Redirigiendo al acceso original de articulo en 16 segundos...
ARTÍCULO
TITULO

An Approach to Implement Cryptographic Protocol Version Downgrade Within a Secure Internal Network: TLS 1.x to SSL

Ganeshkumar S    
Elango Govindaraju    

Resumen

The end to end encryption of connections over the internet have evolved from SSL to TLS 1.3 over the years. Attacks have exposed vulnerabilities on each upgraded version of the cryptographic protocols used to secure connections over the internet. Organisations have to keep updating their web based applications to use the latest cryptographic protocol to ensure users are protected and feel comfortable using their web applications. But, the problem is that, web applications are not always standalone systems, there is usually a maze of systems that are integrated to provide services to the end user. The interactions between these systems happens within the controlled internal private network environment of the organisation. While only the front ending web application is visible to the end user. It is not often feasible to upgrade all internal systems to use the latest cryptographic protocol for internal interfaces/integration due to prohibitive cost of redevelopment and upgrades to infra and systems. Here we define an algorithm to setup internal & external firewalls to downgrade to a lower version of the cryptographic protocol (SSL) within the internal network for the integration/interfacing connections of internal systems while mandating the latest cryptographic protocol (TLS 1.x) for end user connections to the web application.

Palabras claves

 Artículos similares

       
 
Carlos Blanco, Antonio Santos-Olmo and Luis Enrique Sánchez    
As the Internet of Things (IoT) becomes more integral across diverse sectors, including healthcare, energy provision and industrial automation, the exposure to cyber vulnerabilities and potential attacks increases accordingly. Facing these challenges, th... ver más
Revista: Information

 
Carolina Ribeiro, Igor Fernandes and Filipe Portela    
In the age of Industry 4.0, competition between companies is becoming increasingly intense, and companies are turning to trends that aim to improve overall performance. Accordingly, the company ITEK decided to create a global gamification mechanism focus... ver más
Revista: Information

 
Sorin Zoican, Roxana Zoican, Dan Galatchi and Marius Vochin    
This paper illustrates a general framework in which a neural network application can be easily integrated and proposes a traffic forecasting approach that uses neural networks based on graphs. Neural networks based on graphs have the advantage of capturi... ver más
Revista: Applied Sciences

 
Gyurhan Nedzhibov    
Dynamic Mode Decomposition with Control is a powerful technique for analyzing and modeling complex dynamical systems under the influence of external control inputs. In this paper, we propose a novel approach to implement this technique that offers comput... ver más
Revista: Computation

 
Ruth S. Contreras-Espinosa and Jose Luis Eguia-Gomez    
Despite access to reliable information being essential for equal opportunities in our society, current school curricula only include some notions about media literacy in a limited context. Thus, it is necessary to create scenarios for reflection on and a... ver más
Revista: Computers