My Account Log in

2 options

PKI security solutions for the enterprise : solving HIPAA, E-Paper Act, and other compliance issues / Kapil Raina.

Table of contents Available online

View online
LIBRA QA76.9.A25 R345 2003
Loading location information...

Available from offsite location This item is stored in our repository but can be checked out.

Log in to request item
Format:
Book
Author/Creator:
Raina, Kapil.
Language:
English
Subjects (All):
Public key infrastructure (Computer security).
Computer networks--Security measures.
Computer networks.
Electronic commerce--Security measures.
Electronic commerce.
Physical Description:
xxiii, 307 pages : illustrations ; 24 cm
Place of Publication:
Indianapolis, Ind : Wiley Pub., [2003]
Summary:
Do your customers have the confidence to do business over the Internet? By implementing Public Key Infrastructure (PKI) technologies, you'll be able to quickly gain their trust through secure transactions. This book provides you with a clear picture on using this technology in healthcare, financial, government, consumer, and other solutions verticals. Furthermore, the book highlights how you can meet domestic and international compliance regulations for corporate- and government-level standards on security and privacy. It focuses on examples and discusses practical implementation models for each vertical discussed. Included are strategies for developing a business case for PKI deployment. Numerous vendor and solution examples are also included so that you'll be able to choose the right combination for your PKI deployment.
Contents:
Part 1 Trust Basics: Ins and Outs of PKI 1
Trust in the Digital World 3
Implementing Trust 5
Trust Policies 6
Privacy 6
Proper Use of Information 6
Recourse in the Event of Breach of Trust 7
Continuity of Trust 8
User Consent 8
Trust Infrastructure 8
Physical Layer 9
System Layer 10
Application Layer 11
Trust Affiliations 12
Legal Issues with Trust in the Electronic World 14
Binding Trust with the Law 14
P3P 15
Digital Trust Solutions 16
Summary: The Need for Solutions 17
Chapter 2 Complexities of PKI 19
PKI: A Basis for Digital Trust 19
Why Is PKI So Complicated? 20
Security Issues 21
Privacy 22
Authentication 23
Integrity 24
Authorization 25
Nonrepudiation 26
Applications of PKI 27
XKMS 29
PKI Functions 29
Certificate Authority 30
Cross-Certification 32
Registration Authority 33
End-entity 35
Types of Certificates 35
Implementation Issues 37
Setup 37
Back-end Setup 38
User Setup and Registration 38
Certificate Policy and Certificate Practice Statement (CPS) 39
Administration 39
Renewal 40
Search 40
Exception Handling 41
Revocation 41
Escrow 42
Audience 43
Time Allotted for Rollout 43
Expertise Available 44
Funds Available 44
Integration Issues 44
Integration with Applications 45
Integration with Tthird-Party Data 45
Integration with Stronger Authentication Options 46
Integration with Legacy Systems 46
Integration with Single Interface 47
Cost 47
Summary: Best Practices to Reduce Complexity 49
Chapter 3 Best Practices of PKI 51
Insource versus Outsource Factors 51
Public and Private Hierarchies 52
Control and Flexibility 54
Cost and Deployment Time 54
Vendor and Technology Selection 55
Determining the Selection Criteria 55
Financial Strength 56
Scalability 56
Security 57
Operations 57
Support 58
Consulting Strength 59
Vendor Vetting: How to Ask the Right Questions 60
Scope of the Project 61
Project Organization and Management 62
Security Architecture 62
Security Policy 62
Standards and Security Design Guidelines 63
Operational Guidelines 64
Audit 64
Security Awareness and Training 65
Consultant Profiles 65
Project References 66
Design 66
Elements of a PKI Infrastructure 66
CA Hardware and Software Architecture 66
User Setup/Registration Definitions 67
Legal Policy Development 67
RA Agreement 69
RA-End-Entity Agreement 69
Subscriber-End-Entity Agreement 69
Best Practices for PKI Selection 70
Personnel 70
Secure Infrastructure 70
Legal Aspects 71
Deployment Time Frame 71
Costs 72
Implementation 72
Project Management 73
Resources Needed 73
Timelines 74
Summary: Choosing the Right Partner 80
Chapter 4 Selling PKI 81
ROI on PKI, ASAP 81
Reactive versus Proactive Selling Models 82
Success Criteria 83
Implementation ROI 84
Creating ROI Models 85
Cost Savings per Transaction 86
Reduced Processing Time per Transaction 88
New Services 90
Reduced Exposure Model 92
Regulation Compliance Model 93
Nonfinancial Benefits 94
FUD 94
Industry Peer Comparison 94
Vulnerability Assessment 95
Internal Surveys 96
Convenience 97
Case Study: Anatomy of a PKI Sale 98
The Prospect 98
The Pitch 98
The Closing 98
The Payment 98
The Delivery 99
Summary: It's All about the ROI 99
Part 2 Solutions for Trust 101
Chapter 5 Healthcare Solutions 103
HIPAA 103
PKI as a Solution to HIPAA 109
Biometrics and HIPAA 111
Biometrics Overview 111
Hospitals, Doctors, and Managed Care 116
Unique Security Requirements 116
Doctors' Requirements 116
Hospital Characteristics 118
Managed Care 118
Cost and Other Factors 119
Who Pays? 120
Summary: The Healthcare Prognosis 123
Chapter 6 Financial Solutions 125
Financial Sector 125
Consumer 125
Commercial 126
Legal Drivers 127
The Gramm-Leach-Bliley Act 127
Privacy 128
Security 129
Assessment of Risk 130
Control of Risk 130
Supervision of Service Provider Arrangements 131
Revisions of Guidelines 131
Reporting to the Board 131
Secure Wireless Communications under GLBA 132
Fair Credit Reporting Act 132
Electronic Fund Transfer 133
OnLine Mortgage and Loan Applications 134
Identrus 138
Need for Identrus 138
Architecture 139
Applications 142
Future of Identrus 142
Identrus Alternatives 142
Global Trust Authority 143
ABAecom 144
EMV Solutions 144
EU Directives 146
Directive 1999/93/EC 147
Directive 2000/31/EC 148
Safe Harbor Agreement 148
What Do All These Standards Mean for Me? 150
Summary: Money Talks 151
Chapter 7 Government Solutions 153
Types of Government Solutions 153
National Identity Projects 154
Technology Challenges 155
The Trust Factor 156
Citizen Identification Device 157
Terminal Readers 158
Government Regulations 158
E-government projects 158
U.S. Government Initiatives 159
Common Access Card 160
ACES 163
Legal Drivers 166
Paperwork Reduction Act (E-Paper Act) 166
Privacy Act 166
Federal Agency Protection of Privacy Act 167
Government Paperwork Elimination Act 167
Electronic Signatures in Global and National Commerce (E-Sign) Act 169
Federal Bridge Certification Authority 170
Meaning of Assurance 171
International Efforts 173
Australia 173
United Kingdom 175
India 176
Summary: Citizen Certificate 178
Chapter 8 Communications Solutions 179
Secure Messaging 179
Methods of Secure Communications 180
Encryption Point-to Point 180
Encryption with Insecure Pickup 182
Encryption with Secure Pickup 183
Instant Messaging 184
Peer to Peer 185
Guaranteed Delivery 186
Secure Drop-off and Pickup Model 187
Private Internet Network 187
Content Management 188
Policy Methods 189
Secured Delivery 191
Encapsulation 191
Secure Space 192
Time Stamping 192
SSL: The Old Standby 194
Challenges with SSL 194
Deployment Strategies 196
Dedicated SSL 196
Shared SSL 197
Server Appliance Model 197
Alternative Approach: OpenSSL 198
Code Signing 198
Summary: Speaking Digitally 200
Chapter 9 Other Solutions 201
Virtual Private Networks 201
What Is a VPN? 201
Why Do We Need Them? 202
Pros of VPNs 203
Cons of VPNs 203
How Do They Work? 203
Internet Key Exchange 205
Alternatives to IPSec VPNs? 207
Smart Cards 209
Novell Architecture 210
Token FOB 211
Kerberos 212
Took Kits 214
Microsoft 214
Xetex 214
Broadband 214
DOCSIS 216
PacketCable 220
CableHome 221
OpenCable 222
Euro-DOCSIS 223
PKI on a Chip 224
Integrated Security Chip 224
User Verification Manager 224
PKI Standards Support 225
Administrator Utility 225
File and Folder Protection 225
(VPN) Authentication 226
Intel's Solution 226
Other Applications 227
X-Bulk 227
Printers 228
Summary: PKI Is Far and Wide 229
Part 3 Trust Solutions Guide 231
Chapter 10 Overview of Trust Solutions 233
Consultant's Corner 233
Challenges 234
It's the Law! 234
Staying Current 235
Guide to Commercial Solutions by Category 235
VPN Solutions 235
Checkpoint 237
Nokia 237
Netscreen 237
SonicWall 237
Biometric Solutions 238
Device Vendors 238
Middleware Vendors 239
Form-Signing Solutions 239
Stand-Alone Form Signing 240
Hybrid 241
Core Technology 242
Secure Messaging 243
Solutions with End-User Clients 244
Solutions without End-User Clients 244
Miscellaneous Solutions 245
Secure Wireless Solutions 246
Certicom 247
Openwave 247
Diversinet 247
Single Sign-On Solutions 247
Integrated Solutions 249
Hybrid Solutions 250
Content Management Solutions 251
Probix 252
Alchemedia 252
Web Servers 253
Software Web Servers 254
Hardware (Appliance) Web Servers 255
Smart Cards 256
Gemplus 257
Schlumberger 257
Data Storage Protection 257
Brocade 257
Veritas 258
Web Portals 259
Plumtree 259
Hummingbird 259
B2B 259
Cyclone Commerce 260
webMethods 260
SET 260
IBM 260
VeriFone 261
Chapter 11 The Future of PKI 263
The Future of Mobile Security in PKI 264
Mobile VPNs 265
Lessening the Pain 266
Trends in Integration 266
Solution Building 267
Consolidation of the Security Market 267
Survey of the Security Market 268
Encryption 268
Authentication 269
Authorization 271
Administration 271
Firewalls and VPNs 272
Operational Integrity 273
Only the Strong Will Survive 274
One-Stop Shopping 274
PKI Is Only Part of the Solution 276
Need for Good Security Policies 277
Strong Audit Capability 278
Good Physical Security 278
Summary: The Growth of PKI 279.
Notes:
Includes index.
ISBN:
047131529X
OCLC:
51274617

The Penn Libraries is committed to describing library materials using current, accurate, and responsible language. If you discover outdated or inaccurate language, please fill out this feedback form to report it and suggest alternative language.

Find

Home Release notes

My Account

Shelf Request an item Bookmarks Fines and fees Settings

Guides

Using the Find catalog Using Articles+ Using your account