Saturday, October 5, 2019

Technologies Contribute in High School Education Research Proposal

Technologies Contribute in High School Education - Research Proposal Example From the discussion it is clear that  today, many high schools do not have enough computers, this being a major shortcoming to the utter integration of technology in learning initiative; equally, the utilization of the resource available is to a minimum. In fact, top-level management sees no need of increasing the technology resources since the teachers or students put in a little effort in making use of the laptops and computers present; additionally, most of them make random excuses for this, the main being the aspect of time.According to the study findings  meaningfully, teachers’ abilities and awareness play a significant role in the depth at which the technology resources apply in the learning of high school students today. Most of the teachers, who have taught for a long time, are more reluctant to applying technology as compared to new recruits; mainly because of the advancements that are there in their training. All institutions and teachers require taking consider ation of technology as a factor of edification since most students show interest with most of them purchasing laptops and tablet computers that are clear indication that they are willing to use them.  The main objective is proposing ways to improve education and learning for high students through technology, and utilizing the available resources such as schools’ computers and students’ laptops. However, availing these resources is not enough and additional factors require consideration i.e. teachers skills and incentives to engage in the same.

Friday, October 4, 2019

Choose a crisis and discuss how the Chinese government handled it Essay

Choose a crisis and discuss how the Chinese government handled it - Essay Example Food became a problem to feed the growing population. This was followed by intervention of the government through acceptance of importation of world food crops such as maize and potatoes to eradicate the problem. The government decided to come up with certain strategies to counter the high growth rate situation in the country. This was evident through family planning strategy. This policy was established in 1980 and stated that each family should give rise to one child. This was applicable in reducing the large growth rate. In return, there was a balance in the population compared to the previous years. Though some people were against the policy, it has reduced the cost of living of the people of China. The latest statistics shows that this policy has cut down the growth rate which was standing at 1.34 billion by 0.57 percent, which was below the replacement rate (Greenhalgh & Winckler, p, 287). In conclusion, it is evident that the Chinese government has adopted the right policy and strategy of controlling the high population. That is why there is perfect regulation of birth and population in

Thursday, October 3, 2019

Psychology, Theology, and Sprituality in Christian Counseling Essay Example for Free

Psychology, Theology, and Sprituality in Christian Counseling Essay In his conceptual book, Psychology, Theology, and Spirituality in Christian Counseling (1996), McMinn presents a convincing presentation of a multitasking counselor who has developed a niche in the counseling world. New age Christian counselors have developed simultaneous skills that embark on the areas of psychology, theology, and spirituality. This begins our journey down the path of understanding how values and perspectives can be changed as a result of a well rounded, multitasking Christian counselor. With life illustrations and brief counseling scenarios throughout this book, McMinn (1996) provides the reader with an excellent working model of identifying and relating life experiences to Psychology, Theology, and Spirituality. The opposition of modern psychology and theology practices is delivering different contemporary messages concerning mental health. Psychologist Albert Ellis wrote, â€Å"The emotionally healthy individual should primarily be true to himself and not masochistically sacrifice himself for others.† Versus Christian spirituality that identifies and states in scripture that as individuals we are instructed to look out for the interest of others (Phil. 2:4) and to prefer one another in honor (Rom 12:10) (McMinn, 1996). As McMinn works through the concepts of integrating these three distinct disciplines, Christian counseling becomes more complex and multifaceted. Christian counselors set their eyes upon God with an individual’s spiritual growth and mental health in their mind. In addition to placing the pieces of a battered mental health condition focus to the forefront, their client’s eternity of life and knowledge of God is an important piece of the puzzle. A more detailed perspective of psychological and spiritual health, allows every individual to recognize their responsibility to God, to their family and friends and to themselves. As humans, we must understand and have a healthy awareness of brokenness to allow ourselves to experience grace and hope in the midst of our walk on this earth through life’s trials and tribulations with Jesus Christ. Integrating psychology, theology, and spirituality in addition to the niche of multitasking, all three disciplines in unison takes time, energy, loyalty, and dedication of the counseling profession. In the last two thirds of this book, McMinn uses prayer, scripture, sin, confession, forgiveness, and redemption to show us a glimpse of the counseling world. The problem with sin is that it separates us from God; the wonder of redemption is that individuals are brought back into relationship with God. (McMinn, 1996, p. 265). A redemptive Christian counselor has humility and compassion and experiences God’s grace with gratitude. Scripture yanks people out of the grips of sin as a redemptive God shines through. Those who deny sin see no need for spiritual redemption. Confession, allows us to acknowledge our sin and our desperate need for help and through the grace of God we receive forgiveness and experience redemption. Once our affections turn to God, our prayer will never be the same. Our lives will be completed changed and everlasting. â€Å"Bless the Lord, O my Soul, and do not forget all his benefits-who forgives all your iniquity, who heals all your diseases, who redeems your life from the pit, who crowns you with steadfast love and mercy, who satisfies you with good as long as you live so that your youth is renewed like the e agle’s†(Ps. 103:2-5). Response Come to me, all you who are weary and burdened, and I will give you rest. Take my yoke upon you and learn from me, for I am gentle and humble in heart, and you will find rest for your souls. For my yoke is easy and my burden is light.† As I had struggled throughout my chaotic childhood dealing with the presence of alcohol, drugs, fighting, and uncertain living conditions in my circle of life, I developed the ability to discern which people were right for me in my life. My perception of family was skewed. At the age of 7, I lost my grandfather and life’s losses of my protectors continued until 2004 with the death of my first husband Dale. My life was over. My family was a mess. I had just started a new church and I wasn’t sure where God was in my life. My father in law, who preached my husband’s funeral, started providing Christian guidance and support as a lay counselor. We prayed and shared scripture together. At the age of 33, I learned the true meaning of prayer. I knew how to pray and I knew how humbled I had been in my prayers for Dale. In the kindness of his God filled heart, he taught me that humility allows us to see God’s word. As I study and read my Bible, I continue to learn the importance of a Christian family for support and guidance and the necessity to share the story of Jesus Christ. My father in law stepped out in faith to help turn my life around. Through his obedience, I work to help others who are hurting find the power of prayer and scripture in their times of heartache. Reflection As I read through Psychology, Theology, and Spirituality in Christian Counseling (McMinn, 1996), a highlighter was used to mark special passages I needed to keep in the forefront of this class. There are so many key notes to remember in the text, the book was turning a nice shade of yellow. Anyone who is starting out in the counseling field should be required to read this book. McMinn does an excellent job of showing the reader how to integrate our Christian faith and spirituality into the secular world with real life reflections. Christian counselors want to follow the will of God and McMinn provides the examples, guidance, and techniques on how to incorporate God into the counseling session. The major drawback with this work concerns the conclusion. Throughout the reading, it is apparent McMinn is preparing the counselor to learn the skill of multi-tasking. In two pages, McMinn summarizes the whole book. The most important part of integrating the three diverse areas of studies is profound enough for him to provide a greater level of detail to the new counselor concerning the background of multitasking. Success lies in the strategy that is used in multitasking these three distinct practices and beliefs. In dealing with the secular world, this skill is a necessity to bring all three disciplines together. Action I am sending you out like sheep among wolves. Therefore be as shrewd as snakes and as innocent as doves. â€Å"Be on your guard against men; they will hand you over to the local councils and flog you in their synagogues. On my account you will be brought before governors and kings as witnesses to them and to the Gentiles. But when they arrest you, do not worry about what to say or how to say it. At that time you will be given what to say; for it will not be you speaking, but the Spirit of your Father speaking through you. (Matthew 10:16-20). God has given me back tenfold since the loss of my first husband. I have established myself as a praying respiratory therapist at UVA. As Jesus calls me into the counseling field, he is preparing me for the secular world. In my environment, people are at the lowest points of their lives. I use Gods calling on my heart and spirit to reach out in Christian love to these individuals and families. God places pastors, judges, professional basketball players, the rich, the homeless, the curable, the dying, in my path for a reason and a purpose. Life is simple when you are obedient. Go where God calls you. The people I come into contact with are not by accident. I minister to their hearts through their illness and time of need. I pray for God to give me the strength and the right words of his will to deliver to the sick and their families. I pray for each individual that crosses my path to find the love of Jesus Christ and meet him in heaven to spend an everlasting life with our father.

An Ethical Evaluation of Product Placement

An Ethical Evaluation of Product Placement Product placement is the way in which brands are placed into non-advertising media like computer games, books, popular songs and stage plays for e.g. sponsored animations for the promotion of Cadburys chocolate placed in the UK TV soap Coronation Street after the opening titles and after and before the commercial breaks; this is affecting the children and luring them to buy the Cadbury chocolate because small children cannot differentiate that this is an add. It is a growing phenomenon in market, which has received relatively little attention from business ethicists. In marketing at the macro level, there are issues of sustainability and waste of resources through overconsumption by fostering greed and materialism. Marketing operates at the hub of wealth creation; it attracts a lot of the general criticism directed at capitalism concerning the erosion of natural resources and the destruction of the environment. At micro level, it attracts a lot of criticisms for specific cases of dec eit or cheating, such as misleading/inappropriate food labels or differential price advertising. There is widespread criticism of marketing practices promoting products that are harmful to health, like high-fat and high-salt foods, cigarettes and alcohol. UK has made Ofcom(Office of Communication) to make the laws regarding product placement in a way described above.The code includes a section on Commercial references and other matters. Within this section, three principles are specified (under Section 10): (1) broadcasters must maintain full editorial control over programmed content, (2)editorial and advertising must be clearly separated, and (3) product placement is prohibited (http://www.ofcom.org.uk/tv/ifi/codes/bcode/commercial/). Product placement and conventional marketing ethics Ethical evaluation of marketing practices has generally used three major strands of moral philosophy, utilitarianism, deontology and virtue ethics (Robin Reidenbach 1987). We are discussing 2 of them. A utilitarian evaluation of marketing is mainly to focus on its usefulness to society, the fact that at a micro level, it aids mutual exchanges between producers and consumers, while at a macro level, it enables the society to enjoy the benefits of the division of labor. The ethical concerns of consumers regarding product placement fit into this category product placement of guns and cigarettes, for example, may be seen as unethical by some consumers. A utilitarian evaluation may well come to the conclusion that product placement is indeed, an ethical practice. This is under the reasoning that the increased sales are the signs of customer satisfaction as can be reasonably assumed at least for cases of explicit product placement. On the other hand, there is the risk that increased product placement might, undermine the quality of mediated entertainment and information,, thus reducing social, utility even when it increases economic utility. Virtue ethics may provide the greatest critique of product placement because it focuses on the intentions and the character of the person initiating the action rather than the ethical status of the act itself. By evaluating the virtual ethics in product placement ome points which can be drawn are in marketing, legality must be the main criterion for judging the ethical status of the motive.A marketing campaign done for the consumers who are well informed and who know that this is a type of advertisement differs in ethical terms from advertising to children who cannot distinguish between TV programs, games, songs and advertising. If many consumers are aware about the technique of product placement, then it will have very less effect ethically. Many young consumers indeed know about the nature and extent of product placement as it occurs in movies, TV shows and other entertainment products. But the extent to which even an intelligent audience is aware of a product placement communication while they are just enjoying the dramatic entertainment is very difficult to establish. Many consumers will say that they are not influenced by advertising, but this claim seems no more credible than the claim of knowing about product placement as a marketing technique, it does not immune one to deception. Hence, there is a need for an ethical analysis that deals with product placement, which again can apply a utilitarian, a deontological and a virtue ethics perspective; except this it also needs to consider situation-specific factors that arise from the nature of the product, the degree of consumer knowledge, the implication of, market segmentation strategies, the intention, of the marketer and, the intrinsic honesty of, the method of persuasion used.

Wednesday, October 2, 2019

The unsuccesful use of ethanol :: Alternative fuel bio-ethanol

The Unsuccessful Use of Ethanol Current interest in ethanol fuel in the United States mainly lies in bio-ethanol, produced from corn, but there has been considerable debate about how useful bio-ethanol will be in replacing fossil fuels in vehicles. Concerns relate to the large amount of arable land required for crops, as well as the energy and pollution balance of the whole cycle of ethanol production. I don't think the US could implement the use of ethanol or other alternate fuels successfully as Brazil has done for many reasons: firstly, ethanol production in the United States does not benefit the nation's energy security, its agriculture, economy or the environment because ethanol production requires large fossil energy input to produce these fuels than you get out from the combustion of these products. Therefore, it is contributing to oil and natural gas imports and U.S. deficits. The country should instead focus its efforts on producing electrical energy from photovoltaic cells, wind power and burning biomass and producing fuel from hydrogen conversion. Secondly, in Brazil reducing the rate of deforestation seemed likely to be more effective for taking carbon dioxide out of the atmosphere. In the United States, reliance on ethanol to fuel the automobile fleet would require enormous, unachievable areas of corn agriculture, and the environmental impacts would outweigh its benefits, destroying bio-diversity. Ethanol would be mainly made from bio organic material that will be especially grown for this purpose. It also uses a lot of fuel to grow these plants. The same goes for various kinds of vegetable oils that are said to be environmental friendly. Ethanol cannot alleviate the United States? dependence on petroleum, may, however, still be useful in regions or cities with critical pollution problems, and to make use of agricultural wastes. Basically, an increased demand for ethanol would cause land use changes - destroying forests and grasslands to grow corn or other ethanol crops - ethanol and other bio-fuels actually add to global wa rming. Thirdly, as demand for ethanol fuel increases, food crops are replaced by fuel crops, driving food supply down and food prices up. Growing demand for ethanol in the United States has increased corn prices by 50% in Mexico. Average barley prices in the United States rose 17% from January to June 2007 to the highest in 11 years. Prices for all grain crops trend upward, reflecting a progressive increase in farm land devoted to corn for the production of produce ethanol fuel.

Tuesday, October 1, 2019

Fight for Freedom in Toni Morrisons The Song of Solomon :: Song of Solomon Essays

Fight for Freedom in Toni Morrison's The Song of Solomon "The scream that boomed down the cave tunnel and woke the bats came just when Macon thought that he had taken his last living breath. The bleeding man turned toward the direction of the scream and looked at the colored girl long enough for Macon to pull out his knife and bring it down the old man's back. He crashed forward, then turned his head to look at them. His mouth moved and he mumbles something that sounds like 'What for?' Macon stabbed him again and again until he stopped moving his mouth, stop trying to talk and stopped jumping and twitching on the ground" (pg. 171). This is an excerpt for the novel The Song of Solomon (1987), by Toni Morrison. Macon one of the main characters, only a child at the time, kills a man whom he thinks is threatening him and his sister's, Pilate, life. After killing the man the two children travel to the man's camp where they discover three bags of gold. Macon also sees, " the dusty boots of his farther" (pg 170). Becoming alarmed, Pilate says, "I t is Papa!". To her cry a voice whispers 'sing, sing'. Macon greedily packs up the gold while Pilate searchers frantically for their farther. After a terrible fight the two separate. Ironically years later they end up living in the same small Michigan town. Macon and Pilate hate and their family secret all the while still grows in differnt directions. Macon moves on with his life and marries Ruth. The couple have three children, Lean, First Corinthians, and Macon who receives the nickname of Milkman. Milkman being interested in Pilate granddaughter, spends a great deal of his childhood at Pilate's house--despite his fathers disapproval. After living at home for the past thirty years Milkman becomes swamped with his family secret. His farther claims that Pilate stole the gold from the man his killed camp sight. And Pilate claims the bag of her 'inheritance' only to be bones. Becoming frustrated, Milkman sets out to find the truth of his family fude. Toni Morrison's mystery novel keeps the readers curiosity,as she write her storyline about the lifestyle of a black society in the 1980's. Within this black society, the people are pursuing their freedom. Toni theme of her novel is freedom, and each character can only obtain their freedom by one of two paths.

Public Key Cryptography

Abstract- Public-key cryptography is a key technology for e-commerce, intranets, extranets and other web-enabled applications. However, to garner the benefits of public-key cryptography, a supporting infrastructure is needed. The Microsoft ® Windows ® 2000 operating system includes a native public-key infrastructure (PKI) that is designed from the ground up to take full advantage of the Windows 2000 security architecture.This paper describes the fundamentals of public-key security systems, including what benefits they offer and what components are required to implement them. It also describes how the Windows 2000 PKI components deliver the needed services while providing interoperability, security, flexibility, and ease of use. I. Overview Public-key cryptography offers significant security benefits when it's properly implemented. Like other enabling technologies, public-key cryptography requires an infrastructure to deliver its benefits.However, the public-key infrastructure, or PKI, isn't a physical object or software process; instead, it's a set of useful services provided by a collection of interconnected components These components work together to provide public-key-based security services to applications and users. This white paper has two goals: to explain public-key technology and its uses, and to describe the features and benefits provided by the native PKI in the Microsoft ® Windows ® 2000 operating system.Understanding both of these topics will help you to decide where you can use PKI technology to improve your business processes and increase your ability to securely handle transactions with others. In this paper, you'll learn what a public key infrastructure is, what desirable benefits it can offer your operations, and how the Windows 2000 PKI delivers interoperability, security, flexibility, and ease of use. II. History During the early history of cryptography, two parties would agree upon a key using a secure, but non-cryptographic, metho d; for example, a face-to-face meeting or an exchange via a trusted courier.This key, which both parties kept absolutely secret, could then be used to exchange encrypted messages. A number of significant practical difficulties arise in this approach to distributing keys. Public-key cryptography addresses these drawbacks so that users can communicate securely over a public channel without having to agree upon a shared key beforehand. In 1874, a book by William Stanley Jevons[1] described the relationship of one-way functions to cryptography and went on to discuss specifically the factorization problem used to create the trapdoor function in theRSA system.Since the 1970s, a large number and variety of encryption, digital signature, key agreement, and other techniques have been developed in the field of public-key cryptography. The ElGamal cryptosystem (invented by Taher ElGamal) relies on the (similar, and related) difficulty of the discrete logarithm problem, as does the closely rela ted DSA developed at the US National Security Agency (NSA) and published by NIST as a proposed standard. The introduction of elliptic curve cryptography by Neal Koblitz and Victor Miller independently and simultaneously in the mid-1980s has yielded new public-key algorithms based on the discrete logarithm problem.Although mathematically more complex, elliptic curves provide smaller key sizes and faster operations for equivalent estimated security. III. What is public key cryptography? When most people hear the words encrypt or cryptography, they immediately think of secret-key cryptography, wherein two parties share a single secret key that's used both to encrypt and decrypt data. Loss or compromise of the secret key makes the data it encrypts vulnerable. By contrast, public-key systems use two keys: a public key, designed to be shared, and a private key, which must be closely held.These keys are complementary: if you encrypt something with the public key, it can only be decrypted w ith the corresponding private key, and vice versa. Public-key systems depend on the mathematical relationship between the public and private keys. It's not feasible to derive one from the other. There are two fundamental operations associated with public key cryptography: encryption and signing. The goal of encryption is to obscure data in such a way that it can only be read by the intended party. In public-key cryptography, if Bob wants to send Alice some private data, he uses her public key to encrypt it, then sends it to her.Upon receiving the encrypted data, Alice uses her private key to decrypt it. The important concept here is that Alice can freely distribute her public key in order to allow anyone in the world to encrypt data that only she can decrypt. If Bob and Chuck both have copies of her public key, and Chuck intercepts an encrypted message from Bob to Alice, he will not be able to decrypt it; only Alice's private key can do that, and she is the only person who holds it. These two operations can be used to provide three capabilities A PrivacyPrivacy is a necessity for businesses of all kinds, but it's of vital importance for ones that use the Internet. The Internet allows anyone in the world to communicate with anyone else, but it doesn't provide security. Even within your company's internal network, if someone can gain physical access to your network media, they can eavesdrop on any data that traverses it. Public-key cryptography provides privacy via data encryption, whether the data is in the form of e-mail messages, credit card numbers sent over the Internet, or network traffic.Because public keys can be posted freely, complete strangers can establish private communications simply by retrieving each other's public keys and encrypting the data. B. Authentication Any transaction involves two parties, whether they're a client and a server or a customer and a vendor. For many transactions, it's desirable for one or both sides to be able to authentic ate, or verify the identity of, the other. For instance, before a customer provides their credit card number to an e-commerce web site, they will want to know that they are not talking to an imposter.One way that a customer can do this is by making the web site prove that it holds the right private key. For example, a web browser might encrypt a piece of information using the site's public key and ask the web server to decrypt it, thereby demonstrating that the server has the right private key, and proving its identity. Authentication can also take the form of assuring your customers that you produced a particular piece of data and that it has not been tampered with. Public-key cryptography enables you to do this by means of a digital signature, a concept which is an extension of the public-key signing operation discussed above.If Bob wants to digitally sign his company's annual report, he first generates a unique fingerprint of the report using an algorithm called a hash algorithm. Hash algorithms are specially designed to guarantee that even a single changed byte in the document will generate a completely different hash. Next, he encrypts the report and the hash using his private key. Alice (or anyone else) can verify the origin and authenticity of the signed report by first decrypting it using Bob's public key, then calculating her own version of the fingerprint and comparing it to the fingerprint she received.If the two match, it proves two things: that the report has not been tampered with, and it came from Bob. C. Non-repudiation Businesses require the ability to enter into binding agreements, whether in the physical world or on the Internet. Suppliers and buyers need the assurance that if they enter into an agreement, the other party will not be able to repudiate the agreement at some later point. Digital signatures on electronic purchase orders, contracts, and other agreements are legally binding in several countries and in many U.S. states, and legal acceptance is rapidly growing. D. infrastructure Manage keys: a PKI makes it easy to issue new keys, review or revoke existing keys, and manage the trust level attached to keys from different issuers. Publish keys: a PKI offers a well-defined way for clients to locate and retrieve public keys and information about whether a specific key is valid or not. Without the ability to retrieve keys and know that they are valid, your users can't make use of public key services.Use keys: a PKI provides an easy-to-use way for users to use keys—not just by moving keys around where they're needed, but also by providing easy-to-use applications that perform public-key cryptographic operations, making it possible to provide security for e-mail, e-commerce, and networks. E. A capability,not a thing A common misperception is that a PKI is a thing. In fact, it's a capability—the capability to easily publish, manage, and use public keys. Think of a PKI like a municipal water system. A wat er system is made up of purification plants, storage towers, pumps, water mains, and so on, as well as the pipes and faucets in your house.All of the disparate service-providing objects work together to provide a capability for users to obtain water on demand. In a similar way, a PKI consists of a group of discrete components that work together to allow you to use public keys, and public-key cryptography, seamlessly and transparently. The best place to implement a PKI is in the operating system. Operating systems already provide a number of other infrastructures, like the printing infrastructure that moves documents to printers and the file service infrastructure that retrieves files from shared storage.In both cases, the operating system provides a capability to transparently and easily use a network service, just as a PKI does. F. Digital certificates:packaging for public key So far, this paper has mentioned public keys when talking about the objects that a PKI uses. While public keys are required for PKI-based security, they're usually packaged as digital certificates. (It's important to stress that only public keys are packaged into certificates. The private key is never shared, so it doesn't require packaging—it's simply stored securely). The certificate contains the public key and a set of attributes, like the key holder's name.These attributes may be related to the holder's identity, what they're allowed to do, or under what conditions the certificate is valid. The binding between attributes and the public key is present because the certificate is digitally signed by the entity that issued it; the issuer's signature on the certificate vouches for its authenticity and correctness. For a real-world analogy, look in your wallet. If you have a drivers' license, you have the equivalent of a digital certificate. Your license contains a unique key (your license number) and some attributes (an expiration date, your name, address, hair color, and so on).I t's issued by a trusted agency and laminated to prevent it from being tampered with. Anyone who trusts the agency that issued your license and verifies that the lamination is intact can rely on its authenticity. At that point, though, the analogy breaks down—in the real world, only the government can issue a driver's license, so everyone knows that a license issued by Joe's Really Good DMV isn't valid. How do you make the same determination with a digital certificate? The answer lies in the concept of a certificate hierarchy.In a hierarchy, as shown in Figure 1, each issuer, or certificate authority, signs (using its own private key) the certificates it issues. The public half of the CA's keypair is itself packaged in a certificate—one that was issued by a higher-level CA. This pattern can continue through as many levels as desired, with each CA certifying the authenticity of the certificates it has issued. Eventually, though, there must be a top-level CA, called a roo t certificate authority. Since there's nobody above the root CA in the hierarchy, there's nobody to vouch for the authenticity and origin of its certificate.Instead, the root CA signs its own certificate—it simply asserts that it is the root. Figure 1: What a certificate hierarchy looks like Clearly, it's not secure to accept a root CA's assertion of its own identity. To verify a root CA's certificate, a trusted copy of its public key is obtained via an out-of-band method-—that is, it's delivered by a third party instead of over the network—and the key is used to verify that the root certificate is bona fide. Microsoft provides the public keys for many popular root CAs in PK-enabled products like Internet Explorer, allowing users to verify those roots transparently.Root CAs can also provide copies of their public keys for downloading from public web sites. Once the root key has been delivered via an out-of-band means, the user can verify the root certificate, an d hence the entire certificate chain. Even better, because each certificate's digital signature protects it from tampering, certificate chains can be freely passed over insecure media like the Internet. G. Public key enabled application Once your PKI can issue, publish, and control certificates, the next step is to deploy applications that can use them.A well-written application that is tightly integrated with the rest of the PKI can make the use of public-key cryptography all but transparent to the user. The user should not need to know how cryptography works, where certificates are stored, or any of the other details—they should simply indicate what they want done, and leave it to the applications and the PKI to make it happen. Applications can use digital certificates to deliver the benefits of public-key cryptography, and they can combine cryptographic functions like signing and encryption to make possible e-commerce, secure network access, or other desirable services.All Microsoft applications that use public-key cryptography are natively public-key enabled. For example, the Microsoft Outlook ® messaging and collaboration client offers built-in signing and encryption support, combined with the ability to use certificate publishers and root certificates from a number of sources. Internet Explorer, Microsoft Money, and Internet Information Server provide the ability to set up encrypted web sessions. PKI-enabled applications can build on industry-standard protocols to speed development and allow easy interoperability with other organizations, too.H. Hardware support The increasing market demand for PKI implementations has spurred hardware vendors to develop cryptographic hardware, including smart cards, PC cards, and PCI cards that offer onboard cryptographic processing. These hardware devices offer a wide range of capabilities. On the low end, smartcards offer limited cryptographic processing combined with secure key storage; on the high end, multi processor crypto-accelerators allow high-volume web services to secure data without suffering from bottlenecks caused by software cryptographic modules.The best thing about PKI hardware devices is that they're optional—if your application requires additional performance or security, you can add hardware to provide it as necessary, but you can still build a completely functional PKI in software. I. Models The standalone CA model The standalone CA model (see Figure 2) is probably familiar to you if you've used SSL-protected web sites. In the standalone model, some third-party entity holds the root key and certificate for your organization, and it issues and revokes all certificates for your users.This third party might be a commercial CA like VeriSign, Thawte, Belsign, or GTE Cybertrust; it could also be a bank, a law firm, a trade association, or any other organization that you trust to issue certificates on your behalf. Figure 2: The standalone CA model This model allows trus t both within and outside your organization, so you can exchange secure e-mail and e-commerce transactions with outsiders. Standalone CAs also free you from the complexities of issuing, revoking, and tracking certificates.However, it requires you to trust some outside entity with your certificate management, and many third-party CAs levy an individual charge for each issued certificate. The enterprise CA model In this model (see Figure 3), your enterprise acts as its own CA, issuing and revoking certificates subject to your business requirements. Because no outsourcing provider is involved, your organization maintains complete control over its PKI. In addition to that control, though, you can guarantee that no one outside the enterprise can obtain a certificate unless you issue it to them.This model works well for controlling access to internal resources, or for generating certificates whose attributes would be meaningless to an outside entity. For example, you could issue certifica tes to managers that would allow them to make electronic travel reservations through the company travel office. Figure 3: The enterprise CA model Enterprise CAs with subordinates You can expand the flexibility of the enterprise CA model by adding subordinate CAs for individual departments, business units, or subdivisions of the organization. Most organizations already delegate some amount of administrative control to their subunits.For example, individual managers at most companies have some level of purchasing authority; higher-ranking managers can write bigger checks. Even though there's a centralized purchasing department that does much of the enterprise-wide buying, individual units still have the ability to perform day-to-day purchasing tasks. Choose your trust model If the choice of a CA model is the most important one you face when implementing a PKI, choosing a trust model comes in a very close second. When you trust a root, you're making an implicit statement that you trust them to be careful about who they issue certificates to.In this case, careful isn't quite the right word; what you're really saying is that you trust them to follow their prescribed policies and procedures to verify the identity of a certificate holder when they issue the certificate. When you choose to trust a root certificate, you're also choosing to trust certificates signed by that root. Depending on the CA model you use, the practical impact of this choice could be large (as when you choose to trust a large, widely used commercial root CA) or small (like deciding to trust your own accounting department).Normally these decisions are made for the enterprise as a whole; however, the Windows 2000 PKI allows individual users (or their administrators) to make their own trust decisions. In addition, administrators may override or augment user trust decisions with group policies. You also have to choose what you trust certificates to be used for. The X. 509 v3 certificate standard all ows you to specify whether certificates can be used for signing, encryption, or both. For example, you might want to give everyone signature certificates but restrict the use of encryption-capable certificates to certain departments or individuals.Microsoft has extended this feature to allow you to specify additional uses, including signing software components, logging on using a smart card, or recovering an encrypted file. When using the Windows 2000 PKI, the issuer has total control over what the certificate can be used for. IV Conclusion Public key cryptography offers critical business advantages, including the ability to conduct e-commerce and normal business operations with increased privacy, security, and assurance. To deliver these benefits, a public-key infrastructure is necessary that makes it easy to manage, publish and use public keys.Windows 2000 offers a PKI that is completely integrated with the operating system and provides flexible, secure, interoperable services tha t are easy to use, easy to deploy, and easy to manage. References N. Ferguson; B. Schneier (2003). Practical Cryptography. Wiley. ISBN 0-471-22357-3. J. Katz; Y. Lindell (2007). Introduction to Modern Cryptography. CRC Press. ISBN 1-58488-551-3. J. Menezes; P. C. van Oorschot; S. A. Vanstone (1997). Handbook of Applied Cryptography. ISBN 0-8493-8523-7. IEEE 1363: Standard Specifications for Public-Key Cryptography Single Sign-On Technology for SAP Enterprises: What does SAP have to say? [1] ^ Ed Gerck, Overview of Certification Systems: x. 509, CA, PGP and SKIP, in The Black Hat Briefings '99, http://www. securitytechnet. com/resource/rsc-center/presentation/black/vegas99/certover. pdf andhttp://mcwg. org/mcg-mirror/cert. htm ^ Stephen Wilson, Dec 2005, â€Å"The importance of PKI today†, China Communications, Retrieved on 2010-12-13 ^ Mark Gasson, Martin Meints, Kevin Warwick (2005), D3. 2: A study on PKI and biometrics, FIDIS deliverable (3)2, July 2005