Secure Messaging Interoperability - PowerPoint PPT Presentation

1 / 10
About This Presentation
Title:

Secure Messaging Interoperability

Description:

Messages are encrypted by sender; remain encrypted until decrypted by recipient ... Examples: ZixCorp, PostX, HushMail. Co-existence and Interoperability ... – PowerPoint PPT presentation

Number of Views:33
Avg rating:3.0/5.0
Slides: 11
Provided by: russc
Category:

less

Transcript and Presenter's Notes

Title: Secure Messaging Interoperability


1
Secure Messaging Interoperability
2
End to End Secure Messaging
  • Messages are encrypted by sender remain
    encrypted until decrypted by recipient
  • Messages are signed by sender signature is
    verified by recipient
  • Uses a combination of symmetrical and public key
    algorithms
  • Established standards
  • Examples S/MIME, PGP

3
End to End Secure Messaging
  • Certificate administration a challenge
  • Internal renewal, revocation, support
  • External cross certification
  • Messages cannot be scanned for viruses
  • Messages cannot be filtered for content

4
Gateway to Gateway Secure Messaging
  • Messages are encrypted by outbound MTA, typically
    at domain boundary, decrypted by inbound MTA
  • Messages are signed by outbound MTA, typically at
    domain boundary, signature is verified by inbound
    MTA
  • Uses a combination of symmetrical and public key
    algorithms
  • Emerging standards
  • Examples TLS, SMG

5
Web Enabled Secure Messaging
  • Variation 1
  • Sender deposits message in a secure web server,
    sends a URL link to recipient
  • Recipient opens a web browser, establishes SSL
    session, authenticates to server, reads message
  • Variation 2
  • Sender encrypts message with a one-time use key,
    deposits key in a secure web server, sends
    encrypted message together with instructions to
    retrieve key
  • Recipient authenticates to server, retrieves key,
    reads message

6
Web Enabled Secure Messaging
  • Procedures for issuing certificates, key
    distribution and authentication of senders and
    recipients vary by service provider
  • Components of these systems are based on
    standards
  • Examples ZixCorp, PostX, HushMail

7
Co-existence and Interoperability
  • Co-existence - ability to utilize existing SMTP
    infrastructure to send unsigned/unencrypted
    messages between users of different secure
    messaging models
  • Interoperability - ability to send an encrypted
    or signed message between users of different
    secure messaging models

8
Secure Messaging Gateway, v1
  • A profile of S/MIME specification
  • Version 1.0
  • Domain certificates
  • Manual certificate exchange
  • No CRL

9
Issues
  • Certificate interoperability
  • Certificate verification and revocation
  • Certificate repository
  • Certificate discovery
  • Establishing and maintaining trust
  • Patents

10
Possible Approaches
Write a Comment
User Comments (0)
About PowerShow.com