You are here: silicon.com > Software > Security Strategy

Security Strategy

Sun donates 'SSL-lite' to open source group

Introducing 'elliptic curve' technology...

By Stephen Shankland

Published: 23 September 2002 11:00 GMT

Sun has donated new cryptography technology to an open source project at the heart of many secure transactions on the internet.

Sun's "elliptic curve" technology is involved in the process of using keys to encrypt and decrypt information for electronic transactions. Such encryption lets people buy products online, for example, while shielding their credit card number from prying eyes. The server seller donated the technology to the OpenSSL project, a programming group that makes an open source version of the Secure Sockets Layer (SSL) encryption system.

Elliptic curve cryptography will enable secure communications with devices that don't have as much calculating power as most desktop computers, said Whitfield Diffie, Sun's chief security officer and a pioneer of the Diffie-Hellman "public key" cryptography method used today in SSL and other encryption systems.

"Small gadgets are the most obvious place to use it," Diffie said, but once the technology is built, it likely will spread farther. "The deployment schedule is on the order of several years to a decade unless something comes along in the interim. I would conjecture that by 2010 or so, this will be widely used."

Current encryption technology is based on mathematics developed in the 17th and 18th centuries, Diffie said. "Elliptic curve cryptography brings it forward into the mathematics of the 19th century," he said.

Diffie exhorted companies to build security into computing services from the start, not patch it on at the end, and announced Sun products to help in that plan. In combination with software and hardware companies, Sun announced a partnership to build a "perimeter security" product that handles problems at the boundary of corporate computing networks and the public Internet. The product will filter out undesired network traffic, detect intrusions and screen for viruses.

Sun also announced a secure web server, the software that delivers web pages across the internet. Because web servers typically are very public, they're a particular target for attacks over the network.

Stephen Shankland writes for News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Nick Heath Your top HR tech priorities for next year revealed How to make human resources IT work for you

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business


  • Jobs
Java Developer / J2EE Developer (Spring, Tomcat, Jetty etc)

Understanding of HTTP proxy servers is highly desirable; knowledge of WPAD, ICAP, WCCP is a big plus.d) Clear understanding of sockets programming ...

Business Analyst (Credit Card transactions)

Business Analyst. You will have recent experience of working within Bank that issues cards on a First Data platform, as well as developing in-house ...

Researcher in Computational Finance - Cyprus - relocation pack

In addition, the role involves statistical analysis of portfolio risk and returns, involvement in the portfolio management process and monitoring ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: