Home > Ask the Security Experts > Network Security Questions & Answers > What are the alternatives to RC4 and symmetric cryptography systems?
Ask The Security Expert: Questions & Answers
EMAIL THIS

What are the alternatives to RC4 and symmetric cryptography systems?

Mike Chapple EXPERT RESPONSE FROM: Mike Chapple

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 11 April 2007
What's the best way to describe RC4 encryption? How does RC4 encryption compare to other encryption options?

>
EXPERT RESPONSE
RC4 is a symmetric cryptosystem, invented in 1987 by MIT cryptographer Ronald Rivest, who went on to found RSA Security. The algorithm has several known flaws, but it is still widely used.

In symmetric cryptosystems, such as RC4, communicating parties use the same shared secret key to both encrypt and decrypt the communication. For example, if Alice wants to send a private message to Bob, she would encrypt the message with a key (let's call it KAB) and then send the encrypted message to Bob. When Bob receives it, he would need to decrypt the message using the same algorithm (RC4) and the same key (KAB). The obvious disadvantage to this approach is that Alice and Bob must both already know KAB. In addition, a unique key is required for every pair of users that want to communicate. Key management issues quickly become intimidating for symmetric cryptosystems.

RC4 is also known to have several significant flaws in the way it constructs and uses keys. Therefore, most security professionals recommend using alternative symmetric algorithms. Two of the most commonly used ones are the Triple Data Encryption Standard (3DES) and the Advanced Encryption Standard (AES). Many programs that support RC4 also provide built-in support for 3DES and/or AES.

The alternative approach to symmetric encryption is public key (or asymmetric) cryptography, which assigns each user a pair of keys. Every individual has his or her own private key and his or her own public key. These keys are mathematically related in such a fashion that a message encrypted with one key of the pair can only be decrypted with the other key from the same pair. Returning to our example of Alice and Bob, Alice would encrypt the message with Bob's public key and then Bob would decrypt it using his own private key. The nature of asymmetric cryptography makes it possible for each user to freely share his or her public key with other users. The security of the system relies upon the secrecy of the private key. What's the catch? Asymmetric cryptography is generally much slower than symmetric cryptography.

More information:

  • Choose the right public key algorithm.
  • Before RSA Conference 2007, Senior News Writer Bill Brenner sat down with RSA Security CTO Dr. Burt Kaliski. Hear Burt's thoughts on the future of cryptography.


  • Sound Off! -   Be the first to post a message to Sound Off!


    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Network Security
    Will Cisco's plan to open access to the IOS improve network security?
    Will VoIP attacks result in more than just spam?
    Should enterprises implement a mandatory iPhone VPN?
    Will organizations that lag behind on IPv6 adoption have greater security risks?
    Should iPhone email be sent without SSL encryption?
    How to secure an FTP connection
    DMVPN configuration: Is an additional firewall needed between the router and the Internet?
    Is centralized logging worth all the effort?
    What are the pros and cons of shaping P2P packets?
    Should an ISP keep corrupted machines off of a network?

    Enterprise Data Protection
    Web 2.0 and e-discovery: Risks and countermeasures
    Screencast: Recovering lost data with WinHex
    Countermeasures against targeted attacks in the enterprise
    Websense, Reconnex top Forrester ranking of DLP vendors
    Are open recursive DNS servers inherently insecure?
    Penetration testing: Helping your compliance efforts
    Worst practices: Learning from bad security tips
    The ins and outs of database encryption
    RSA attendees see data classification, rights management projects stumble
    Worst practices: Encryption conniptions

    PKI and Digital Certificates
    What is the best way to administer exams to students via computer?
    Should computer exams be transmitted as PDF files or Word files?
    Should PKI systems be used for laptop encryption?
    Email authentication showdown: IP-based vs. signature-based
    VeriSign to shed businesses, return to security roots
    How do anonymous credentials and selective disclosure certificates affect enterprise IAM?
    Choosing from the top PKI products and vendors
    Can the symmetric encryption algorithm for S/MIME messages be changed?
    Securing VoIP Networks: Threats, Vulnerabilities and Countermeasures
    Creating a personal digital certificate
    PKI and Digital Certificates Research

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    cut-and-paste attack  (SearchSecurity.com)
    data splitting  (SearchSecurity.com)
    deperimeterization  (SearchSecurity.com)
    Google hacking  (SearchSecurity.com)
    masquerade  (SearchSecurity.com)
    snooping  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts