What Is VPN Encryption?

Reference | in , | by theWHIR

To ensure that your VPN is secure, limiting user access is only one piece of the equation; once the user is authenticated, the data itself needs to be protected as well. Without a mechanism to provide data privacy, information flowing through the channel will be transmitted in clear text, which can easily be viewed or stolen with a packet sniffer. Most modern VPNs use some kind of cryptosystem, in order to scramble data into cipher text, which is then decrypted into readable text by the recipient.nThe type of encryption available is highly varied. However, there are two basic cryptographic systems: symmetric and asymmetric. Symmetric cryptography tends to be much faster to deploy, and are commonly used to exchange large packets of data between two parties who know each other, and use the same private key to access the data.nAsymmetric systems are far more complex and require a pair of mathematically related keys – one public and one private – in order to be accessed. This method is often used for smaller, more sensitive packets of data, or during the authentication process.nAs a general rule, longer encryption keys are the strongest. The bit length of the algorithm determines the amount of effort required to crack the system using a “brute force” attack, where computers are combined to calculate all the possible key permutations. Currently, some countries have governmental restrictions on encryption strength in a VPN, such as Japan, which may require multiple key lengths in an international tunneling solution.nIn the United States, many different encryption schemes are available. The Data Encryption Standard (DES) is a 20-year old, thoroughly tested system that uses a complex symmetric algorithm, although it is considered less secure than recent systems. Triple DES and 3DES use multiple passes of the original version to increase the key length, thus strengthening security. Other methods, like Encapsulated Security Payload or Outer Cipher Block Chaining, can be used to further scramble the data, and maintain or verify its integrity. Although an unbreakable algorithm has yet to be developed, a sophisticated encryption system will greatly minimize the chance of any security gaps.nMost VPN devices, whether hardware- or software-based, use some sort of encryption scheme, and may vary in cost according to the strength of the system used. There are many different products for encrypting tunnels, from trusted companies like Check Point Software, Digital Equipment Corp., Morning Star Technologies, and PSINet, for example. It is important to keep in mind that adding strong third-party encryption to your VPN can slow down transmission speeds.nSome products also feature selective encryption, allowing administrators to decide whether or not to encrypt a subset of traffic, based on the data being accessed. In some cases, you may choose to apply a tougher algorithm to particularly important packets coming off the server. The combination of selective encryption and access control would allow the user to create a specific encrypted session to the VPN application of choice, ensuring the safety of the data as well as guaranteeing network security.

theWHIR.com

About

Since 2000, The Web Host Industry Review has made a name for itself as the foremost authority of the Web hosting industry providing reliable, insightful and comprehensive news, interviews and resources to the hosting community. TheWHIR is an iNET Interactive property. For more information on iNET Interactive, visit http://www.inetinteractive.com

No related posts.

OLDER:

NEWER:

{ 1 comment… read it below or add one }

Agence de communication montauban March 6, 2012 at 7:08 am

Is it that you can use a vpn to surf anonymously? thank you

Reply

Leave a Comment

Most Recent Posts

Read Back Issues of WHIR Magazine

  • Thumbnail image for The Social Media Issue

    May 2012 - The Social Media Issue

    Read the Digital Edition – It seems rather serendipitous that, as we began preparing to launch this social media focused issue of WHIR magazine, the WHIR organization, and other iNET Interactive editorial properties began working in earnest to measure and track engagement as a metric on our websites and on the content we publish.

    Read The Digital Edition
  • Thumbnail image for 2012 Hottest Hosts Directory

    February 2012 - 2012 Hottest Hosts Directory

    Read the Digital Edition – This edition of our Hottest Hosts buyer’s guide and directory issue is the fifth instance of the annual publication, a milestone that kind of snuck up on me, personally, but which I think provides an intriguing validation of the format, and of the principle behind it. The hosted services industry …Read More

    Read The Digital Edition
  • Thumbnail image for The Killer Business Model

    October 2011 - The Killer Business Model

    Read the Digital Edition – In pursuit of some inspiration for your killer business model, we sought out some of the really cool things being done in the hosting space by providers trying to stand out from the crowd. They’re not all huge companies yet, but they’ve all got some really interesting ideas, and more importantly, they’re looking at innovating in a way that could inspire some really original thinking from you.

    Read The Digital Edition