Browse Definitions :
Definition

open security

Open security is an approach to safeguarding software, hardware and other information system components with methods whose design and details are publicly available.

Open security is based on the idea that systems should be inherently secure by design. That concept derives from Kerckhoff’s principle, which maintains that a Cryptographic system should be secure enough that, even if all its details but the key are available to the general public, the system will still be safe. The mathematician Claude Shannon further refined Kerckhoff’s principle. According to Shannon’s maxim, "one ought to design systems under the assumption that the enemy will immediately gain full familiarity with them."

An open cryptographic system includes algorithmic transparency. In such a system, the strength of a cryptographic implementation must be based on secrecy of the key. Keys are a fundamental element of cryptography, generated to encrypt and decrypt sensitive information.

One of the major challenges of cryptography is ensuring the secrecy of the keys, while ensuring that the authorized parties can access them at the appropriate time. Different levels of security may be sought, depending on the sensitivity of the message. A system is said to be computationally secure if it is theoretically breakable through a brute force attack but the time and expense required makes it not worth the effort. A system is said to be unconditionally or perfectly security exists when an attacker with unlimited resources still could not break it.

This was last updated in August 2015

Continue Reading About open security

SearchCompliance
  • ISO 31000 Risk Management

    The ISO 31000 Risk Management framework is an international standard that provides businesses with guidelines and principles for ...

  • pure risk

    Pure risk refers to risks that are beyond human control and result in a loss or no loss with no possibility of financial gain.

  • risk reporting

    Risk reporting is a method of identifying risks tied to or potentially impacting an organization's business processes.

SearchSecurity
  • Pretty Good Privacy (PGP)

    Pretty Good Privacy or PGP was a popular program used to encrypt and decrypt email over the internet, as well as authenticate ...

  • email security

    Email security is the process of ensuring the availability, integrity and authenticity of email communications by protecting ...

  • Blowfish

    Blowfish is a variable-length, symmetric, 64-bit block cipher.

SearchHealthIT
SearchDisasterRecovery
  • What is risk mitigation?

    Risk mitigation is a strategy to prepare for and lessen the effects of threats faced by a business.

  • fault-tolerant

    Fault-tolerant technology is a capability of a computer system, electronic system or network to deliver uninterrupted service, ...

  • synchronous replication

    Synchronous replication is the process of copying data over a storage area network, local area network or wide area network so ...

SearchStorage
  • direct access

    In computer storage, direct access is the process of reading and writing data on a storage device by going directly to where the ...

  • kibi, mebi, gibi, tebi, pebi and exbi

    Kibi, mebi, gibi, tebi, pebi and exbi are binary prefix multipliers that, in 1998, were approved as a standard by the ...

  • holographic storage (holostorage)

    Holographic storage is computer storage that uses laser beams to store computer-generated data in three dimensions.

Close