Search

Custom Search

Click Here

Showing posts with label Internet Technology. Show all posts
Showing posts with label Internet Technology. Show all posts

Thursday, June 12, 2008

Bluetooth Technology

Bluetooth Technology

"Automatic communication between various devices within a small area in a house or an office makes it possible to provide unique and innovative services to a professional worker or a small group of workers using portable devices. Bluetooth technology has this potential and is coming along fast and quick. It will replace clumsy wires, make information transfer automatic without synchronization cradles and introduce many new applications. Technology visionaries hope that it will do what infra red could not do over the past six years." - Editor


In an attempt to standardize data transfer and synchronization between disparate mobile devices in the short-distance range, Intel and Microsoft established in 1998 a major industry consortium that included IBM, Toshiba, Ericsson, Nokia, and Puma Technology. Code-named Blue Tooth for the 10th century Danish king who unified Denmark, the companies have created a single synchronization protocol to address end-user problems arising from the proliferation of various mobile devices -- including smart phones, smart pagers, PDAs, handheld PCs, copiers, printers, notebooks, and many future digital appliances at home -- that need to keep data consistent from one device to another. The proposed Bluetooth solutions (hardware and software-based) would automatically synchronize mobile devices when end-users enter their offices or home. Intel and others are designing the sending and receiving radio frequency chip sets. Price point for hardware is in $5-20 range eventually.
Since the start of this initiative in 1998, interest in Bluetooth has grown tremendously - signified by 1800 members of Bluetooth consortium by mid 2000.
While Bluetooth consortium demonstrated prototype products in the 1999-2000, there are no production-quality enduser products using blue tooth technology as of now, as far as we know. Component products (radios and chips) that can be integrated into finished products have started becoming available from Ericsson and others. However, here is an opportunity for more start-up companies. irDA is a competing technology and has been implemented in many products for over 6-7 years now but BlueTooth has a few distinct advantages - with Ericsson/Microsoft/Intel team behind it. In our opinion, there are relative benefits with several competing technologies - there is some overlap too. Let competitive products thrive so that we the users get the best solutions.

What is Bluetooth?

"Think of a connected world of electronic devices and appliances around you! You click on an icon for a device and you are linked to it, automatically and transparently"
Bluetooth technology eliminates the need for numerous and inconvenient cable attachments for connecting fixed computers, mobile phones, mobile computers, handheld devices, digital cameras and even new breed of digital appliances. It will enable users to connect a wide range of computing and telecommunications devices easily and simply, without the need to buy, carry, or connect cables - quite often proprietary to a specific device. It delivers opportunities for rapid ad hoc connections, and the possibility of automatic, unconscious, connections between devices. It creates the possibility of using mobile data in a variety of applications.
Bluetooth makes wireless communication and networking between devices in a small localized area of a room or a small office as easy as switching on the light. In Bluetooth all the connections between devices are instantaneous and invisible and the devices can talk even if they are not in line of sight because Bluetooth utilizes a radio-based link. Your laptop could send information to a printer in the next room, or your microwave could send a message to your mobile phone telling you that your meal is ready.
Bluetooth is actually a standard for wireless communications between devices in a personal area network (PAN) using radio frequency for a short range (around 10 meters). So any two devices that follow the standard can communicate and exchange data between each other without the need of any connection to be made between them. A group of Bluetooth devices like a mobile phone, a digital camera, a hand held device etc. can instantly form a network with each other as soon as they are switched on. You could have a mobile phone in your pocket and you could be sending e-mails using your laptop without making any connection between your laptop and the mobile. Your refrigerator could be placing an order with the supermarket if your milk supply has been exhausted using your mobile phone.
Briefly, Bluetooth technology

uses radio waves in 2.4 GHz band - therefore, no line of sight is required
supports multipoint, not just point to point
works in a small confined area - 10 to 15 meters apart
is able to support speeds of 1-2 Mbps today but will offer higher speeds in future
chip sets are relatively inexpensive (though more expensive than IrDA)- $10 to $20 today in large quantities - will go down in future
has significant industry support with over 1800 members in the industry consortium

How Bluetooth Technology Works

"Connective convenience"

Bluetooth is a high-speed, low-power microwave wireless link technology, designed to connect phones, laptops, PDAs and other portable equipment together with little or no work by the user. Unlike infra-red, Bluetooth does not require line-of-sight positioning of connected units. The technology uses modifications of existing wireless LAN techniques but is most notable for its small size and low cost. The current prototype circuits are contained on a circuit board 0.9cm square, with a much smaller single chip version in development. The cost of the device is expected to fall very fast, from $20 initially to $5 in a year or two. It is envisioned that Bluetooth will be included within equipment rather than being an optional extra. When one Bluetooth product comes within range of another, (this can be set to between 10cm and 100m) they automatically exchange address and capability details. They can then establish a 1 megabit/s link (up to 2 Mbps in the second generation of the technology) with security and error correction, to use as required. The protocols will handle both voice and data, with a very flexible network topography.

This technology achieves its goal by embedding tiny, inexpensive, short-range transceivers into the electronic devices that are available today. The radio operates on the globally-available unlicensed radio band, 2.45 GHz (meaning there will be no hindrance for international travelers using Bluetooth-enabled equipment.), and supports data speeds of up to 721 Kbps, as well as three voice channels. The bluetooth modules can be either built into electronic devices or used as an adaptor. For instance in a PC they can be built in as a PC card or externally attached via the USB port.



Each device has a unique 48-bit address from the IEEE 802 standard. Connections can be point-to-point or multipoint. The maximum range is 10 meters but can be extended to 100 meters by increasing the power. Bluetooth devices are protected from radio interference by changing their frequencies arbitrarily upto a maximum of 1600 times a second, a technique known as frequency hopping. They also use three different but complimentary error correction schemes. Built-in encryption and verification is provided.
Moreover, Bluetooth devices won't drain precious battery life. The Bluetooth specification targets power consumption of the device from a "hold" mode consuming 30 micro amps to the active transmitting range of 8-30 milliamps (or less than 1/10th of a watt). The radio chip consumers only 0.3mA in standby mode, which is less than 3 % of the power used by a standard mobile phone. The chips also have excellent power-saving features, as they will automatically shift to a low-power mode as soon as traffic volume lessens or stops.
Bluetooth devices are classified according to three different power classes, as shown in the following table.
Power Class Maximum Output Power
1 100 mW (20 dBm)
2 2.5 mW (4 dBm)
3 1 mW (0 dBm)
But beyond untethering devices by replacing the cables, Bluetooth radio technology provides a universal bridge to existing data networks, a peripheral interface, and a mechanism to form small private ad hoc groupings of connected devices away from fixed network infrastructures. Designed to operate in a noisy radio frequency environment, the Bluetooth radio uses a fast acknowledgment and frequency hopping scheme to make the link robust. Bluetooth radio modules avoid interference from other signals by hopping to a new frequency after transmitting or receiving a packet. Compared with other systems operating in the same frequency band, the Bluetooth radio typically hops faster and uses shorter packets. This makes the Bluetooth radio more robust than other systems. Short packages and fast hopping also limit the impact of domestic and professional microwave ovens. Use of Forward Error Correction (FEC) limits the impact of random noise on long-distance links. The encoding is optimized for an uncoordinated environment.


Bluetooth guarantees security at the bit level. Authentication is controlled by the user by using a 128 bit key. Radio signals can be coded with 8 bits or anything upto 128 bits. The Bluetooth radio transmissions will conform to the safety standards required by the countries where the technology will be used with respect to the affects of radio transmissions on the human body. Emissions from Bluetooth enabled devices will be no greater than emissions from industry-standard cordless phones. The Bluetooth module will not interfere or cause harm to public or private telecommunications network.


The Bluetooth baseband protocol is a combination of circuit and packet switching. Slots can be reserved for synchronous packets. Each packet is transmitted in a different hop frequency. A packet nominally covers a single slot, but can be extended to cover up to five slots. Bluetooth can support an asynchronous data channel, up to three simultaneous synchronous voice channels, or a channel, which simultaneously supports asynchronous data and synchronous voice. It is thus possible to transfer the date asynchronously whilst at the same time talking synchronously at the same time. Each voice channel supports 64 kb/s synchronous (voice) link. The asynchronous channel can support an asymmetric link of maximally 721 kb/s in either direction while permitting 57.6 kb/s in the return direction, or a 432.6 kb/s symmetric link.

Modes of operation

An interesting aspect of the technology is the instant formation of networks once the bluetooth devices come in range to each other. A piconet is a collection of devices connected via Bluetooth technology in an ad hoc fashion. A Piconet can be a simple connection between two devices or more than two devices. Multiple independent and non-synchronized piconets can form a scatternet. Any of the devices in a piconet can also be a member of another by means of time multiplexing. i.e a device can be a part of more than one piconet by suitably sharing the time. The Bluetooth system supports both point-to-point and point-to-multi-point connections. When a device is connected to another device it is a point to point connection. If it is connected to more that one (upto 7 ) it is a point to multipoint connection. Several piconets can be established and linked together ad hoc, where each piconet is identified by a different frequency hopping sequence. All users participating on the same piconet are synchronized to this hopping sequence. If a device is connected to more than one piconet it communicates in each piconet using a different hopping sequence. A piconet starts with two connected devices, such as a portable PC and cellular phone, and may grow to eight connected devices. All Bluetooth devices are peer units and have identical implementations. However, when establishing a piconet, one unit will act as a master and the other(s) as slave(s) for the duration of the piconet connection. In a piconet there is a master unit whose clock and hopping sequence are used to synchronize all other devices in the piconet. All the other devices in a piconet that are not the master are slave units. A 3-bit MAC address is used to distinguish between units participating in the piconet. Devices synchronized to a piconet can enter power-saving modes called Sniff and hold mode, in which device activity is lowered. Also there can be parked units which are synchronized but do not have a MAC addresses. These parked units have a 8 bit address, therefore there can be a maximum of 256 parked devices.


Voice channels use either a 64 kbps log PCM or the Continuous Variable Slope Delta Modulation (CVSD) voice coding scheme, and never retransmit voice packets. The voice quality on the line interface should be better than or equal to the 64 kbps log PCM. The CVSD method was chosen for its robustness in handling dropped and damaged voice samples. Rising interference levels are experienced as increased background noise: even at bit error rates up 4%, the CVSD coded voice is quite audible.

Sunday, February 10, 2008

Internet


Internet
The global TCP/IP public internetwork that originated in the ARPANET project of the U.S. Department of Defense in the 1970s. The original purpose of ARPANET was to create a wide area network (WAN) that would allow researchers at various defense and civilian research agencies to communicate with each other and to collaborate on projects. When ARPANET grew larger and an increasing number of civilian agencies such as universities and networking companies wanted access to it, administration of the network (now called the Internet) was given to the National Science Foundation (NSF) and then to Internet Network Information Center (InterNIC).

The backbone networks that make up the Internet are owned and managed by private companies, including MCI WorldCom and Sprint. These companies often share physical lines and often lease lines from Regional Bell Operating Companies (RBOCs). Backbone lines on the Internet are linked at points called Network Access Points (NAPs), where Internet service providers (ISPs) can exchange traffic. Examples of NAPs include MCI WorldCom’s "MAE West" NAP in San Jose, California, and the company’s "MAE East" NAP in Washington, D.C. An ISP leases a point of presence (POP) connection to a backbone’s network in order to supply individual users and companies with Internet services. See the Web link in this entry for topological and descriptive views of the architecture of the Internet.

The Internet is not owned by any one group; it is a collection of networks and gateways that run a common TCP/IP protocol and that all evolved from ARPANET. Nevertheless, various administrative bodies oversee various aspects of the Internet. These groups include the following:

· Internet Society (ISOC), which coordinates a number of other bodies and gives advice and direction to them.
· Internet Architecture Board (IAB), which is responsible to the ISOC and oversees the architecture of the Internet.
· Internet Engineering Task Force (IETF), which is responsible to the IAB and develops Internet protocols that define the TCP/IP protocol suite, the Domain Name System (DNS), and so on.
· Internet Assigned Numbers Authority (IANA), which is soon to be replaced by the Internet Corporation for Assigned Names and Numbers (ICANN). IANA is responsible for coordinating the registration of DNS names and assigning IP addresses.
Although a large number of Internet protocols currently support applications for users of the Internet, these services are constantly evolving, and many are rapidly disappearing as new services emerge. By far the most popular business uses of the Internet are the World Wide Web (WWW) and e-mail. Usenet newsgroups and Internet Relay Chat (IRC) are also popular.

Internet protocols
A term that generally refers to application-layer TCP/IP protocols commonly used over the Internet. The following table shows many of the standard Internet protocols in use today. Some of these protocols, such as Gopher, are rapidly waning in popularity. To access a protocol such as Hypertext Transfer Protocol (HTTP) with a Web browser such as Microsoft Internet Explorer, you would use a Uniform Resource Locator (URL) beginning with http://
Standard Internet Protocols
Protocol
Protocol Name
Description
http
Hypertext Transfer Protocol
Used for Web pages that contain text, graphics, sound, and other digital information stored on a Web server on the World Wide Web
ftp
File Transfer Protocol
Transfers files between two computers over the Internet
gopher
Gopher protocol
Displays information stored on a network of Gopher servers
wais
WAIS protocol
Used for accessing a Wide Area Information Servers database
file
File protocol
Opens a file on a local hard disk or a network share
https
Secure Hypertext Transfer Protocol
Establishes an encrypted HTTP connection using the Secure Sockets Layer (SSL) protocol
mailto
MailTo protocol
Starts a Simple Mail Transfer Protocol (SMTP) e-mail program to send a message to the specified Internet e-mail address
news
News protocol
Opens a Network News Transfer Protocol (NNTP) newsreader and the specified Usenet newsgroup
nntp
Network News Transfer Protocol
Performs the same function as the News protocol
mid
Musical Instrument Digital Interface (MIDI) protocol
Plays MIDI sequencer files if the computer has a sound card
telnet
Telnet protocol
Starts a Telnet terminal emulation program
rlogin
Rlogin protocol
Starts an Rlogin terminal emulation program
tn3270
TN3270 protocol
Starts a TN3270 terminal emulation program
pnm
RealAudio protocol
Plays RealAudio streaming audio from a RealAudio server
mms
Microsoft Media Server (MMS) protocol
Plays .asf streams from a Microsoft NetShow server

Secure attention sequence (SAS)

The secure attention sequence (SAS) offers protection against Trojan horse programs that masquerade as common system applications. For example, it is impossible to write a Trojan horse program that presents the user with a phony Windows Security dialog box in an attempt to steal a user’s credentials, because this program cannot be activated by the SAS. The most that a hacker can do is write a Trojan horse program that displays a Windows Security dialog box at random times while the user is already logged on. To guard against such an event, you should educate users to always use the SAS keystroke sequence even if the computer they are using already displays what appears to be the Windows Security dialog box.
The SAS also kills any logon scripts that are running and can be used to terminate scripts that have stopped responding.

Secure Hypertext Transfer Protocol (S-HTTP)
An Internet protocol for encryption of Hypertext Transfer Protocol (HTTP) traffic. Secure Hypertext Transfer Protocol (S-HTTP) is an application-level protocol that extends the HTTP protocol by adding encryption to Web pages. It also provides mechanisms for authentication and signatures of messages. S-HTTP provides broad support for implementing different types of cryptographic algorithms and key management systems. Although S-HTTP systems can make use of digital certificates and public keys, messages can also be encrypted on a per-transaction basis using symmetric session keys.

Secure/Multipurpose Internet Mail Extensions (S/MIME)

A protocol for the secure exchange of e-mail and attached documents originally developed by RSA Security. Secure/Multipurpose Internet Mail Extensions (S/MIME) adds security to Internet e-mail based on the Simple Mail Transfer Protocol (SMTP) method and adds support for digital signatures and encryption to SMTP mail to support authentication of the sender and privacy of the communication. Note that because HTTP messages can transport MIME data, they can also use S/MIME.

Secure Sockets Layer (SSL)
A handshaking protocol for communication over the Internet that provides secure authentication and data encryption. Secure Sockets Layer (SSL) was developed by Netscape Communications for the secure transmission of information over the Internet. SSL works between the application and transport layers on a TCP/IP host to provide encryption of data for data security and encryption of user credentials for secure authentication. SSL uses the Rivest-Shamir-Adleman (RSA) public key cryptography method and is dependent on the implementation of digital certificates and a supporting public key infrastructure (PKI). Both the client and the server must support SSL. Because SSL is application independent, it can be used to encrypt data transmission for many application-layer Internet protocols, including Hypertext Transfer Protocol (HTTP), Simple Mail Transfer Protocol (SMTP), and Network News Transfer Protocol (NNTP).

Security Account Manager (SAM) database

The database of user and group account information stored on a domain controller in a Microsoft Windows NT–based network. The Security Account Manager (SAM) database is also known as the domain directory database, or sometimes simply the directory database.
The SAM database occupies a portion of the Windows NT registry. All user accounts, group accounts, and resource definitions such as shares and printers have their security principals defined in the SAM database. Because the entire SAM database must reside in a domain controller’s RAM, it cannot exceed about 40 MB in Windows NT, which works out to about 40,000 user accounts, or 26,000 users and Windows NT workstations combined. (The following table lists the size of common objects in a SAM database.)

Security Administrator Tool for Analyzing Networks (SATAN)

A free tool developed by Dan Farmer and Wietse Venema in 1995 for remotely analyzing the security of networks. Security Administrator Tool for Analyzing Networks (SATAN) consists of a variety of routines that probe a network for security holes in a similar way that hackers do. SATAN tests the vulnerabilities of TCP/IP hosts using common TCP/IP protocols, such as File Transfer Protocol (FTP), Network File System (NFS), and Network Information System (NIS), and analyzes how the host responds to requests based on these protocols. The results are stored in a database and can be displayed using a Web browser.
SATAN runs on machines running UNIX and needs the Perl interpreter to operate. Typically, SATAN identifies weaknesses in the setup and configuration of network software; network administrators can use it to check the configuration of their network software. SATAN can also identify the network services that are running and provide information about the types of hardware and software and the topology of the network.

Security descriptor

A unique header for an object stored in Active Directory of Microsoft Windows 2000. Security descriptors contain security identifiers (SIDs), which are discretionary access control lists (DACLs) or system access control lists (SACLs) that specify the access permissions for the object. Specifically, the security descriptor for an object contains the following:
· The owner SID:
Identifies the security principal (the owner of the object)
· The group SID:
Used only by Services for Macintosh and the POSIX subsystem
· The DACL:
Contains the access permissions and rights for the object and its attributes, along with the SIDs of the security principals who can access the object
· The SACL:
Contains system-wide security policies such as the auditing policy

Security group
One of two types of groups in Microsoft Windows 2000 that are created and stored in Active Directory; the other is distribution groups. Security groups are used for grouping accounts and for controlling access to resources, much in the same way that global groups and local groups are used in Microsoft Windows NT–based networks. (In other words, all groups in Windows NT are security groups.) Security groups are security principals that can contain other security principals such as user, group, and computer objects from Active Directory.
Security groups come in three types:
· Domain local groups:
Provide users with permissions to access resources; used only within the specific domain in which they are created
· Global groups:
Logically group users for administrative purposes and have visibility in the current domain and trusted domains
· Universal groups:
Similar to global groups but reduce global catalog replication traffic when they are used

Security identifier (SID)

An internal number in the Security Account Manager (SAM) database of a domain controller in Microsoft Windows NT or Windows 2000 that uniquely identifies a user, group, or computer account within a domain. Security identifiers (SIDs) are used internally by Windows NT and Windows 2000 to provide user accounts with access to network resources.
Security zone

A feature of Microsoft Internet Explorer that allows users to designate which intranets and portions of the Internet are trusted or distrusted. The more trusted a zone is, the broader the permissions it grants for executing scripts, Microsoft ActiveX controls, and Java applets, and for executing other potentially hazardous actions. Security settings for a zone can be high, medium, low, or custom.
Here are the zones you can configure and their default security settings:
· Internet zone (medium):
For sites on the Internet that are considered unsafe and for which access is restricted
· Local intranet zone (medium):
For internal sites that are connected to the local network
· Trusted sites zone (low):
For Internet sites that are considered safe for unrestricted access
· Restricted sites zone (high):
For sites on the Internet that have not been determined either safe or unsafe and are thus considered extremely dangerous

Security subsystem

· Local Security Authority (LSA):
Checks to see whether users have permission to access the system itself. The LSA manages the local security policy, generates access tokens, supports interactive logons, and manages auditing.

· Logon processes:
Display the Windows NT and Windows 2000 Security dialog boxes, in which a user can log on to the system interactively. Windows NT and Windows 2000 also include remote logon processes for pass-through authentication by remote users who want to access network resources.

· Security Account Manager (SAM) database:
The database in the registry that contains the user and group account credentials. The LSA uses the SAM database to determine whether to allow a user to log on to the network.

· Security Reference Monitor:
Checks to see whether users have permission to access a particular object, such as a file on an NTFS volume. The Security Reference Monitor enforces the access validation functions of the LSA and generates audit messages (if this feature is enabled).

Internet Protocol Security (IPSec)

A protocol for negotiating and controlling the security of transmissions over a TCP/IP internetwork. Internet Protocol Security (IPSec) defines standards for data encryption and data integrity at the level of Internet Protocol (IP) datagrams and can be used to encrypt transmission of data and ensure that the data originated from the sender and was not modified in transit. IPSec encrypts data at the IP level and uses tunneling to securely send information over the Internet and between intranets. IPSec is an emerging Internet Engineering Task Force (IETF) standard and is implemented in the Microsoft Windows 2000 operating system.
How It Works
IPSec is implemented at the transport layer of the Open Systems Interconnection (OSI) reference model and protects IP and higher protocols using security policies that can be configured to meet the needs of securing users, sites, applications, or the enterprise in general. IPSec essentially resides as an additional layer under the TCP/IP protocol stack and is controlled by security policies installed on each machine and by an encryption scheme negotiated between the sender and the receiver. These security policies consist of a collection of filters with associated behaviors. When the IP address, port number, and protocol of an IP packet match a particular filter, the corresponding behavior is applied to the packet.
In Windows 2000, these security policies are created and assigned at the domain level or for individual hosts using the IPSec Management snap-in for the Microsoft Management Console (MMC). IPSec policies consist of rules that specify the security requirements for different forms of communication. These rules are used to initiate and control secure communication based on the nature of the IP traffic, the source of the traffic, and its destination. These rules specify authentication and negotiation methods, tunneling attributes, and connection types.
To establish a security association (secure communication session) between two computers, a protocol framework called ISAKMP/Oakley is used. ISAKMP/Oakley includes a set of cryptographic algorithms but is also extensible to support user-defined encryption algorithms. During the negotiation process, agreement is reached on the authentication and security methods to be used, and a shared key is generated for data encryption. IPSec supports two different kinds of security associations:

Authentication Header (AH) protocol:
Provides user authentication and protection from replay attacks and supports data authentication and integrity functions. AH enables the recipient to be sure of the identity of the sender and that the data has not been modified during transmission. AH does not provide any encryption of the data itself. AH information is embedded in the IP packet’s header and can be used alone or with the Encapsulating Security Payload (ESP) protocol.

· Encapsulating Security Payload (ESP) protocol:
Encapsulates and encrypts user data to provide full data confidentiality. ESP also includes optional authentication and protections from replay attacks and can be used either by itself or with AH. ESP information is also embedded in the IP packet’s header.

Devices and software configured to support IPSec can use either public key encryption using keys supplied by certificate authorities (CAs) or preshared keys for private encryption.