ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Industry watch Toolkit

RSA: Split passwords make secrets safer

Peter Judge ZDNet.co.uk

Published: 16 Apr 2003 08:54 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Breaking passwords in two and storing them in two places will make systems more secure, said RSA Security at its eponymous security show in San Francisco on Tuesday. The company also launched a framework for increased integration of its identity management products.

RSA's Nightingale uses "secret-splitting", a cryptographic technique previously used in very high-end systems. A Nightingale server holds part of the password, which has been cryptographically split in two, according to a process invented by cryptographer Adi Shamir in the 1970s. The process has previously only been used in high-end bespoke systems for banking.

"This is secret-splitting for the masses," said Burt Kaliski, chief scientist at RSA Security. The developers' kit will be available in June, aimed at early adopters. It will be used alongside smartcard systems, so that users' passwords, and the personal life secrets they give to the company to retrieve their password, are not accessible if the server's data store is accessed by a hacker.

"The data store is a single place which, if compromised, defeats the whole system," said Kaliski. "With secret-splitting there is no single point of compromise."

Nightingale is just the start of secret-splitting in RSA's products. Shamir's original paper suggested splitting secrets to several stores, so that, for instance, three out of five of them could reconstruct the secret. Nightingale simplifies the process to two.

"So far, Nightingale is good for short secrets," said Kaliski. "It could be used for strong secrets such as a bank's signature key. There is a need now for weak secrets to be split effectively."

Nightingale has been engineered to make no changes to the user experience, but companies may want to advertise that they are using it as a way to keep their customers' sensitive data more secure, RSA said.

"E-commerce sites want to be sure that their customers' order information does not fall into the wrong hands," said Kaliski, suggesting that regulations and the risk of lawsuits will force vendors to increase their protection.

He said that a Nightingale brand might be created to identify sites where private data is split.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
56 out of 120 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Unix SA/Engineer (Solaris,Linux, LVM, Veritas) BANKING

This role is more of a solution-engineering role than just a straight split between support & projects. Excellent technical knowledge gained from a ...

SENIOR NETWORK ENGINEER - CISCO WAN & CALL MANAGER - HOME BASED

Role with be split between home based working, Europe wide travel, occasional international travel & visits to their Midlands base. Excellent role is ...

IT Help Desk Analyst

New Look IT Systems Stores and Head Offices. Customer focus, Business awareness, Strong organisational skills - Confidence to provide on site ...

Discussions

harpless harpless

SAP goes big business

Friday 25 July 2008, 6:17 PM

1 comment
pjc158 pjc158

Will Drizzle rain on Sun's MySql

Friday 25 July 2008, 5:30 PM

1 comment
pjc158 pjc158

Show me the money!

Friday 25 July 2008, 5:18 PM

5 comments

Featured Talkback

When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal