Question

In: Computer Science

You are working as a consultant and are assigned the task to set up a secure...

You are working as a consultant and are assigned the task to set up a secure communication
channel between three premises in the company. The communication should be using
symmetric encryption with new keys exchanged on a daily basis. All premises have individual
X.509 certificates. Describe a solution that includes how to carry out the encryption, key
exchange and certifying that there is no malicious man-in-the-middle attempt

Kindly answer this question in the field of Applied Computer Security....

Solutions

Expert Solution

Answer: An SSL X.509 Certificate is most reliable when issued by a trusted Certificate Authority (CA). The CA has to follow very strict rules and policies about who may or may not receive an SSL Certificate. So, when you have a valid SSL Certificate from a trusted CA, there is a higher degree of trust.

The encryption key exchange is carried out in the following manner:

  1. A browser requests a secure page.
  2. The web server sends its public key with its certificate.
  3. The browser checks that the certificate was issued by a trusted root authority or Certificate Authority and that the certificate is still valid and that the certificate is related to the site contacted.
  4. The browser then uses the public key, to encrypt a random symmetric encryption key and sends it to the server with the encrypted URL required as well as other encrypted http data.
  5. The web server decrypts the symmetric encryption key using its private key and uses the symmetric key to decrypt the URL and http data.
  6. The web server sends back the requested html document and http data encrypted with the symmetric key.
  7. The browser decrypts the http data and html document using the symmetric key and displays the information.

How to check if the connection is secure or not:

  1. A standard web site without SSL security displays “HTTP” at the beginning of the web site address in the browser address bar. This stands for “Hypertext Transfer Protocol,” and is the conventional way to transmit information over the Internet. However, a web site that is secured with an SSL Certificate will have “HTTPS” before the address. This stands for “Hypertext Transfer Protocol Secure”.
  2. You will also see a padlock symbol on the top or bottom of the Internet browser.
  3. By clicking the closed padlock in the browser window, or certain SSL trust marks, you can see the authenticated organization name. In high-security browsers, the authenticated organization name is prominently displayed and the address bar turns green when an Extended Validation (EV) SSL Certificate is detected. If the information does not match, or the certificate has expired, the browser displays an error message or warning.

Related Solutions

Imagine you are working for Drexel Morgan Bank, and you are assigned with the task of...
Imagine you are working for Drexel Morgan Bank, and you are assigned with the task of evaluating Earl Grey, Inc. Consider the following financial information of this company. Consider the following information about Earl Grey, Inc. Total assets $250 million Total debt $110 million Preferred stock $ 35 million Common stockholders' equity $105 million Net profits after taxes $25.5 million Number of preferred stock outstanding 1.5 million shares Number of common stock outstanding 9 million shares Preferred dividends paid $2.5...
You have been assigned to set up a LAN for your office. a.Discuss the role and...
You have been assigned to set up a LAN for your office. a.Discuss the role and importance of communications media as part of this setup [2 marks] b.Identify two(2) types of communications media, clearly indicating your preference to create this LAN. Justify your preference.[4marks] 2.The use of social media as a tool for communication is on a rise in society today. As it relates to education, discuss: a.Two (2) possible benefits to studentsof using social media[4 marks] b.Two (2)challenges of...
As a Geologist in consultant firm, you are assigned to work at the ground investigation site...
As a Geologist in consultant firm, you are assigned to work at the ground investigation site for a residential development project in the New Territories East adjoining Tolo Channel (i.e. Ma On Shan). How would you describe to the developer your findings of the major rock and mineral group?
As a Project Engineer in consultant firm, you are assigned to design a residential building with...
As a Project Engineer in consultant firm, you are assigned to design a residential building with basement at Yuen Long. How would you describe to the developer your findings from site investigation?
A ) Suppose you are working as an economic consultant and you are supposed to explain...
A ) Suppose you are working as an economic consultant and you are supposed to explain the consequences of the following cases to your clients. Answer each part separately. Suppose due to a war in a neighbouring country, the country received refugees which increased the labour force. Also, there is a huge reduction in global oil prices. By using the Aggregate Supply curve, show the possible effects of these two changes on the price level and aggregate output in the...
You are a senior adviser to the EPA. You have been assigned the task of creating...
You are a senior adviser to the EPA. You have been assigned the task of creating an oversight board which will be in charge of the creation and enforcement of regulations relating to mining. Your plan calls for the appointment of ten (10) members. To attract the best possible board members you are considering adding a provision that no member may be terminated except "only for good cause." What are the arguments both for and against the "only for good...
Suppose you are working as an economic consultant and you are supposed to explain the consequences...
Suppose you are working as an economic consultant and you are supposed to explain the consequences of the following cases to your clients. Answer each part separately. a) (3 pts) Suppose due to a war in a neighbouring country, the country received refugees which increased the labour force. Also, there is a huge reduction in global oil prices. By using the Aggregate Supply curve, show the possible effects of these two changes on the price level and aggregate output in...
You are assigned the task of determining the bacterial density of newly-grown culture. You decide that...
You are assigned the task of determining the bacterial density of newly-grown culture. You decide that you will analyze the sample with two methods, spectrophotometry and dilution plating. Your results show the sample tested using spectrophotometry had a bacteria density that was roughly ten folds that of the plated sample. Please explain in detail.
You work for a pharmaceutical company where you are assigned the task of creating new drug...
You work for a pharmaceutical company where you are assigned the task of creating new drug therapies to treat thyroid disorders such as hyperthyroidism (high levels of T3 and T4) and hypothyroidism (low levels of T3 and T4). Your team has designed a few drugs, and your job is to identify which drug(s) would be successful in treating thyroid disorders based on your knowledge of thyroid hormone synthesis. Below is the list of drugs your team designed (all of these...
Question 1. Suppose you are working as a consultant for a firm that is a monopoly...
Question 1. Suppose you are working as a consultant for a firm that is a monopoly and is worried about its policies in the short run. What would you recommend in terms of quantity changes (raise, cut, shut down or stay put) and price changes (raise, cut, stay put) in each of the following situations a through c: a. [5 points] P = $299 MC = $349 AVC = $249 b. [5 points] MR = $150 MC = $100 AVC...
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT