BLOGGER TEMPLATES AND TWITTER BACKGROUNDS

Tuesday, June 23, 2009

Applications of 3rd Party Certifications in Malaysia

E-commerce is gradually becoming an essential part of our life. Internet users achieved to a number of 1.57 Billion users worldwide in 2009 and the total e-commerce sales in the U.S. has reached 145.6 billion US dollars in 2008. However, when it comes to internet safety, we are still concerned and worried on security problems. This is because e-commerce involves transaction processes with no boundaries and the transfer of data is highly exposed to potential attacks like phishing, hacking and virus attacks. Therefore, having a good security system is not enough for an online business to take place. We need an additional security feature which is the 3rd party certification programme.


The 3rd party certification programme or commonly known as the digital certification programme is an additional attachment on a website or an electronic message for security purposes. So how does the certification process work? When a person wanted to send a confidential message, he needs to obtain a digital certificate from the certified authorities. The programme will help to encrypt the message then send it to the receiver. The encrypted message can only be accessed by using a private key given to the sender and the 3rd party certification programme will also have a public key that is like a ‘spare key’ for the private key to encrypt and decrypt information. Popular certification programmes in Malaysia include Secure Sockets Layer (SSL), Digicert, MSC Trustgate, VeriSign and MyCert. These certification programmes help to enhance the security of data transfer by providing a certificate instead of requesting only a user name or password.


APPLICATIONS OF 3RD PARTY CERTIFICATION:


Online business and Server Securtiy

When customers purchase products online, they would like to visit the websites they trusted

for. Digital certificates will help to ensure stronger security by providing better encryptions and more secured, instant verification that the websites are free from worries. For example, MSC Trustgate Malaysia provided services on Secure Socket Layer (SSL) Certificates for Internet, Intranet and Server security. The SSL provides two kinds of IDs, which are the Global Server ID and Secure Server ID. The Global Server ID enables 128 to 256 bits of encryption to secure the communication of business sites with its visitors. Customers can conduct business purchases with this service because it comes with a VeriSign Secured Seal that proves the website has been verified. The Secure Server ID protects transfers of sensitive data on the websites. With this SSL server IDs, online businesses can obtain purchase orders and volume discounts conveniently with easy set up steps and efficient security management because this certificate helps to manage the domain with multiple servers. Besides, the certificate will have flexible bundles according to business needs and wider compatibility with all types of web servers. DigiCert Malaysia also provides the DIGISIGN ID that is widely used in E-business applications like online banking, stock trading and insurance.


Enterprise Trust Services

Enterprises need to have quick and cost-effective web services in order to conduct their businesses with top security. Therefore, enterprises need to have an effective Public Key Infrastructure (PKI) and certificate authority system in order to have a more established security policy and certificate lifecycle management. In this case, Trustgate provides the Enterprise Managed PKI service that provides faster deployment and lower operating costs. These services help the enterprises to manage in designing, provisioning , staffing and maintaining its own system.


Transfer of Documents & E-mails

Everyday we have millions or billions of documents and emails transferred through the Internet. Some of the files transferred contain confidential information. Digital Certificates help to ensure information remains private during transit. It uses the private and public key to facilitate the authentication, privacy, authorization, integrity and non-repudiation of the information transferred online. This is in accordance to the Digital Signature Act 1997. MSC Trustgate Malaysia provides the CryptoSuite and Secured E-mail that enable security of confidential files and emails. The digital certificate encrypts the file and let the recipient with the public key to decrypt the contents. Confidential emails are substituted from handwritten signature and sealed envelopes using the Digital ID. DigiCert Malaysia, another certificate authority also provides the DigiSign File Manager that supports digital signature and asymmetrical key encryption and decryption of files with online or offline digital signing with multiple file formats.


Mobile Commerce

The advancement of M-commerce enables mobile banking and other financial services to take place. Besides, mobile phones can be used to transfer documents online. Therefore, an effective security feature should be added for mobile commerce. Trustgate advances their service by turning the SIM card into a Mobile Digital Identity to secure mobile banking transactions just like the encryption features in CryptoSuite. The only difference is this mobile feature runs on a wireless PKI platform and Mobile Operator Infrastructure. DigiCert Malaysia also offers DigiCert Mobile applications to attach the digital certificates that are able to store in the phone for application access. Mobile users can transact securely over the internet through GPRS, Bluetooth or 3G with these smart applications.


MyKad Applications

Malaysians now can use their own identification card to process transactions through the ATM machine. All we need to have is a microchip on our IC. This is a special feature brought by MSC Trustgate by providing this special MyKey PKI that works with the physical MyKad. This enables Malaysians to digitally sign documents or transactions online. This MyKey PKI provides a few types of modules for businesses to develop the applications of the MyKad. The modules include MyKey Application Programming Interface, Signing and Verification Module and the MyKad Client Kit.


From the information provided above, we can observe that the 3rd party certification is in more priority for this ever developing e-commerce world. Nevertheless, this digital certificate authorities play a very important role by ensuring online security and enhancing customer confidence to use more online services.


Sources: http://www.msctrustgate.com

http://www.digicert.com.my/

http://www.verisign.com

No comments:

Post a Comment