using digital certificates to secure sensitive communications at uw madison

20
Using Digital Certificates to Secure Sensitive Communications at UW-Madison WHOOHA Nicholas Davis – DoIT Middleware

Upload: nicholas-davis

Post on 21-Jun-2015

86 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Using Digital Certificates To Secure Sensitive Communications At Uw Madison

Using Digital Certificates to Secure Sensitive Communications at UW-Madison

WHOOHANicholas Davis – DoIT Middleware

Page 2: Using Digital Certificates To Secure Sensitive Communications At Uw Madison

Overview• Old business processes vs. new

business processes• Protecting your electronic identity• Email security• Digital certificates defined• What digital certificates can do for

your department• How digital certificates can help

your increase security• Questions• Next Steps

Page 3: Using Digital Certificates To Secure Sensitive Communications At Uw Madison

Old vs. New Business Processes• UW-Madison has

historically relied upon manual business processes

• Transcripts, HR Data, Contracts, Research Data, Health Information, Financial and Accounting Information—all kept on paper

• Physically secure• Difficult to access,

replicate and distribute

Page 4: Using Digital Certificates To Secure Sensitive Communications At Uw Madison

Old vs. New Business Processes

• As the amount of information we manage has increased, we have turned to electronic information systems to help us organize and disseminate information in a more efficient manner

Page 5: Using Digital Certificates To Secure Sensitive Communications At Uw Madison

Old vs. New Business Processes

• Today, we send official documents as email attachments

• We send email and documents to group mail lists

• Access to information is much greater than it was in the days of manual processes

• With new technologies there are new threats

Page 6: Using Digital Certificates To Secure Sensitive Communications At Uw Madison

Protecting Your Personal Identity

• When you send a document, how does the receiver know it came from you?

• When you send an electronic document, wouldn’t you want the same assurance?

Page 7: Using Digital Certificates To Secure Sensitive Communications At Uw Madison

Email Security

• How secure is the email you sent this morning?

• What happens to an email once you click the “send” button?

• Network, Intermediary Servers, Receiving Email Server, End User’s Workstation

• Laptops!

Page 8: Using Digital Certificates To Secure Sensitive Communications At Uw Madison

Digital Certificates Defined• A digital certificate is NOT a software

application• A digital certificate is an “electronic

passport”, with special added features

• Proves your identity• Allows you to protect your

information with encryption• Functionality already built into

existing applications on your compter

Page 9: Using Digital Certificates To Secure Sensitive Communications At Uw Madison

What Digital Certificates Can Do For Your Department

• Provide electronic equivalent of pen and paper signature

• Proves that the document (Word, Excel, PDF, Powerpoint) came from you

• Proves that the document has not been altered from origianl form

Page 10: Using Digital Certificates To Secure Sensitive Communications At Uw Madison

Example

Page 11: Using Digital Certificates To Secure Sensitive Communications At Uw Madison

Example

Page 12: Using Digital Certificates To Secure Sensitive Communications At Uw Madison

Encryption• Protects your email from being

read and/or altered from the moment it leaves your computer

• Simple as “click and send”• In order to receive encrypted

email, you must have a digital certificate

• In order to encryption to work bi-directionally, both users must have digital certificates

Page 13: Using Digital Certificates To Secure Sensitive Communications At Uw Madison

Example

Page 14: Using Digital Certificates To Secure Sensitive Communications At Uw Madison

If The Encrypted Email Is Intercepted

Page 15: Using Digital Certificates To Secure Sensitive Communications At Uw Madison

Uses

• Signing official documents (and email) to prove authorship

• Encrypting sensitive emails and attachments

Page 16: Using Digital Certificates To Secure Sensitive Communications At Uw Madison

Think About ThisCould cause harm in

a critical situationCase Scenario

Multiple hoax emails sent with Chancellor’s name and email. When real crisis arrives, people might not believe the warning.

It is all about trust!

Page 17: Using Digital Certificates To Secure Sensitive Communications At Uw Madison

Case Scenarios To Be Avoided

• HR related email concerning Nicholas Davis is intercepted by someone on the campus network and sent to newspaper

• Laptop containing spreadsheet with SSN’s of all UW faculty is stolen at Moscow airport.

Page 18: Using Digital Certificates To Secure Sensitive Communications At Uw Madison

The Technology Is Trustworthy

• X.509 is the industry standard

• Used by National Security Agency

• Used in all Western European passports

• Used by GE, Raytheon, J&J, P&G

Page 19: Using Digital Certificates To Secure Sensitive Communications At Uw Madison

The Technology Is Managed• DoIT generates, distributes,

supports and manages the digital certificate program

• Our certificates are provided by Verisign, the most widely trusted issuer of digital certificates

• We keep copies—just in case

Page 20: Using Digital Certificates To Secure Sensitive Communications At Uw Madison

Questions, Comments• Nicholas Davis• [email protected] (info)