NEWS Breaking passwords in two and storing them in two places will make systems more secure, RSA Security said at its eponymous security show in San Francisco on Tuesday. The company also launched a framework for increased integration of its identity management products. RSA's Nightingale uses "secret-splitting", a cryptographic technique previously used in very high-end systems. A Nightingale server holds part of the password, which has been cryptographically split in two, according to a process invented by cryptographer Adi Shamir in the 1970s. The process has previously only been used in high-end bespoke systems for banking. "This is secret-splitting for the masses," said Burt Kaliski, chief scientist at RSA Security. The developers' kit will be available in June, aimed at early adopters. It will be used alongside smartcard systems, so that users' passwords, and the personal life secrets they give to the company to retrieve their password, are not accessible if the server's data store is accessed by a hacker. "The data store is a single place which, if compromised, defeats the whole system," said Kaliski. "With secret-splitting there is no single point of compromise." Nightingale is just the start of secret-splitting in RSA's products. Shamir's original paper suggested splitting secrets to several stores, so that, for instance, three out of five of them could reconstruct the secret. Nightingale simplifies the process to two. "So far, Nightingale is good for short secrets," said Kaliski. "It could be used for strong secrets such as a bank's signature key. There is a need now for weak secrets to be split effectively." Nightingale has been engineered to make no changes to the user experience, but companies may want to advertise that they are using it as a way to keep their customers' sensitive data more secure, RSA said. "Ecommerce sites want to be sure that their customers' order information does not fall into the wrong hands," said Kaliski, suggesting that regulations and the risk of lawsuits will force vendors to increase their protection. He said that a Nightingale brand might be created to identify sites where private data is split. Peter Judge writes for ZDNet UK
Split passwords make data safer
Secret-splitting = secret squirrel
Post your comment
In order to post a comment you need to be registered and logged in.
You can also log in with Facebook. Log in or create your silicon.com account below
Get silicon.com's daily newsletter
-

Enter your email to register
Featured white papers
-
Why is encryption important?
Data protection has become a hot topic, but where is the real threat and what can you do to protect your business? How...
-
CIO challenges: Bringing your iPad to work
The arrival of personal technology in the office is a challenge for all organisations. The technology is here, but not...
-
2012 Olympics: Is your business prepared?
Athletes prepare for all kinds of conditions and problems in competition. With the London-hosted Olympics fast...
Keep in touch with silicon.com
-
Connect with silicon.com on Facebook
Discuss the news of the day with the silicon.com team
-
Follow silicon.com on Twitter
Get regular updates from the silicon.com editors
-
Join the silicon.com LinkedIn networking group
Network with your peers and share expertise
Latest jobs
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
silicon.com newsletters
-
Stay up to date with silicon.com newsletters
Keep up with the latest news and analysis from silicon.com with our free email newsletters





