Browse Definitions :
Definition

open security

Open security is an approach to safeguarding software, hardware and other information system components with methods whose design and details are publicly available.

Open security is based on the idea that systems should be inherently secure by design. That concept derives from Kerckhoff’s principle, which maintains that a Cryptographic system should be secure enough that, even if all its details but the key are available to the general public, the system will still be safe. The mathematician Claude Shannon further refined Kerckhoff’s principle. According to Shannon’s maxim, "one ought to design systems under the assumption that the enemy will immediately gain full familiarity with them."

An open cryptographic system includes algorithmic transparency. In such a system, the strength of a cryptographic implementation must be based on secrecy of the key. Keys are a fundamental element of cryptography, generated to encrypt and decrypt sensitive information.

One of the major challenges of cryptography is ensuring the secrecy of the keys, while ensuring that the authorized parties can access them at the appropriate time. Different levels of security may be sought, depending on the sensitivity of the message. A system is said to be computationally secure if it is theoretically breakable through a brute force attack but the time and expense required makes it not worth the effort. A system is said to be unconditionally or perfectly security exists when an attacker with unlimited resources still could not break it.

This was last updated in August 2015

Continue Reading About open security

SearchNetworking
  • network packet

    A network packet is a basic unit of data that's grouped together and transferred over a computer network, typically a ...

  • virtual network functions (VNFs)

    Virtual network functions (VNFs) are virtualized tasks formerly carried out by proprietary, dedicated hardware.

  • network functions virtualization (NFV)

    Network functions virtualization (NFV) is a network architecture model designed to virtualize network services that have ...

SearchSecurity
  • Android System WebView

    Android System WebView is a system component for the Android operating system (OS) that allows Android apps to display web ...

  • data masking

    Data masking is a method of creating a structurally similar but inauthentic version of an organization's data that can be used ...

  • computer worm

    A computer worm is a type of malware whose primary function is to self-replicate and infect other computers while remaining ...

SearchCIO
  • privacy compliance

    Privacy compliance is a company's accordance with established personal information protection guidelines, specifications or ...

  • contingent workforce

    A contingent workforce is a labor pool whose members are hired by an organization on an on-demand basis.

  • product development (new product development -- NPD)

    Product development, also called new product management, is a series of steps that includes the conceptualization, design, ...

SearchHRSoftware
  • talent acquisition

    Talent acquisition is the strategic process employers use to analyze their long-term talent needs in the context of business ...

  • employee retention

    Employee retention is the organizational goal of keeping productive and talented workers and reducing turnover by fostering a ...

  • hybrid work model

    A hybrid work model is a workforce structure that includes employees who work remotely and those who work on site, in a company's...

SearchCustomerExperience
  • Salesforce Trailhead

    Salesforce Trailhead is a series of online tutorials that coach beginner and intermediate developers who need to learn how to ...

  • Salesforce

    Salesforce, Inc. is a cloud computing and social enterprise software-as-a-service (SaaS) provider based in San Francisco.

  • data clean room

    A data clean room is a technology service that helps content platforms keep first person user data private when interacting with ...

Close