks & Rescorla, 2008;Freier et al., 1996) and Secure Realtime Transport Protocol (SRTP) (Lehtovirta et al., 2007), have been proposed in the literature to address the problems and challenges of a secure unicast communication channel.One of the most important factors in unicast communication channel protection is the cryptographic key.The issues of key distribution and key type, therefore, determine the security of the unicast communication channel.IPsec and SSL/TLS are the most famous, secure and widely deployed among all the protocols for protecting data over insecure networks.IPsec is a suite of protocols for protecting communications over Internet Protocol (IP) networks through the use of cryptographic security services.It supports network-level peer authentication, data origin authentication, data integrity, data confidentiality (encryption), and replay protection.However, in IPsec, communication is protected by session keys, and the security of a session key is guaranteed by long-term shared keys.Therefore, once the long-term keys are compromised, the security of IPsec is under threat.As Perlman and Kaufman (2001) indicated, IPsec is vulnerable to dictionary attack, due to the pre-shared long-term keys, and Ornaghi and Valleri (2003) demonstrated it in a BlackHat conference.Moreover, in IPsec, the long-term shared keys involve into key exchange protocol to generate session keys.According to information entropy (Gray, 1990), the uncertainty of key www.intechopen.