Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


November 10, 2003

All About GnuPG


RSS
View this exclusive article with VIP access -- click here to join |
See More Security Articles Here | Reprints | Or sign up for our VIP Monthly Pass!
Main Article    WinPT and GnuPG

Phil Zimmermann released the original pretty good privacy (PGP) program in 1991. Almost immediately, the US government filed a lawsuit to block the program's distribution but later withdrew the lawsuit. Because of the quality of its encryption, the US government considered the program munitions and thus permitted export of the program outside the United States with a permit only. By 1996, the Massachusetts Institute of Technology (MIT) was distributing a free version of the software within the United States, and a commercial version was available at http://www.pgp.com (http://www.pgpi.com for foreign parties). Because PGP uses RSA as a public-key algorithm and the patented International Data Encryption Algorithm (IDEA) as a symmetric algorithm, the software can't be distributed completely for free. (MIT's patent for RSA expired in September 2000, but the IDEA patent doesn't expire until 2011.)

The Gnu's Not UNIX (GNU) Privacy Guard (GnuPG) project uses only nonpatented, encumbered algorithms to emulate PGP functionality. The default algorithms are the digital signature algorithm (DSA, sometimes referred to as Digital Signature Standard—DSS) and the El Gamal algorithm (ELG), but GnuPG also supports other algorithms, including RSA. GnuPG uses two types of cryptographic algorithms: symmetric and asymmetric (also known as public-key cryptography). The former uses one key to scramble data and unscramble data. For years, Data Encryption Standard (DES) was the primary standard for symmetric cryptography, but in 2001, Advanced Encryption Standard (AES) superseded DES as the federal standard. For some time, many experts have considered standard DES to be cryptographically unsafe, so GnuPG can use AES and Triple DES (3DES), which is stronger than standard DES. The central problem with symmetric cryptography revolves around key distribution. Having only one key for both decryption and encryption means that the key must be passed back and forth between users, creating a security risk. Public-key cryptography solves this problem in an ingenious way. RSA and its descendents, such as DSA, use the concept of trap-door functions and primes. A trap-door function is one that's easy to compute one way but nearly impossible to reverse. For RSA, this computation is the product of two large prime numbers. Knowing one makes solving the other easy, but knowing neither makes solving either extremely difficult. (This explanation is a gross oversimplification but gives you a basic idea of how the math works.) . . .

Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
No Jobs, No Excitement at Apple's Last Macworld Keynote

Apple CEO Steve Jobs made the right move in skipping out on his company's last appearance at Macworld: In a Tuesday keynote address at the conference, Apple had no interesting new products to sell, opting instead to spend mind-numbing amounts of time on ...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

CES 2009: Ballmer Announces Windows 7, Windows Live, Live Search Milestones

During his first-ever Consumer Electronics Show (CES) 2009 keynote address last night in Las Vegas, Microsoft CEO Steve Ballmer announced the pending public availability of a feature-complete Windows 7, the final version of Windows Live Essentials, and ...


Security Whitepapers The Impact of Messaging and Web Threats

Why SaaS is the Right Solution for Log Management

Protecting (You and) Your Data with Exchange Server 2007

Related Events Security Summit

How IE7 & The New Extended Validation SSL Certificates Impact Your Site

Top 10 Email Security Challenges and Solutions

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2009 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing