
Introducing 'elliptic curve' technology...
Published: 23 September 2002 11:00 BST
Sun has donated new cryptography technology to an open source project at the heart of many secure transactions on the internet.
Sun's "elliptic curve" technology is involved in the process of using keys to encrypt and decrypt information for electronic transactions. Such encryption lets people buy products online, for example, while shielding their credit card number from prying eyes. The server seller donated the technology to the OpenSSL project, a programming group that makes an open source version of the Secure Sockets Layer (SSL) encryption system.
Elliptic curve cryptography will enable secure communications with devices that don't have as much calculating power as most desktop computers, said Whitfield Diffie, Sun's chief security officer and a pioneer of the Diffie-Hellman "public key" cryptography method used today in SSL and other encryption systems.
"Small gadgets are the most obvious place to use it," Diffie said, but once the technology is built, it likely will spread farther. "The deployment schedule is on the order of several years to a decade unless something comes along in the interim. I would conjecture that by 2010 or so, this will be widely used."
Current encryption technology is based on mathematics developed in the 17th and 18th centuries, Diffie said. "Elliptic curve cryptography brings it forward into the mathematics of the 19th century," he said.
Diffie exhorted companies to build security into computing services from the start, not patch it on at the end, and announced Sun products to help in that plan. In combination with software and hardware companies, Sun announced a partnership to build a "perimeter security" product that handles problems at the boundary of corporate computing networks and the public Internet. The product will filter out undesired network traffic, detect intrusions and screen for viruses.
Sun also announced a secure web server, the software that delivers web pages across the internet. Because web servers typically are very public, they're a particular target for attacks over the network.
Stephen Shankland writes for News.com
My Client, a leading Consulting Company based in Reading is seeking a Technical Architect who is capable of working across multiple projects to join ...
A fantastic opportunity has arisen for an Encryption analyst the ideal candidate will have exposure to ICSF, TKE/ DKMS etc. Apply now Rate excellent ...
Applications support specialist? Experienced in final line support of business critical applications? Strong background in open source languages? ...
CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.
Stories from the web...
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page
Peter Cochrane Peter Cochrane's Blog: Is convergence a fiction? Or could it finally be happening…
Clive Longbottom Quocirca's Straight Talking: A game of two halves Microsoft Virtualisation scores while its SOA bores...