Reader small image

You're reading from  Enterprise Cloud Security and Governance

Product typeBook
Published inDec 2017
PublisherPackt
ISBN-139781788299558
Edition1st Edition
Tools
Right arrow
Author (1)
Zeal Vora
Zeal Vora
author image
Zeal Vora

Zeal Vora works as a DevSecOps Engineer primarily in the area of Defensive Security. He spends his days protecting and implementing security controls to help mitigate attacks both on the Cloud and servers. He is actively involved in security consultation, helping various startups which have been breached to overcome the breach and start again with a secure infrastructure.
Read more about Zeal Vora

Right arrow

Perfect forward secrecy

Encryption keeps your data secret until the time the secret key remains safe.

If the key is stolen, both the past encrypted messages and the future messages can easily be compromised.

To solve this problem, security researchers have come up with a new implementation called Perfect Forward Secrecy (PFS).

In PFS, we constantly keep changing keys for a new set of conversation and at the end of the conversation, the keys are generally deleted.

In the case where PFS is implemented, even if the latest key gets stolen, it can only decrypt the latest messages, but not the previous ones.

Implementation of perfect forward secrecy in nginx

PFS is a property of elliptical curve Diffie-Hellman. So, instead of using...

lock icon
The rest of the page is locked
Previous PageNext Page
You have been reading a chapter from
Enterprise Cloud Security and Governance
Published in: Dec 2017Publisher: PacktISBN-13: 9781788299558

Author (1)

author image
Zeal Vora

Zeal Vora works as a DevSecOps Engineer primarily in the area of Defensive Security. He spends his days protecting and implementing security controls to help mitigate attacks both on the Cloud and servers. He is actively involved in security consultation, helping various startups which have been breached to overcome the breach and start again with a secure infrastructure.
Read more about Zeal Vora