2 options
PKI security solutions for the enterprise : solving HIPAA, E-Paper Act, and other compliance issues / Kapil Raina.
Table of contents Available online
View onlineLIBRA QA76.9.A25 R345 2003
Available from offsite location
- Format:
- Book
- Author/Creator:
- Raina, Kapil.
- Language:
- English
- Subjects (All):
- Public key infrastructure (Computer security).
- Computer networks--Security measures.
- Computer networks.
- Electronic commerce--Security measures.
- Electronic commerce.
- Physical Description:
- xxiii, 307 pages : illustrations ; 24 cm
- Place of Publication:
- Indianapolis, Ind : Wiley Pub., [2003]
- Summary:
- Do your customers have the confidence to do business over the Internet? By implementing Public Key Infrastructure (PKI) technologies, you'll be able to quickly gain their trust through secure transactions. This book provides you with a clear picture on using this technology in healthcare, financial, government, consumer, and other solutions verticals. Furthermore, the book highlights how you can meet domestic and international compliance regulations for corporate- and government-level standards on security and privacy. It focuses on examples and discusses practical implementation models for each vertical discussed. Included are strategies for developing a business case for PKI deployment. Numerous vendor and solution examples are also included so that you'll be able to choose the right combination for your PKI deployment.
- Contents:
- Part 1 Trust Basics: Ins and Outs of PKI 1
- Trust in the Digital World 3
- Implementing Trust 5
- Trust Policies 6
- Privacy 6
- Proper Use of Information 6
- Recourse in the Event of Breach of Trust 7
- Continuity of Trust 8
- User Consent 8
- Trust Infrastructure 8
- Physical Layer 9
- System Layer 10
- Application Layer 11
- Trust Affiliations 12
- Legal Issues with Trust in the Electronic World 14
- Binding Trust with the Law 14
- P3P 15
- Digital Trust Solutions 16
- Summary: The Need for Solutions 17
- Chapter 2 Complexities of PKI 19
- PKI: A Basis for Digital Trust 19
- Why Is PKI So Complicated? 20
- Security Issues 21
- Privacy 22
- Authentication 23
- Integrity 24
- Authorization 25
- Nonrepudiation 26
- Applications of PKI 27
- XKMS 29
- PKI Functions 29
- Certificate Authority 30
- Cross-Certification 32
- Registration Authority 33
- End-entity 35
- Types of Certificates 35
- Implementation Issues 37
- Setup 37
- Back-end Setup 38
- User Setup and Registration 38
- Certificate Policy and Certificate Practice Statement (CPS) 39
- Administration 39
- Renewal 40
- Search 40
- Exception Handling 41
- Revocation 41
- Escrow 42
- Audience 43
- Time Allotted for Rollout 43
- Expertise Available 44
- Funds Available 44
- Integration Issues 44
- Integration with Applications 45
- Integration with Tthird-Party Data 45
- Integration with Stronger Authentication Options 46
- Integration with Legacy Systems 46
- Integration with Single Interface 47
- Cost 47
- Summary: Best Practices to Reduce Complexity 49
- Chapter 3 Best Practices of PKI 51
- Insource versus Outsource Factors 51
- Public and Private Hierarchies 52
- Control and Flexibility 54
- Cost and Deployment Time 54
- Vendor and Technology Selection 55
- Determining the Selection Criteria 55
- Financial Strength 56
- Scalability 56
- Security 57
- Operations 57
- Support 58
- Consulting Strength 59
- Vendor Vetting: How to Ask the Right Questions 60
- Scope of the Project 61
- Project Organization and Management 62
- Security Architecture 62
- Security Policy 62
- Standards and Security Design Guidelines 63
- Operational Guidelines 64
- Audit 64
- Security Awareness and Training 65
- Consultant Profiles 65
- Project References 66
- Design 66
- Elements of a PKI Infrastructure 66
- CA Hardware and Software Architecture 66
- User Setup/Registration Definitions 67
- Legal Policy Development 67
- RA Agreement 69
- RA-End-Entity Agreement 69
- Subscriber-End-Entity Agreement 69
- Best Practices for PKI Selection 70
- Personnel 70
- Secure Infrastructure 70
- Legal Aspects 71
- Deployment Time Frame 71
- Costs 72
- Implementation 72
- Project Management 73
- Resources Needed 73
- Timelines 74
- Summary: Choosing the Right Partner 80
- Chapter 4 Selling PKI 81
- ROI on PKI, ASAP 81
- Reactive versus Proactive Selling Models 82
- Success Criteria 83
- Implementation ROI 84
- Creating ROI Models 85
- Cost Savings per Transaction 86
- Reduced Processing Time per Transaction 88
- New Services 90
- Reduced Exposure Model 92
- Regulation Compliance Model 93
- Nonfinancial Benefits 94
- FUD 94
- Industry Peer Comparison 94
- Vulnerability Assessment 95
- Internal Surveys 96
- Convenience 97
- Case Study: Anatomy of a PKI Sale 98
- The Prospect 98
- The Pitch 98
- The Closing 98
- The Payment 98
- The Delivery 99
- Summary: It's All about the ROI 99
- Part 2 Solutions for Trust 101
- Chapter 5 Healthcare Solutions 103
- HIPAA 103
- PKI as a Solution to HIPAA 109
- Biometrics and HIPAA 111
- Biometrics Overview 111
- Hospitals, Doctors, and Managed Care 116
- Unique Security Requirements 116
- Doctors' Requirements 116
- Hospital Characteristics 118
- Managed Care 118
- Cost and Other Factors 119
- Who Pays? 120
- Summary: The Healthcare Prognosis 123
- Chapter 6 Financial Solutions 125
- Financial Sector 125
- Consumer 125
- Commercial 126
- Legal Drivers 127
- The Gramm-Leach-Bliley Act 127
- Privacy 128
- Security 129
- Assessment of Risk 130
- Control of Risk 130
- Supervision of Service Provider Arrangements 131
- Revisions of Guidelines 131
- Reporting to the Board 131
- Secure Wireless Communications under GLBA 132
- Fair Credit Reporting Act 132
- Electronic Fund Transfer 133
- OnLine Mortgage and Loan Applications 134
- Identrus 138
- Need for Identrus 138
- Architecture 139
- Applications 142
- Future of Identrus 142
- Identrus Alternatives 142
- Global Trust Authority 143
- ABAecom 144
- EMV Solutions 144
- EU Directives 146
- Directive 1999/93/EC 147
- Directive 2000/31/EC 148
- Safe Harbor Agreement 148
- What Do All These Standards Mean for Me? 150
- Summary: Money Talks 151
- Chapter 7 Government Solutions 153
- Types of Government Solutions 153
- National Identity Projects 154
- Technology Challenges 155
- The Trust Factor 156
- Citizen Identification Device 157
- Terminal Readers 158
- Government Regulations 158
- E-government projects 158
- U.S. Government Initiatives 159
- Common Access Card 160
- ACES 163
- Legal Drivers 166
- Paperwork Reduction Act (E-Paper Act) 166
- Privacy Act 166
- Federal Agency Protection of Privacy Act 167
- Government Paperwork Elimination Act 167
- Electronic Signatures in Global and National Commerce (E-Sign) Act 169
- Federal Bridge Certification Authority 170
- Meaning of Assurance 171
- International Efforts 173
- Australia 173
- United Kingdom 175
- India 176
- Summary: Citizen Certificate 178
- Chapter 8 Communications Solutions 179
- Secure Messaging 179
- Methods of Secure Communications 180
- Encryption Point-to Point 180
- Encryption with Insecure Pickup 182
- Encryption with Secure Pickup 183
- Instant Messaging 184
- Peer to Peer 185
- Guaranteed Delivery 186
- Secure Drop-off and Pickup Model 187
- Private Internet Network 187
- Content Management 188
- Policy Methods 189
- Secured Delivery 191
- Encapsulation 191
- Secure Space 192
- Time Stamping 192
- SSL: The Old Standby 194
- Challenges with SSL 194
- Deployment Strategies 196
- Dedicated SSL 196
- Shared SSL 197
- Server Appliance Model 197
- Alternative Approach: OpenSSL 198
- Code Signing 198
- Summary: Speaking Digitally 200
- Chapter 9 Other Solutions 201
- Virtual Private Networks 201
- What Is a VPN? 201
- Why Do We Need Them? 202
- Pros of VPNs 203
- Cons of VPNs 203
- How Do They Work? 203
- Internet Key Exchange 205
- Alternatives to IPSec VPNs? 207
- Smart Cards 209
- Novell Architecture 210
- Token FOB 211
- Kerberos 212
- Took Kits 214
- Microsoft 214
- Xetex 214
- Broadband 214
- DOCSIS 216
- PacketCable 220
- CableHome 221
- OpenCable 222
- Euro-DOCSIS 223
- PKI on a Chip 224
- Integrated Security Chip 224
- User Verification Manager 224
- PKI Standards Support 225
- Administrator Utility 225
- File and Folder Protection 225
- (VPN) Authentication 226
- Intel's Solution 226
- Other Applications 227
- X-Bulk 227
- Printers 228
- Summary: PKI Is Far and Wide 229
- Part 3 Trust Solutions Guide 231
- Chapter 10 Overview of Trust Solutions 233
- Consultant's Corner 233
- Challenges 234
- It's the Law! 234
- Staying Current 235
- Guide to Commercial Solutions by Category 235
- VPN Solutions 235
- Checkpoint 237
- Nokia 237
- Netscreen 237
- SonicWall 237
- Biometric Solutions 238
- Device Vendors 238
- Middleware Vendors 239
- Form-Signing Solutions 239
- Stand-Alone Form Signing 240
- Hybrid 241
- Core Technology 242
- Secure Messaging 243
- Solutions with End-User Clients 244
- Solutions without End-User Clients 244
- Miscellaneous Solutions 245
- Secure Wireless Solutions 246
- Certicom 247
- Openwave 247
- Diversinet 247
- Single Sign-On Solutions 247
- Integrated Solutions 249
- Hybrid Solutions 250
- Content Management Solutions 251
- Probix 252
- Alchemedia 252
- Web Servers 253
- Software Web Servers 254
- Hardware (Appliance) Web Servers 255
- Smart Cards 256
- Gemplus 257
- Schlumberger 257
- Data Storage Protection 257
- Brocade 257
- Veritas 258
- Web Portals 259
- Plumtree 259
- Hummingbird 259
- B2B 259
- Cyclone Commerce 260
- webMethods 260
- SET 260
- IBM 260
- VeriFone 261
- Chapter 11 The Future of PKI 263
- The Future of Mobile Security in PKI 264
- Mobile VPNs 265
- Lessening the Pain 266
- Trends in Integration 266
- Solution Building 267
- Consolidation of the Security Market 267
- Survey of the Security Market 268
- Encryption 268
- Authentication 269
- Authorization 271
- Administration 271
- Firewalls and VPNs 272
- Operational Integrity 273
- Only the Strong Will Survive 274
- One-Stop Shopping 274
- PKI Is Only Part of the Solution 276
- Need for Good Security Policies 277
- Strong Audit Capability 278
- Good Physical Security 278
- Summary: The Growth of PKI 279.
- Notes:
- Includes index.
- ISBN:
- 047131529X
- OCLC:
- 51274617
The Penn Libraries is committed to describing library materials using current, accurate, and responsible language. If you discover outdated or inaccurate language, please fill out this feedback form to report it and suggest alternative language.