Strong Encryption for PC-to-any-Host Connectivity

General Information Concerning Encryption Methods

US Export Restrictions for Encryption

Strong Encryption with HOB Software Products

Strong Encryption for Secure PC-to-Host Communication (HOBLink 3270)

Secure Web-to-Host Connectivity with HOBLink J-Term (3270 Terminal Emulation in Java)

Strong Encryption with HOBLink Secure

red-arr.gif (922 Byte)   HOBLink Secure

Encryption Methods

The technical details of many encryption methods used in public networks today are common knowledge. For these methods the security function is contained in a bit of addition information (the key) which is inserted during encryption. Theoretically, any encryption method can be cracked by trying all the possible keys (so-called full key search).

In practice, however, when a key of sufficient length is used, security breaches of this type can be prevented. 40-bit-long keys have been cracked many times already; 56-bit keys are also no longer considered secure, although a huge effort is required to break them. At 128 bits, decoders run up against physical and practical limitations: a computer that could test all the keys of this length would have to possess unimaginable computing power – currently, this is only theoretically possible.

The Data Encryption Standard (DES) uses a key length of 56 bits. More recent implementations usually favor the International Data Encryption Algorithm (Idea) which encodes using 128 bits. However, the key length alone is not a measure of the effectiveness of the encryption method. In many cases there are less complicated assaults on security than the full key search – also an important factor to consider when choosing an encryption method.

US Export Restrictions for Encryption

In the USA, exporting cryptography is still legally restricted. For German companies this sometimes means that they are forced to use insecure encryption when they employ software from American manufacturers.

Up to the end of 1996 the International Traffic and Arms Regulation (ITAR) prohibited the export of encryption technology used by the military. As a result, only software with a maximum of 40-bit encryption could be exported from the USA. Documents encrypted with this method can be decrypted within a few hours.

Since the end of 1996 exporting cryptography is no longer regulated by the ITAR, but falls under the control of a law – the Export Administration Regulations (EAR). There are, however, still strict limitations on encryption technology. These restrictions mandate that the trade commission grant approval for export.

Authorization is required for exporting encryption greater than 56-bit. The responsible regulatory body for this type of export permit is the US Department of Commerce. However, the guiding institution in the background is the National Security Agency (NSA). This agency's primary task is monitoring messages which are relevant to the security of the United States.

"Strong Encryption" for HOB Products

Since HOB software products are developed in Germany, they do not fall under the US trade restrictions. This puts you on the safe side with HOB encryption technology for  software. We exclusively use encryption methods which have never been broken and, therefore, which are considered absolutely secure. You can obtain the following encryption solutions from HOB:

Strong Encryption for Secure PC-to-Host Communication (S/390) for HOBLink 3270 (3270 Emulation)

In the classic communications environment based on a 3270 emulation under Windows, we offer an encryption solution not only for SNA but also for TCP/IP which is considered absolutely secure. This encryption solution consists of two components, a host component (HOBCOM) and a client, which in this case is the HOBLink 3270 emulation. This configuration protects the entire communication path (end-to-end encryption between client and host). The encryption is based on the Blowfish algorithm, which has a 64-bit block cipher and a maximum key length of 256 bits. The actual data key is generated from the user key combined with a time stamp. You can encrypt either the entire data stream or just the password; data originating from on-screen communications as well as from the printer can also be encrypted.

Products required for securely connecting HOBLink 3270 (3270 emulation) under Windows (32-bit):

  • HOBCOM (OS/390, MVS, VM, VSE)

  • HOBLink 3270 V. 4.4 (Windows 32-bit)

Graphical illustration of encryption

Encryption 3270

Secure Web-to-Host Connectivity with HOBLink J-Term (3270 Terminal Emulation in Java)

The growing trend toward integrating hosts in the Internet and intranet environments makes the data security issue more critical than ever. With this background, the solution described above is predestined for Web-to-Host communication. HOBLink J-Term, a combined 3270, 5250 and VT525 emulation in native Java, also gives you the option of encrypting the password or the entire data stream. The only prerequisite for the communication is a Java-capable Internet browser (e.g., Netscape Navigator or Microsoft Internet Explorer).

Graphical illustration of Web-to-Host encryption (3270)

Encryption HOBLink J-Term

Products needed for securely connecting HOBLink J-Term (combined 3270, 5250 and VT525 terminal emulation in Java). Encryption for 3270 data stream only:

  • HOBCOM (OS/390, MVS, VM, VSE)

  • HOBLink J-Term 2.3 or HOBLink J-Term Entry 1.1 or 1.2

HOBLink Secure - Strong Encryption
based on SSL V. 3.0

HOBLink Secure offers you an additional encryption solution. HOBLink Secure is an optional software product and can be used with the following HOB software products:

Web-to-Host

HOBLink J-Term – 3270, 5250 and VT525 Emulation in Java
HOBLink J-DRDA – JDBC Database Driver Type 4 for access to all IBM DB2 Databases

Classic Emulations

HOBLink 3270 – 3270 Terminal Emulation for Windows (32 bit)

Midrange Connectivity

HOBLink 5250 – 5250 Emulation for Windows (32 bit)

Unix Connectivity

HOBLink VT525 – VT525 Terminal Emulation for Windows (32 bit)

NT/Windows 2000 Connectivity

HOBLink JWT – Java Windows Terminal for platform-independent access to MS Windows Terminal Server/ Windows 2000 (Windows Anywhere)

Host/Server Solutions

HOBLink SNA Router – SNA Router (Gateway) for connecting 3270 Emulations originating from TCP/IP and SNA to Hosts which are exclusively in the SNA network.

HOBLink Secure is an optional software for the products listed above. 

Encryption Solution with HOBLink Secure and HOB Software Products

HOBLink Secure is an encryption solution based on SSL V. 3.0 that can be used as an option for the products mentioned above and which does not fall under the export restrictions for encryption software. HOBLink Secure consists of three components:

Client

HOBLink Secure Client for Java
HOBLink Secure Client for Windows (32-bit)

Redirector

HOBLink Secure Redirector for Java
HOBLink Secure Redirector for Windows (32-bit)

SSL Manager

The following encryption methods can be employed:

DH (Diffie-Hellmann)
RSA (Rivest, Shamir, Adelman)

The following encryption algorithms are supported:

RC2 – with  40-bit maximum
RC4 – with  128-bit maximum
DES – with  56-bit maximum
3DES – with  168-bit maximum (Three 56-bit keys, effective key length: 112 bits)

The following digital signatures (hash functions, message digests) are supported:

  • MD5

  • SHA-1

Graphical illustration of encryption: (Solution 1: HOBLink Secure Client and Redirector)

HOBLink Secure

Additional Solution Options

HOBLink Secure is based on the SSL V. 3.0 standard and, with the HOBLink Secure Client (Java or Windows, 32 bit), is compatible to other SSL encryption components. In other words, if you use the Link Secure Client instead of using the HOBLink Secure Redirector, you can use an existing Redirector (e.g., included in IBM SecureWay Communications Server).

The same is true for the HOBLink Secure Client. If you are already using a client software with SSL V. 3.0 support, you can use the HOBLink Secure Redirector. One point should be noted, however:  if you are using only one HOBLink Secure component - either just the HOBLink Secure Client or the HOBLink Secure Redirector - you can employ only the encryption which the "foreign" product supports as a maximum. In most cases, only a limited encryption can be carried out which, as mentioned in the introduction, complies with the trade restrictions.

More about HOBLink Secure

Our Marketing department will be glad to answer any further questions you might have.

Further information at: Strong Encryption: Secure PC-to-Any-Host Connectivity

 

webmaster@hobsoft.com, Last Updated: 03. Jul 07

 


| Home | News | Products | Software tests | Sitemap | Feedback |

Imprint