Answer Posted / ramkumar
A user can generate his or her own key pair, or, depending
on local policy, a security officer may generate key pairs
for all users. There are tradeoffs between the two
approaches. In the former, the user needs some way to trust
his or her copy of the key generation software, and in the
latter, the user must trust the security officer and the
private key must be transferred securely to the user.
Typically, each node on a network should be capable of
local key generation. Secret-key authentication systems,
such as Kerberos, often do not allow local key generation,
but instead use a central server to generate keys.
Once a key has been generated, the user must register his
or her public key with some central administration, called
a Certifying Authority (CA). The CA returns to the user a
certificate attesting to the validity of the user's public
key along with other information (see Questions 4.1.3.10-
4.1.3.12). If a security officer generates the key pair,
then the security officer can request the certificate for
the user. Most users should not obtain more than one
certificate for the same key, in order to simplify various
bookkeeping tasks associated with the key.
| Is This Answer Correct ? | 0 Yes | 0 No |
Post New Answer View All Answers
What are "stream" and "block" ciphers?
WHAT IS A SAMPLE USER INTERFACE OF DES ENCRYPTION/DECRYPTION PROJECT?
What is meant by 1024, 2048, 5096 bit encryption?
What is the Popular Symmetric-Key Encryption Method
Do digital signatures help detect altered documents and transmission errors?
Blowfish uses the longest key. Does this mean it is the strongest cipher?
What is key management ?
What is the mceliece cryptosystem?
A company wants to transmit data over the telephone, but it is concerned that its phones may be tapped. All of its data is transmitted as four-digit integers. It has asked you to write a program that will encrypt its data so that the data may be transmitted more securely. Your script should read a four digit integer entered by the user in a prompt dialog and encrypt it as follows: Replace each digit by (the sum of that digit plus 7) modulus 10. Then swap the first digit with the third, and swap the second digit with the fourth. Then output XHTML text that displays the encrypted integer.
What is nonlinear cryptography?
What is cryptographic synchronisation?
Is there a limit on the file size or on the number of encrypted files?
What is an algorithm?
What is the difference between a message authentication code (MAC) and a one-way hash?
How to change the location of the Kryptel (Silver Key) program group?