Tuesday, July 31, 2012

Digital Signature / Electronic Signature / Digital Certificate

  • Gemini

Digital Signatures and Certificates: How They Work and Why You Need Them

Digital Signatures

A digital signature is a mathematical technique used to ensure the authenticity and integrity of digital data. It's like a handwritten signature in the digital world.

How it works:

    Key Generation: A pair of cryptographic keys is generated: a public key and a private key.
    Signing: The sender uses their private key to create a digital signature for the data.
    Verification: The recipient uses the sender's public key to verify the digital signature. If the verification is successful, it confirms that the data has not been altered and originates from the claimed sender

Digital Certificates

A digital certificate is an electronic document that verifies the identity of a person or entity. It's issued by a trusted third party called a Certificate Authority (CA).

How it works:

    Certificate Request: An individual or organization requests a digital certificate from a CA.
    Verification: The CA verifies the identity of the requester.
    Certificate Issuance: If the verification is successful, the CA issues a digital certificate containing the entity's public key and other relevant information.
    Distribution: The certificate is digitally signed by the CA and distributed to the entity.

Why Do We Need Them?

    Authentication: Verifies the identity of the sender.
    Integrity: Ensures that the data has not been tampered with.
    Non-repudiation: Prevents the sender from denying having sent the data.
    Confidentiality: While not directly providing confidentiality, digital signatures are often used in conjunction with encryption to protect data privacy.

Real-world applications:

    Secure email communication (S/MIME)
    Online banking and e-commerce
    Software distribution
    Secure website connections (HTTPS)

By using digital signatures and certificates, individuals and organizations can establish trust in the digital world and protect sensitive information.
  • explain the simple certificate enrollment protocol.

    The Simple Certificate Enrollment Protocol (SCEP) is a protocol used for issuing and managing digital certificates in a public key infrastructure (PKI) environment. SCEP is a lightweight protocol that allows for automated certificate enrollment and renewal, and it is widely used in enterprise environments.

    Here is a high-level overview of the SCEP process:

    1. Certificate Enrollment Request: The certificate enrollment process begins when a device or user sends a certificate enrollment request to the Certificate Authority (CA) using the SCEP protocol. The request typically includes information such as the subject name and public key of the certificate requester.

    2. CA Authorization: The CA will then validate the identity of the requester and determine whether they are authorized to receive a certificate. This may involve checking the requester's credentials or other identifying information.

    3. Certificate Issuance: If the requester is authorized to receive a certificate, the CA will issue a certificate to the requester. The certificate is typically encrypted with the requester's public key to ensure confidentiality.

    4. Certificate Delivery: The CA then delivers the certificate to the requester, typically over a secure channel such as HTTPS.

    5. Certificate Installation: The requester then installs the certificate on their device, completing the enrollment process.

    SCEP is designed to be a simple and lightweight protocol that can be easily implemented in a variety of environments. It is commonly used for certificate enrollment in enterprise environments, such as for mobile device management and VPN authentication.

  • explain automated certificate enrollment and renewal

Automated certificate enrollment and renewal is a process that allows digital certificates to be automatically issued and renewed by a Certificate Authority (CA) without the need for manual intervention from the certificate holder. This process is commonly used in public key infrastructure (PKI) environments to ensure that certificates are always up to date and to reduce the administrative burden of managing certificates.

The process typically works as follows:

  1. Certificate Enrollment: When a device or user needs a digital certificate, it sends a certificate enrollment request to the CA using a protocol such as SCEP or ACME. The request includes information such as the subject name and public key of the certificate requester.

  2. Certificate Issuance: If the requester is authorized to receive a certificate, the CA will issue a certificate and send it to the requester. The certificate is typically encrypted with the requester's public key to ensure confidentiality.

  3. Certificate Renewal: Before the certificate expires, the requester's device or application will automatically request a new certificate from the CA using the same protocol as the initial enrollment. The CA will validate the requester's identity and issue a new certificate to replace the expiring certificate.

Automated certificate enrollment and renewal allows for certificates to be issued and renewed quickly and efficiently, without the need for manual intervention. This reduces the risk of certificates expiring and causing disruptions to applications or services that rely on them. It also reduces the administrative burden of managing certificates, freeing up IT staff to focus on other tasks.

  • explain x.509 v3 certificate.

    An X.509 v3 certificate is a digital certificate that is used to authenticate the identity of a person, organization, or device on a computer network. The certificate contains information such as the name of the certificate holder, the certificate's public key, the certificate's digital signature, and the certificate's validity period.

    Here are some key components of an X.509 v3 certificate:

    1. Subject: The name of the certificate holder, which can be an individual or an organization.

    2. Public Key: The certificate holder's public key, which is used to encrypt and verify data.

    3. Certificate Authority (CA): The organization that issues the certificate and verifies the identity of the certificate holder.

    4. Digital Signature: A signature that is generated using the CA's private key to verify the authenticity of the certificate.

    5. Validity period: The period of time during which the certificate is valid.

    In addition to the above components, X.509 v3 certificates can also contain additional information such as extensions, which can provide further details about the certificate holder or the intended usage of the certificate.

    X.509 v3 certificates are commonly used for secure communication over the internet, including SSL/TLS encryption and digital signatures. They are also used for authentication in VPNs and other network services.


  • Digital Signatures



digital signing is a special process that is applied to an electronic document
this process is a code which is specific to the document thus the signature can not be copied to other documents
digital signatures require public and private key
we always keep our private key safe so that nobody can use it but we publish our public key to everyone we need to communicate
we sign document with our private key and the recipient uses our public key to verify that document is same as we send it.
if someone changes document then document will not validate.So your signature can't be copied while physical signature can be copied.
if someone else signs the document with another private key pretending to be you this can't work as your public key can't verify this document.




  • Digital Signatures



we digitally signs documents,messages,images etc
when we sign digitally we actually encrypts something with our privaye key
before encryption process what we want to digitally sign is applied to hashing procedure
when we sign a document hash is encrypted rather than document.
encrypted hash is called digital signature




  • Security+ Digital Signatures



primary purpose is authentication which means I want to know who sends document,to prevent someone to pretend to be someone else
message is hashed (provides integrity)
hash of message is encrypted with private key
encrypted hash can only be decrypted with public key



  • digital signature

A digital signature or digital signature scheme is a mathematical scheme for demonstrating the authenticity of a digital message or document
A valid digital signature gives a recipient reason to believe that the message was created by a known sender and that it was not altered in transit

http://en.wikipedia.org/wiki/Digital_Signature


A digital signature is used to verify a message. It is basically an encrypted hash of the message. The recipient can check if the message was tampered with by hashing the received message and comparing this value with the decrypted signature.


  • Digital Certificates - CompTIA Security+ SY0-301: 6.3



digital certificates are pulic key certificates that we use in browsers
Certificate Authority(CA) publishes digital certificate
PGP,open PGP




  • The basic difference is that it is impractical to separate a digital signature from the contents it signs whereas an electronic signature can be separated.


An electronic signature is any author identification and verification mechanism used in an electronic system. This could be a scan of your real hand-written signature or any kind of electronic authenticity stamp. It's a generic term that covers a lot of authenticity measures.

PDF creation software (e.g. Adobe Acrobat) has the ability to create both scanned hand-written signatures and cryptographic digital signatures. The OpenXML document (docx, xlsx, etc.) format also supports such signatures, so you should be able to produce similar results in Microsoft Office / OpenOffice

A digital signature is a type of electronic signature. It is a signature generated by a computer for a specific document, for the purposes of strong authenticity verification. For example, in asymmetric cryptography, a private key might be used to sign a hash of a document, which anyone in possession of the corresponding public key can verify but not forge. It also prevents modification of the document after the signature is generated. This allows one user to place a digital signature on a document, and many other users to verify that the signature is correct

http://security.stackexchange.com/questions/17554/what-is-the-difference-between-an-electronic-signature-and-a-digital-signature


  • "Electronic Signature" is a generic, technology-neutral term that refers to the universe of all of the various methods by which one can "sign" an electronic record. Although all electronic signatures are represented digitally (i.e., as a series of ones and zeroes), they can take many forms and can be created by many different technologies. Examples of electronic signatures include: a name typed at the end of an e-mail message by the sender; a digitized image of a handwritten signature that is attached to an electronic document (sometimes created via a biometrics-based technology called signature dynamics); a secret code or PIN to identify the sender to the recipient; a code or "handle" that the sender of a message uses to identify himself; a unique biometrics-based identifier, and a digital signature (created through the use of public key cryptography).


"Digital Signature" is simply a term for one technology-specific type of electronic signature. It involves the use of public key cryptography to "sign" a message and is perhaps the one type of electronic signature that has generated the most business and technical efforts in addition to legislative responses.

http://www.xyzmo.com/en/resource-center/Pages/DigitalSignatureFAQ.aspx



  • Electronic Signature

An electronic signature can be any piece of electronic data, such as a JPEG image of a signature or name, a sound recording, a symbol, or a voiceprint. An electronic signature can even be something as simple as a typed name.
they are problematic when it comes to security and integrity
electronic signatures are not considered a secure way of signing and are useful only in environments where signers are familiar with and in very close proximity to one another.


Digital Signature
A digital signature is a secure form of an electronic signature. In this way, digital signatures are a sub-group of electronic signatures, and they provide a signature and content integrity as well as non-repudiation of signed documents.

As opposed to an electronic signature, a digital signature cannot be copied, forged, or tampered with. This is because digital signatures are based on Public Key Infrastructure (PKI) technology, which, using a cryptographic operation, creates a ‘fingerprint’ unique to both the signer and the content. For this reason, a digital signature ensures signer authenticity and data integrity

http://www.arx.com/information/digital-electronic-signature/differences-electronic-and-digital-signatures.htm




  • U.S. legislation (ESIGN/UETA) defines an electronic signature as “an electronic sound, symbol, or process, attached to or logically associated with a contract or other record and executed or adopted by a person with the intent to sign the record”.

One of the most commonly used Electronic Signatures today is the Text Typed signature; text typed meaning that one has used a keyboard to type their name, with the intent to sign “something”.
 Although this is the most common, electronic signatures are not limited to this method.
 SmartSign allows businesses to have documents e-signed using other accepted methods such as voice, mouse, signature pads, iPad/iPhone (with your finger or stylus), smart-phones and the list goes on.
 What is important to note; an electronic signature can be applied almost by any means, but it is just the first step in a fully secure and compliant electronic signature process.

Digital signatures require the use of a digital certificate, essentially a type of key or code that utilizes cryptographic algorithms to assure the integrity and authenticity of electronic media, and the information within.
Put simply, the application uses an algorithm to generate a unique code by processing the source file. That unique code, think of it as a document’s fingerprint, is then encrypted using the private key stored in the digital certificate.
The result of all this processing is a secure document that is tampering evident.
If any value in the source document is corrupted or maliciously altered, it can be easily detected by verifying the original signature.




http://www.eoriginal.com/blog/index.php/2011/03/24/what-is-the-difference-between-an-electronic-and-digital-signature/




  • electronic signature

An electronic signature, or e-signature, is any electronic means that indicates either that a person adopts the contents of an electronic message, or more broadly that the person who claims to have written a message is the one who wrote it (and that the message received is the one that was sent).

http://en.wikipedia.org/wiki/Electronic_signature


  • A digital signature is used to verify a message.

It is basically an encrypted hash of the message.
The recipient can check if the message was tampered with by hashing the received message and comparing this value with the decrypted signature.
To decrypt the signature, the corresponding public key is required.
A digital certificate is used to bind public keys to persons or other entities
If there were no digital certificates, the digital signature could be easily be forged, as the recipient could not check if the public key belongs to the sender.
The digital certificate itself is signed by a trusted third party, a Certificate Authority(CA) like VeriSign

In cryptography, a public key certificate (also known as a digital certificate or identity certificate) is an electronic document which uses a digital signature to bind together a public key with identity information
such as the name of a person or an organization, their address, and so forth. The certificate can be used to verify that a public key belongs to an individual

http://stackoverflow.com/questions/2882506/what-is-the-difference-between-digital-signature-and-digital-certificate




Digital signature: Suppose Alice wants to send a signed document or message to Bob. The first step is generally to apply a hash function to the message, creating what is called a message digest. The message digest is usually considerably shorter than the original message. In fact, the job of the hash function is to take a message of arbitrary length and shrink it down to a fixed length. To create a digital signature, one usually signs (encrypts) the message digest as opposed to the message itself.

Alice sends Bob the encrypted message digest and the message, which she may or may not encrypt. In order for Bob to authenticate the signature, he must apply the same hash function as Alice to the message she sent him, decrypt the encrypted message digest using Alice's public key and compare the two. If the two are the same he has successfully authenticated the signature. If the two do not match there are a few possible explanations. Either someone is trying to impersonate Alice, the message itself has been altered since Alice signed it or an error occurred during transmission.

Digital certificate: In addition, someone could pretend to be Alice and sign documents with a key pair he claims is Alice's. To avoid scenarios such as this, there are digital documents called certificates that associate a person with a specific public key.

http://www.rsa.com/rsalabs/node.asp?id=2182

  • The Online Certificate Status Protocol (OCSP) is an Internet protocol used for obtaining the revocation status of an X.509 digital certificate

It was created as an alternative to certificate revocation lists (CRL), specifically addressing certain problems associated with using CRLs in a public key infrastructure (PKI).

Comparison to CRLs
Since an OCSP response contains less information than a typical certificate revocation list (CRL), it puts less burden on network and client resources
Since an OCSP response has less data to parse, the client-side libraries that handle it can be less complex than those that handle CRLs
OCSP discloses to the responder that a particular network host used a particular certificate at a particular time. OCSP does not mandate encryption, so other parties may intercept this information
https://en.wikipedia.org/wiki/Online_Certificate_Status_Protocol



  • OCSP overcomes the chief limitation of CRL: the fact that updates must be frequently downloaded to keep the list current at the client end. When a user attempts to access a server, OCSP sends a request for certificate status information. The server sends back a response of "current", "expired," or "unknown." The protocol specifies the syntax for communication between the server (which contains the certificate status) and the client application (which is informed of that status). OCSP allows users with expired certificates a grace period, so they can access servers for a limited time before renewing.

http://searchsecurity.techtarget.com/definition/OCSP


  • The Online Certificate Status Protocol (OCSP) is the protocol used by browsers to obtain the revocation status of a digital certificate attached to a website. Naturally OCSP speed is considered one of the main criteria for quality, as browsers reach out to webservers and confirm that the SSL certificate is valid.

http://www.symantec.com/connect/blogs/what-ocsp


  • What is a Code Signing Certificate?

A Code Signing Certificate is a digital certificate that contains information that fully identifies an entity and is issued by a Certificate Authority such as GlobalSign. The Digital Certificate binds the identity of an organization to a public key that is mathematically related to a private key pair. The use of private and public key systems is called Public Key Infrastructure (PKI).

Signing Code with a Code Signing Certificate
When a digital signature is applied, a timestamp is also recorded. This time‐stamping feature acts to ensure the signed code remains valid even after the digital certificate expires. Unless you’re adding additional code or making changes to the code, a new signature does not need to be applied (even if the digital certificate used to initially sign the code expires).

Code Signing Helps Prove
Content Source:
Code Signing identifies that the software or application is coming from a specific source (a developer or signer).
Content Integrity:
Code Signing ensures that a piece of code has not been altered and determines whether code is trustworthy for a specific purpose. If the application/ software code is tampered with or altered after digitally signing, the signature will appear invalid and untrusted.
https://www.globalsign.com/en/code-signing-certificate/what-is-code-signing-certificate/


Jack wants to send a document by email to Gill 
neither of them care if somebody reads it, there is nothing secret about it 
Gill wants to make sure document definitely came from Jack  and nobody else made changes to it on the way
"Software" prepares digital signature on Jack's computer
SHA-256 algorithm is used for hashing.
copy of document is processed with SHA-256 algorithm 
result is hash value(digest of the document)
hashing is one way process
hashing makes sure document's integrity
"Software" encrypts hash value using Jack's private key 
encrypted hash is embedded in the original document, now "signed document"
document now has a digital signature ,now "signed document"
Jacks sends Gill a copy of "signed document" and copy of public key 
Alternatively Jack can put public key on his website
Gill's computer decrpyts Jacks digital signature with public key 
If Gill can decrypt it then she knows it came from Jack
Gill's computer uses SHA-256 algorithm to calculate hash value again, using the text of document 
IF Gill computer's calculated hash value is the same as the hash value Jack sent, then Gill can be sure the document has not been tampered with since it was created.

  • In cryptography, X.509 is an International Telecommunication Union (ITU) standard defining the format of public key certificates.[1] X.509 certificates are used in many Internet protocols, including TLS/SSL, which is the basis for HTTPS,[2] the secure protocol for browsing the web. They are also used in offline applications, like electronic signatures.


In cryptography, a public key certificate, also known as a digital certificate or identity certificate, is an electronic document used to prove the validity of a public key.

The certificate includes information about the key, information about the identity of its owner (called the subject), and the digital signature of an entity that has verified the certificate's contents (called the issuer).

If the signature is valid, and the software examining the certificate trusts the issuer, then it can use that key to communicate securely with the certificate's subject 

In email encryption, code signing, and e-signature systems, a certificate's subject is typically a person or organization

However, in Transport Layer Security (TLS) a certificate's subject is typically a computer or other device, though TLS certificates may identify organizations or individuals in addition to their core role in identifying devices.
TLS, sometimes called by its older name Secure Sockets Layer (SSL), is notable for being a part of HTTPS, a protocol for securely browsing the web.

In a typical public-key infrastructure (PKI) scheme, the certificate issuer is a certificate authority (CA),[2] usually a company that charges customers to issue certificates for them

By contrast, in a web of trust scheme, individuals sign each other's keys directly, in a format that performs a similar function to a public key certificate.

The most common format for public key certificates is defined by X.509

Email certificate
In accordance with the S/MIME protocol, email certificates can both establish the message integrity and encrypt messages. To establish encrypted email communication, the communicating parties must have their digital certificates in advance. Each must send the other one digitally signed email and opt to import the sender's certificat
Some publicly trusted certificate authorities provide email certificates, but more commonly S/MIME is used when communicating within a given organization, and that organization runs its own CA, which is trusted by participants in that email system.

Self-signed and root certificates

A self-signed certificate is a certificate with a subject that matches its issuer, and a signature that can be verified by its own public key
For most purposes, such a self-signed certificate is worthless. However, the digital certificate chain of trust starts with a self-signed certificate, called a "root certificate," "trust anchor," or "trust root." A certificate authority self-signs a root certificate to be able to sign other certificates.

An intermediate certificate

An intermediate certificate has a similar purpose to the root certificate; its only use is to sign other certificate. However, an intermediate certificate is not self-signed. A root certificate or another intermediate certificate need to sign it.

end-entity or leaf certificate 
An end-entity or leaf certificate is any certificate that cannot sign other certificates. For instance, TLS/SSL server and client certificates, email certificates, code signing certificates, and qualified certificates are all end-entity certificates.

Code-signing certificate: Certificates can validate apps (or their binaries) to ensure they were not tampered with during delivery.

Subject: The entity a certificate belongs to: a machine, an individual, or an organization.
Issuer: The entity that verified the information and signed the certificate.

https://en.wikipedia.org/wiki/Public_key_certificate


  • Let's Encrypt is a non-profit certificate authority run by Internet Security Research Group (ISRG) that provides X.509 certificates for Transport Layer Security (TLS) encryption at no charge

https://en.wikipedia.org/wiki/Let%27s_Encrypt


  • In cryptography, X.509 is an International Telecommunication Union (ITU) standard defining the format of public key certificates.[1] X.509 certificates are used in many Internet protocols, including TLS/SSL, which is the basis for HTTPS,[2] the secure protocol for browsing the web. They are also used in offline applications, like electronic signatures.

An X.509 certificate binds an identity to a public key using a digital signature. A certificate contains an identity (a hostname, or an organization, or an individual) and a public key (RSA, DSA, ECDSA, ed25519, etc.), and is either signed by a certificate authority or is self-signed.

When a certificate is signed by a trusted certificate authority, or validated by other means, someone holding that certificate can use the public key it contains to establish secure communications with another party, or validate documents digitally signed by the corresponding private key.


End-entity certificate
This is an example of a decoded X.509 certificate that was used by wikipedia.org and several other Wikipedia websites. It was issued by GlobalSign, as stated in the Issuer field. Its Subject field describes Wikipedia as an organization, and its Subject Alternative Name (SAN) field for DNS describes the hostnames for which it could be used. The Subject Public Key Info field contains an ECDSA public key, while the signature at the bottom was generated by GlobalSign's RSA private key.

Intermediate certificate
This is an example of an intermediate certificate belonging to a certificate authority. This certificate signed the end-entity certificate above, and was signed by the root certificate below. Note that the subject field of this intermediate certificate matches the issuer field of the end-entity certificate that it signed. Also, the "subject key identifier" field in the intermediate matches the "authority key identifier" field in the end-entity certificate.

Root certificate
This is an example of a self-signed root certificate representing a certificate authority. Its issuer and subject fields are the same, and its signature can be validated with its own public key. Validation of the trust chain has to end here. If the validating program has this root certificate in its trust store, the end-entity certificate can be considered trusted for use in a TLS connection. Otherwise, the end-entity certificate is considered untrusted.

https://en.wikipedia.org/wiki/X.509

  • Applied to cryptography, the public and private key pair is used to encrypt and decrypt a message, ensuring both the identity of the sender and the security of the message itself. The most common use case of X.509-based PKI is Transport Layer Security (TLS)/Secure Socket Layer (SSL), which is the basis of the HTTPS protocol, which enables secure web browsing. But the X.509 protocol is also applied to code signing for application security, digital signatures, and other critical internet protocols.

The Benefits of X.509 Certificates

Trust - Digital certificates allow individuals, organizations, and even devices to establish trust in the digital world. As the foundation for all digital identities, X.509 certificates are everywhere and are essential to every connected process from websites to applications to endpoint devices and online documents

When a certificate is signed by a trusted CA, the certificate user can be confident that the certificate owner or hostname/domain has been validated, while self-signed certificates can be trusted to a lesser extent as the owner doesn't go through any additional validation before issuance.

Scalability - An additional benefit of this certificate-based approach to identity is scalability. The PKI architecture is so scalable that it can secure billions of messages exchanged daily by organizations over their own networks and across the internet. What enables this is that public keys can be distributed widely and openly without malicious actors being able to discover the private key required to decrypt the message

The Basis of Public Key Infrastructure
The public key is comprised of a string of random numbers and can be used to encrypt a message. Only the intended recipient can decipher and read this encrypted message and it can only be deciphered and read by using the associated private key, which is also made of a long string of random numbers. This private key is secret and is known only to the recipient. As the public key is published for all the world to see, public keys are created using a complex cryptographic algorithm to pair them with an associated private key by generating random numeric combinations of varying lengths so that they cannot be exploited through a brute force attack. The most common algorithms used to generate public keys are:

Rivest–Shamir–Adleman (RSA)
Elliptic curve cryptography (ECC)
Digital signature algorithm (DSA)

PKI Certificate Encoding
One notable element not defined in the X.509 standard is how the certificate contents should be encoded to be stored in files.

However, there are two encoding schemas commonly used to store digital certificates in files:

Distinguished Encoding Rules (DER) - most common, as the schema addresses most data objects. Certificates encoded by DER are binary files and cannot be read by text editors but can be processed by web browsers and many client applications.
Privacy Enhanced Mail (PEM) is an encrypted email encoding schema that can be used to convert DER-encoded certificates into text files.

Common Applications of X.509 Public Key Infrastructure

Web Server Security with TLS/SSL Certificates

Digital Signatures and Document Signing
Digital signatures are a specific type of electronic signature that leverages PKI to authenticate the identity of the signer and the integrity of the signature and the document. Digital signatures cannot be altered or duplicated in any way, as the signature is created by generating a hash, which is encrypted using a sender's private key. This cryptographic verification mathematically binds the signature to the original message to ensure that the sender is authenticated and the message itself has not been altered.

Code Signing
Code Signing enables application developers to add a layer of assurance by digitally signing applications, drivers, and software programs so that end users can verify that a third party has not altered or compromised the code they receive. To verify the code is safe and trusted, these digital certificates include the software developer's signature, the company name, and timestamping.

Email Certificates
S/MIME certificates validate email senders and encrypt email contents to protect against increasingly sophisticated social engineering and spear phishing attacks. By encrypting/decrypting email messages and attachments and by validating identity, S/MIME email certificates assure users that emails are authentic and unmodified.

SSH Keys
SSH keys are a form of X.509 certificate that provides a secure access credential used in the Secure Shell (SSH) protocol.
SSH keys not only improve security, but also enable the automation of connected processes, single sign-on (SSO), and identity and access management at the scale that today's businesses require.

Digital Identities
X.509 digital certificates also provide effective digital identity authentication. As data and applications expand beyond traditional networks to mobile devices, public clouds, private clouds, and Internet of Things devices, securing identities becomes more important than ever. And digital identities don't have to be restricted to devices; they can also be used to authenticate people, data, or applications. Digital identity certificates based on this standard enable organizations to improve security by replacing passwords, which attackers have become increasingly adept at stealing.

https://sectigo.com/resource-library/what-is-x509-certificate

transmission delay vs propagation delay



propagation delay means how much time your packet will take to reach from node A to node B,
and transmission delay means that how much time your packet will take to be transmitted at node B.

http://www.edaboard.com/thread91197.html

Propagation delay is how long it takes one bit to travel from one end of the "wire" to the other (it's proportional to the length of the wire)
Transmission delay is how long it takes to get all the bits into the wire (it's packet_length/data_rate).
http://stackoverflow.com/questions/17868153/propagation-delay-vs-trasmission-delay

Propagation delay


 propagation delay, which is the time after full message has been sent from the sender, until it has reached the receiving node
 The propagation speed depends on the physical medium of the link (that is, fiber optics, twisted-pair copper wire, etc.) and is in the range of  meters/sec for copper wires and  for wireless communication, which is equal to the speed of light

 Propagation time = Distance / propagation speed

 Example: Ethernet communicaiton over a UTP copper cable with maximum distance of 100 meter between computer and switching node results in:
Maximum link propagation delay ˜ 100 m / (200 000 000 m/s) = 0.5 µs

http://en.wikipedia.org/wiki/Transmission_time



  • Consider a network with a single 5 Mbps (megabits per second) link and a 15 ms (millisecond) propagation delay. 

The sender transmits a 3000-byte packet to a receiver.
Give all answers in units of milliseconds

What is the transmission delay for the packet?

 dtrans = L/R

 L = 3000 B = 24,000 b

 24,000 b * 1000 ms        24
           ----------   =  --- ms = 4.8 ms
           5,000,000 b      5
 
 
Assuming transmission begins at time 0, when will the first bit of the packet arrive at the receiver?

15 ms (this is the definition of propagation delay, which is given in the problem statement)

What is the total end-to-end delay for the packet, i.e., at what time does the entire packet reach the receiver?

 de2e = dtrans  + dprop
 de2e  = 4.8 ms + 15 ms = 19.8 ms

What is the total end-to-end delay for a 6000-byte packet?

 de2e = dtrans  + dprop

 dtrans = L/R

 L = 6000 B = 48,000 b

 48,000 b * 1000 ms        48
           ----------   =  --- ms = 9.6 ms
           5,000,000 b      5

 de2e = dtrans  + dprop
 de2e = 9.6 ms + 15 ms = 24.6 ms

 http://www.cs.odu.edu/~mweigle/CS312-F11/Quiz1

transmission time


the transmission time, is the amount of time from the beginning until the end of a message transmission.
In the case of a digital message, it is the time from the first bit until the last bit of a message has left the transmitting node.
The packet transmission time in seconds can be obtained from the packet size in bit and the bit rate in bit/s as:

Packet transmission time = Packet size / Bit rate

Example: Assuming 100 Mbit/s Ethernet, and the maximum packet size of 1526 bytes, results in

Maximum packet transmission time = 1526*8 bit / (100 000 000 bit/s) ˜ 122 µs


http://en.wikipedia.org/wiki/Transmission_time

Terms



  • Transmission delay

Amount of time transmitting data. Measured from when the first bit of data is pushed on the wire to the when last bit of data is pushed on the wire.


  • Propagation delay


Time a single bit spends traversing the link. Measured as how long it takes to travel the distance of the wire at approximately the speed of light.


  • Round-Trip Time (RTT)


Total time for a packet to reach destination and a response to return to the sender


  • Bandwidth (capacity)

Amount of data sent (or received) per unit time. Measured in bits/time.


  • transmission delay vs propagation delay
transmission delay

In a network based on packet switching, transmission delay (or store-and-forward delay) is the amount of time required to push all of the packet's bits into the wire. In other words, this is the delay caused by the data-rate of the link.
Transmission delay is a function of the packet's length and has nothing to do with the distance between the two nodes. This delay is proportional to the packet's length in bits,

propagation delay

The time required for a signal to pass through a given complete operating circuit
The time it takes to transmit a signal from one place to another. Propagation delay is dependent solely on distance and two thirds the speed of light

http://in.answers.yahoo.com/question/index?qid=20090218195707AA8qyoK

Propagation delay is how long it takes one bit to travel from one end of the "wire" to the other (it's proportional to the length of the wire, crudely).
Transmission delay is how long it takes to get all the bits into the wire in the first place (it's packet_length/data_rate).
http://stackoverflow.com/questions/17868153/propagation-delay-vs-trasmission-delay



Saturday, July 21, 2012

how to write a report



1-write down what you know
2-write down what you want to know
what you want to learn
do your research
3-write down what you have learnt

How to write a report - KWL (+audio).wmv
http://www.youtube.com/watch?v=TBmW-68WcpQ



integrating your thought with other thoughts which were already written in other papers
3 steps
1-research
2-analysis
3-integration

there's always a chance for revision,revisiting

How To Write Research Paper: Creative Writing Lessons & Tips: Writebynight
http://www.youtube.com/watch?v=0FPvQQQCUT8&feature=related


What's a report?
3 types

-information only reports
-research reports
-case study analysis reports

-information only reports
like management reports,stuff absenties report etc
generally very short and contains just data

-research reports
like product development report
generally reports at universities

-case study analysis reports
real life report in a confined environment

purpose
scope;what needs to be written in the report

features of well-written report

1-objectivity
don't include your opinions

2-thorough research

3-structure

4-clear wrtigin style

inductive vs deductive report?

report layout
-title page
-executive summary(abstract)
-table of contents
-introduction
context of report
general subject
describe the problem
define objectives



Report Writing
http://www.youtube.com/watch?v=AFGNKJruxdg&feature=related

Tuesday, July 17, 2012

Extract, transform and load (ETL)

Extract, transform and load (ETL) is a process in database usage and especially in data warehousing that involves:
Extracting data from outside sources
Transforming it to fit operational needs (which can include quality levels)
Loading it into the end target (database or data warehouse)

http://en.wikipedia.org/wiki/Extract,_transform,_load


  • SSSI (SQL Server Integration Services) Microsoft

Microsoft Integration Services is a platform for building high performance data integration solutions, including extraction, transformation, and load (ETL) packages for data warehousing

Integration Services includes graphical tools and wizards for building and debugging packages; tasks for performing workflow functions such as FTP operations, executing SQL statements, and sending e-mail messages; data sources and destinations for extracting and loading data; transformations for cleaning, aggregating, merging, and copying data; a management service
http://msdn.microsoft.com/en-us/library/ms169917(v=sql.105).aspx

Ad-Hoc Query


"ad hoc" reporting systems allow the users themselves to create specific, customized queries.
Typically this would be via a user-friendly GUI-based system without the need for the in-depth knowledge of SQL, or database schema that a programmer would have.
Because such reporting has the potential to severely degrade the performance of a live system, it is usually provided over a data warehouse.
Ad hoc querying/reporting is a business intelligence subtopic, along with OLAP, data warehousing, data mining and other tools.
http://en.wikipedia.org/wiki/Ad_hoc

An Ad-Hoc Query is a query that cannot be determined prior to the moment the query is issued.
It is created in order to get information when need arises and it consists of dynamically constructed SQL which is usually constructed by desktop-resident query tools.
http://www.learn.geekinterview.com/data-warehouse/dw-basics/what-is-an-ad-hoc-query.html

ERP , SCM, CRM


Information Technology (IT) departments for solutions to achieve greater efficiency and for business software to improve customer service

Business managers are always looking to compare the cost of IT solutions with the potential return on investment (ROI)


  • ERP, the Complete Business Solution

The biggest decision and most risky solution is that of an Enterprise Resource Planning system, or ERP.
This solution can be a complete replacement for all of the business software and procedures within the company by a single suite of programs that are specifically designed to efficiently manage assets and resources based around a comprehensive financial system
The benefit of ERP is having a single solution provider for everything from accounts through manufacturing and warehouse management to human resources.
Every package is linked to allow extensive business intelligence.




  • SCM for Efficient Management of the Supply Chain

Supply Chain Management as the "design, planning, execution, control, and monitoring of supply chain activities with the objective of creating net value, building a competitive infrastructure, leveraging worldwide logistics, synchronizing supply with demand, and measuring performance globally".



  • CRM, Customer Relationship Management

A CRM software solution provides a database where every piece of communication such as telephone call; email or direct conversation can be logged to ensure that promises can be met and leads can be efficiently followed.
This is especially important where a business has many customers or those that have a team of sale staff who may need to know the details of the last conversation.

http://suite101.com/article/erp-scm-crm-business-software-solutions-a275320

  • A CRM Without Boundaries

Vtiger CRM is considered the most powerful open source CRM solution
https://www.vtiger.com/open-source/

Data WareHouse Overview


-periodically updated,relatively static
-seperated from operational databases

building and maintaning datawarehouse tools

-dbms tool: oracle,teradata
-middleware tool:any ETL tool like informatica
-metadata tool:teradata metadata  repository
-warehouse administration tool:any database administration tool like oracle enterprise manager
-OLAP & Query tools:microstrategy,cognos


  • data warehouse
-a storage area for processed and integrated data across different sources
-operational and external data

-allows the users to extract data for business analysis and strategic decision making
-supports management decision making process
-stand-alone repository of information which is ingtegrated from several operational databases

  • DATA WAREHOUSING Basics

Tuesday, July 10, 2012

Characteristics of a software architect



Using the film industry as an analogy, the project manager is the producer (making sure things get done), whereas the architect is the director (making sure things get done correctly).

As the technical lead on the project, the characteristics and skills of the architect are typically broad, rather than deep

the architect is a technical leader, which means that, as well as having technical skills, the architect exhibits leadership qualities.
Leadership can be characterized in terms of both position in the organization and also in terms of the qualities that the architect exhibits.

the architect is the technical lead on the project and should have the authority to make technical decisions.
The project manager, on the other hand, is more concerned with managing the project plan in terms of resources, schedule, and cost

since the success of the architect is closely linked to the quality of the team, participation in interviewing new team members is also highly appropriate.

Successful architects are people-oriented, and every architect takes time to act as a mentor and coach to the members of their team.
"architect" refers to the role, which may be fulfilled by either an individual or a team.
If the architect role is to be fulfilled by a team, then it is important to have one individual who is considered the lead architect, who is responsible for owning the vision and can act as a single point of coordination across the architecture team

Good architects know their strengths and weaknesses
it is often the case that an architect is supported by a number of "trusted advisors."
Such architects acknowledge where they are weak and compensate for these weaknesses by either obtaining the necessary skills or working with other people to fill the gaps in their knowledge

Day-to-day, the development team will often look to the architect to tell them what to do and often how to do it

Therefore, a good architect will have a balance of software development knowledge and business domain knowledge

architects should have a certain level of programming skills, even if they do not necessarily write code.

Specifically, the architect should have effective language skills, including speaking, writing, and presentation abilities. Also, the communication is two-way. The architect should be a good listener and observer, as well as a good talker.

Communication with the project team is particularly important, since the architect is not simply responsible for conveying information to the team, but also for motivating them

An architect who is unable to make decisions in an environment where much is unknown, where there is insufficient time to explore all alternatives, and where there is pressure to deliver is unlikely to succeed. Such an environment is to be expected, and successful architects acknowledge the situation, rather than try to change it. Thus, the architect needs to be "thick-skinned" since they may need to correct their decisions and backtrack at times during a project

Successful architects are not geeks only concerned with technology.

http://www.ibm.com/developerworks/rational/library/mar06/eeles/










  • The role of the Software Architect

Build durable architectures (Independence with regard to API/framework providers)
Promote genericity and abstraction
Bridge between developers, project managers, and business experts
Often mixed culture (.NET/J2EE/opensource)

the role is often close to the role of a technical expert.
An architect is often an ex-developer who has accumulated such experience as to reach a good level in expertise.
Communication skills are required.
Diplomacy and pedagogy skills are also required to be able to explain architectures, debate about them and have them adopted
An architect must be able to step back and take a higher-level look, which is often difficult for developers and projects managers because they are often too focused on a specific project and so on immediate needs
This means raising from the application level to the information system level.
an architect must be able to quickly read and analyze code.
An architect doesn’t take part to a project only at its beginning, but during the whole project’s lifecycle to ensure a right implementation of the design and architecture.
"Architects are a lot slower in getting a solution, especially if the problem is simple!"

http://madgeek.com/Articles/Architect/EN/architect.htm

Duties, Skills, & Knowledge of a Software Architect


primary duties of a chief software architect, including

    duties of an architect
    skills of an architect
    knowledge required by an architect
    duties of an organization to its architects and   architecture-based development projects
   
   
    Duties:
    A good architect provides a development team with all of the tools they need to put together a great system.
    Review and improve on existing systems, making use of new technologies and methodologies to seek continual improvement for existing systems.
    Provide high level guidance and direction on project work, making sure tha new projects fit in with an overall strategic vision.
    Strong communication with both technical and business teams
    Some duties are common between them only difference is about orientation.
    In which Project Manager aligned more toward Client interaction, People, Time & cost management.
    An architect can be of any type based on organization structure and its hierarchy
    An Architect must be good learner as Software Industry changing trands frequently
    Provide guidance to others on how software should be built
    abstracts the complexity of a system into a manageable model
    Act as a consultant-strategist for everyone
    he may have to wear multiple hats - as a "manager" to co-ordinate with all stakeholders, as a salesman to "sell" the idea behind his solution, as a "developer" to develop POC or pilot to prove that his solution will work, as an "executive" to drive through the implementation.
   
   
   
   
    Skills:
    An architect must be technically competent and a strong communicator (written, verbal, presentation...).
    Ability to impart knowledge to others
   
   
    Software is the living codification of ideas, brought together to achieve economic benefits for society and ultimately to bring enjoyment to individuals. Similar to living entities, software is subject to the forces of evolution and change, and ultimately has a mortality unless adaptation and growth is maintained.
    The role of the chief software architect is understand, codify and communicate the forces of adaptation and change while maintaining the organizational balance between economic drivers and technical capabilities.
   
   
    http://www.sei.cmu.edu/architecture/research/previousresearch/duties.cfm
   

Are You a Software Architect?


There are a number of different qualities that you can look for in a software architect
and their past experience is often a good gauge of their ability to undertake the role.
you need to look deeper to understand the level of involvement, influence, leadership and responsibility that has been demonstrated across a number of different areas.


All you have to do is figure out what the requirements are and design a system that satisfies them
Broadly speaking, the software architecture on most projects can be broken down into two phases; the architecture is defined and then it's delivered.
Delivery of the software architecture
Definition of the software architecture



Definition of the software architecture
the architecture definition part of the role can be broken down further into a number of different elements



Management of non-functional requirements
Non-functional requirements need to be specific, measurable, achievable and testable if we are going to satisfy them
Sometimes the stakeholders will tell us that "the system must be fast", but that's far too subjective

Architecture definition:
It's fair to say that every software system has an architecture,
but not every software system has a defined architecture.
The architecture definition process lets you think about how you're going to take the requirements along with any imposed constraints and solve the problem.
Architecture definition is about introducing structure, guidelines, principles and leadership to the technical aspects of a software project
Defining architecture is your job as a software architect but there's a big difference between designing a software system from scratch and extending an existing one.

Technology selection:
it does have its fair set of challenges when you look at cost, licensing, vendor relationships, technology strategy, compatibility, interoperability, support, deployment, upgrade policies, end-user environments and so on.

Architecture evaluation:
an architecture works if it satisfies the non-functional requirements,
provides the necessary foundation for the rest of the code
and provides a sufficient platform for solving the underlying business problem
If you can test your architecture, then you can prove that it works. And if you can do this as early as possible, you can reduce the overall risk of project failure rather than simply hoping for the best.

Architecture collaboration:



Delivery of the software architecture

Ownership of the bigger picture:
sells the vision throughout the entirety of the software development lifecycle,
If you've defined an architecture, it makes sense to remain continually engaged and evolve your architecture rather than choosing to hand it off to an "implementation team".

Leadership:
Owning the bigger picture is one aspect of technical leadership
These include taking responsibility, providing technical guidance, making technical decisions and having the authority to make those decisions.

Coaching and mentoring:
While technical leadership is about steering the project as a whole, there are times when individuals need assistance
coaching and mentoring provides a way to enhance people's skills and to help them improve their own careers.
there's a big difference between coaching your team in architecture and design versus helping them with their coding problems.

Quality assurance:
From a software development perspective, these could include
coding standards,
design principles and source code analysis tools through to the use of continuous integration, automated unit testing and code coverage tools.


Design, development and testing:
The last thing that falls squarely within the role of a software architect is design, development and testing.
why shouldn't the day-to-day coding activities be a part of an architect's role?
the architect can experience the same pain as everybody else on the team, which in turn helps them better understand how their architecture is viewed from a development perspective.

Are you a software architect?
there's a high probability that those same developers are already undertaking parts of the software architecture role, irrespective of their job title.

http://www.infoq.com/articles/brown-are-you-a-software-architect/











Core Technical Requirements
Software architects must have a background in coding software using one or more programming languages.
This coding experience will be with complex and large-scale solutions in a team environment.

Soft Skills
The software architect must have excellent interpersonal skills

Issues during performance testing often require the architect to determine root cause and design a solution

http://www.ehow.com/list_6785106_software-architect-requirements.html#ixzz20ADaYwJX







Who is Right for the Architect Role?
Too frequently, "architect" is a promotion offered to top-notch developers in an effort to retain them
The best architects, then, are good technologists and command respect in the technical community, but also are good strategists, organizational politicians (in the best sense of the word), consultants and leaders.
http://www.bredemeyer.com/who.htm


Monday, July 9, 2012

online sql practices


Test your SQL Skills
http://www.w3schools.com/sql/sql_tryit.asp

sqlcourse
http://www.sqlcourse2.com/orderby.html

Java Performance



  • Intertech - Complete Java Performance Tuning Training - Part 1 

http://www.youtube.com/watch?v=YB2xvYCY4B8


  • Learn about JVM internals - what does the JVM do? 

http://www.youtube.com/watch?v=UwB0OSmkOtQ&feature=results_main&playnext=1&list=PLB18801A9A208A463


  • JVM Tuning & Troubleshooting - Türkçe - Gökhan Fazli Çelik - part 1 of 3 

http://www.youtube.com/watch?v=yUJRMwiEK0E



  • From Java code to Java heap

the memory overhead of putting an int value into an Integer object, the cost of object delegation, and the memory efficiency of the different collection types

http://www.ibm.com/developerworks/java/library/j-codetoheap/



quizes,tests,exams


CSC407H Exercises: Summer 2006
http://www.cdf.utoronto.ca/~csc407h/summer/exercises.shtml

course pages


CSC407H: Software Architecture -- Summer 2006
http://www.cdf.toronto.edu/~csc407h/summer/


CSC407 Software Architecture
Winter 2007
http://www.cdf.toronto.edu/~csc407h/winter/


CSC407 Software Architecture
Fall 2006
http://www.cdf.toronto.edu/~csc407h/fall/