1
SYMMETRIC AND ASYMMETRIC CRYPTOGRAPHYसिमेट्रिक और एसिमेट्रिक क्रिप्टोग्राफी
ENCRYPTION converts plain text into cipher text with a cryptographic algorithm.
- SYMMETRIC: ONE secret key encrypts and decrypts. It gives confidentiality only; AES is an example
- ASYMMETRIC: TWO keys. You share the PUBLIC key, and never share the PRIVATE key
- What one key encrypts, only the other key of the pair can decrypt
- To send you a secret, the sender encrypts with YOUR public key; you decrypt with your private key
- RSA, Diffie-Hellman and elliptic curve systems are asymmetric
- सिमेट्रिक: एक गुप्त कुंजी एन्क्रिप्ट और डिक्रिप्ट करती है। यह केवल गोपनीयता देती है; एईएस इसका उदाहरण है
- एसिमेट्रिक: दो कुंजियाँ। आप सार्वजनिक कुंजी साझा करते हैं, और निजी कुंजी कभी साझा नहीं करते
- जोड़े की एक कुंजी जो एन्क्रिप्ट करे, उसे केवल दूसरी कुंजी डिक्रिप्ट कर सकती है
- आपको गुप्त संदेश भेजने के लिए प्रेषक आपकी सार्वजनिक कुंजी से एन्क्रिप्ट करता है; आप अपनी निजी कुंजी से डिक्रिप्ट करते हैं
- आरएसए, डिफी-हेलमैन और एलिप्टिक कर्व प्रणालियाँ एसिमेट्रिक हैं
2
HOW A DIGITAL SIGNATURE WORKSडिजिटल हस्ताक्षर कैसे काम करता है
A digital signature proves who sent a document, and that it was not altered. It uses asymmetric cryptography.
- The sender HASHES the document into a MESSAGE DIGEST
- The sender ENCRYPTS the digest with the sender's PRIVATE KEY. That is the signature, appended to the document
- You decrypt the signature with the sender's PUBLIC KEY to get digest H1
- You hash the document yourself to get H2. If H1 equals H2, the signature is valid
- It gives INTEGRITY, AUTHENTICITY and NON-REPUDIATION
- प्रेषक दस्तावेज को हैश करके मैसेज डाइजेस्ट बनाता है
- प्रेषक डाइजेस्ट को अपनी निजी कुंजी से एन्क्रिप्ट करता है। यही हस्ताक्षर है, जो दस्तावेज से जोड़ा जाता है
- आप प्रेषक की सार्वजनिक कुंजी से हस्ताक्षर डिक्रिप्ट करके डाइजेस्ट एच1 पाते हैं
- आप स्वयं दस्तावेज हैश करके एच2 पाते हैं। यदि एच1 और एच2 बराबर हों, तो हस्ताक्षर वैध है
- यह अखंडता, प्रामाणिकता और अस्वीकार्यता-रोध देता है
3
PKI AND THE CONTROLLER OF CERTIFYING AUTHORITIESपीकेआई और प्रमाणन प्राधिकारी नियंत्रक
PKI, PUBLIC KEY INFRASTRUCTURE, binds public keys to their owners through certificates.
- A REGISTRATION AUTHORITY verifies a person's identity and links it to the public key
- A CERTIFICATION AUTHORITY, CA, signs the person's public key and identity with its own private key
- A validation system confirms whether a certificate is still valid; revoked ones go on a CERTIFICATE REVOCATION LIST
- In India the CCA, CONTROLLER OF CERTIFYING AUTHORITIES, licenses CAs under section 21 of the IT Act
- The CCA runs the ROOT CERTIFYING AUTHORITY OF INDIA, RCAI, and the National Repository of Digital Certificates
- रजिस्ट्रेशन अथॉरिटी व्यक्ति की पहचान सत्यापित करके उसे सार्वजनिक कुंजी से जोड़ती है
- सर्टिफिकेशन अथॉरिटी, सीए, व्यक्ति की सार्वजनिक कुंजी और पहचान पर अपनी निजी कुंजी से हस्ताक्षर करती है
- सत्यापन प्रणाली पुष्टि करती है कि प्रमाणपत्र अब भी वैध है या नहीं; रद्द प्रमाणपत्र सर्टिफिकेट रिवोकेशन लिस्ट में जाते हैं
- भारत में सीसीए, अर्थात् प्रमाणन प्राधिकारी नियंत्रक, आईटी अधिनियम की धारा 21 के अंतर्गत सीए को लाइसेंस देता है
- सीसीए भारत का रूट प्रमाणन प्राधिकारी, आरसीएआई, और डिजिटल प्रमाणपत्रों का राष्ट्रीय भंडार चलाता है
4
DIGITAL SIGNATURE CERTIFICATESडिजिटल हस्ताक्षर प्रमाणपत्र
The PKI report lists four classes of certificate.
- CLASS 0: for demonstration and testing only
- CLASS 1: confirms your name and e-mail address; CLASS 2: checks your details against recognised consumer databases
- CLASS 3: high assurance, for e-commerce; issued only on your personal appearance before the CA
- A DSC carries your public key, name and e-mail, expiry date, serial number, and the CA's own digital signature
- An E-TOKEN is a USB device holding your DSC, safer than keeping it on the computer
- क्लास 0: केवल प्रदर्शन और परीक्षण के लिए
- क्लास 1: आपका नाम और ई-मेल पता पुष्ट करता है; क्लास 2: आपके विवरण मान्य उपभोक्ता डेटाबेसों से जाँचता है
- क्लास 3: उच्च आश्वासन, ई-कॉमर्स के लिए; केवल सीए के सामने आपकी व्यक्तिगत उपस्थिति पर जारी
- डीएससी में आपकी सार्वजनिक कुंजी, नाम और ई-मेल, समाप्ति तिथि, क्रम संख्या, और सीए का अपना डिजिटल हस्ताक्षर होता है
- ई-टोकन आपका डीएससी रखने वाला यूएसबी उपकरण है, जो उसे कंप्यूटर पर रखने से सुरक्षित है