Corporate Security Requirements for Conducting Business over the Internet
Michael A. Simonyi · Auerbach Publications eBooks · 2002
Conducting business over the Internet is not as safe as conducting business over secured private lines. Contrary to popular belief, conducting business over the Internet is a very hazardous undertaking. Placing a Web server on the Internet and exposing business applications over 128-bit Secure Socket Layer (SSL) is not considered a highly secure solution. One might think that 128-bit SSL is secure enough, so why do banks not use it? Everyone else does. For most intents and purposes, 128-bit SSL suffices for encrypting trivial transactions. However, keep in mind that although the banks use SSL to provide transaction security to the consumer, they do not use it internally to protect their monetary transactions. Military-grade encryption systems are known to use key lengths on the order of 1024K and up. The previous government standard of 56-bit Data Encryption Standard (DES) was broken in 1997 and recently again in 1999 in less than 24 hours by using a distributed algorithm from www.distributed.net . Currently, the challenge to break RC5 SSL is underway and has been for some time. It is only a matter of time before the key will be cracked via a brute-force method. In general, the longer the encryption key length, the greater the time required to crack the key. The Federal Information Processing Office requirements in the United States have standardized on 3DES, also known as the Triple DES algorithm. 3DES uses dual encryption keys and a three-phase mechanism to encrypt and decrypt a data stream. 3DES is a 168-bit encryption standard that is available in all security-capable devices manufactured and sold in North America. 3DES is not considered a highly secure encryption mechanism but it is the standard set forth by the Federal Information Processing Office ( https://ccf.arc.nasa.gov/ fipmo/index.html). For the majority of business transactions over the Internet, SSL and 3DES are acceptable. For others that demand higher levels of security that support greater key encryption lengths, proprietary encryption hardware or software will be required. A note of caution, however: the greater the encryption key length, the more time required to encrypt and decrypt the data. As such, encryption will increase the average latency time for completing a transaction between two points.