|
Securing Your Web Site For Business
Introduction |
|
Businesses that accept transactions via the Web can gain a competitive edge by
reaching a worldwide audience, at very low cost. But the Web poses a unique set
of security issues, which businesses must address at the outset to minimize risk.
Customers will submit information via the Web only if they are confident that their
personal information, such as credit card numbers, financial data, or medical
history, is secure.
VeriSign, Inc., the leading provider of trust services for electronic commerce and communication, offers a low-cost, proven solution for securely conducting business over the Web. By installing a VeriSign Server ID (available as part of VeriSign’s Secure Site solutions) on your server, you can securely collect sensitive information online, and increase business by giving your customers confidence that their transactions are safe.
|
|
|
|
Increase your competitive edge with a secure Web site
A secure Web site can provide your business with powerful competitive advantages, including online sales and streamlined application processes for products such as insurance, mortgages, or credit cards. Credit card sales can be especially lucrative: according to independent analysts, cash transactions on the Internet will reach $9 billion by 2000, and $30 billion in 2005. No merchant can afford to ignore a market this large. |
|
|
|
Secure your Web Site with a VeriSign Server ID
A proven, low-cost solution to secure online transactions is available today. VeriSign Server IDs have earned the trust of businesses world-wide, including virtually all of the Fortune 500 companies on the Web and all of the top 40 e-commerce sites. To date, VeriSign has issued over 180,000 Server IDs. This section describes how VeriSign Server IDs work to make online transactions secure. |
|
|
|
Standard Secure Server IDs (included with VeriSign’s Secure Site and Secure Site Plus services) enable 40-bit SSL sessions when communicating with export-version Netscape and Microsoft Internet Explorer Web browsers. Export-version browsers are used by over 50 percent of Internet users. 40-bit SSL is strong enough for most intranets and lower-volume Web sites. But when communicating with domestic-version Web browsers, standard Secure Site IDs enable super-strong 128-bit SSL encryption, the world’s most powerful. 128-bit SSL encryption has never been broken: according to RSA Labs, it would take a trillion-trillion years to crack using today’s technology. Global Server IDs(included with VeriSign’s Global Site and Global Site Plus services) automatically ensure a minimum level of 128-bit SSL encryption when communicating with both domestic and export versions of Netscape Communicator and Internet Explorer. The encryption power of Global Server IDs make them ideal for sites that exchange sensitive, personal information, such as credit card numbers, with customers. VeriSign is one of the only providers authorized by the U.S. Department of Commerce to sell 128-bit SSL IDs in the U.S., and may sell them only to specified categories of organizations, including online merchants, healthcare organizations, insurance companies, and banks and financial institutions. The ultimate result of a VeriSign Server ID on your site: safe online transactions that protect customers and your business. Customers gain confidence that they are sending their personal information to a legitimate business and not an impostor. In turn, you know that your company is receiving accurate information that the customer cannot later refute. Make online commerce easy for your customers Installing VeriSign Server IDs not only makes e-commerce safer for your customers; it actually makes it easier to submit information, such as a credit card number over the Internet. The Netscape Navigator and the Microsoft Internet Explorer browsers have built-in security mechanisms to prevent users from unwittingly submitting their personal information over insecure channels. If a user tries to submit information to an unsecured site (a site without a Server ID), the browsers will, by default, show a warning, which can make the purchase process seem threatening.
![]() In contrast, if a user submits credit card or other information to a site with a valid Server ID and an SSL connection, the warning does not appear. The secure connection is seamless, making the online shopping experience more pleasant. In addition, when you install a VeriSign Server ID, the 100 million prospective customers with Microsoft and Netscape browsers are reassured that they are shopping on a secure site. Visitors can be sure that transactions with your site are secured by looking for the following cues:
![]() |
|
Enhance sales, convenience, and security with VeriSign Solutions When you have established your secure Web site, you can take advantage of a wealth of options from VeriSign to further enhance your e-commerce operation.
Attract more customers with VeriSign’s Secure Site Seal
|
|
With the Secure Site Seal, included with every Secure Site service, you can display the number-one trust brand on the Internet (Cheskin/Studio Archetype Study) to give your customers the confidence to communicate and transact business with your site. The Seal allows your visitors to check your Server ID’s information and status in real time, and provides additional protection against the misuse of revoked and expired certificates. |
|
A Secure Site Seal icon also appears next to your organization’s listing in Network
Solutions’ comprehensive Web site directory at
http://www.dotcomdirectory.com, alerting every directory user that your site is set
apart from the crowd by VeriSign’s superior security features.
Simplify management of multiple Server IDs Is your site hosted on 10 or more servers? With one simple purchase, VeriSign’s OnSite managed service lets you issue all the Server IDs you need—either standard or universal 128-bit SSL certificates— in bundles of 10, 25, 50, 100, or more. A convenient one-step purchasing process lets you take advantage of a single purchase order, and volume discounts make OnSite the most cost-effective way to secure big sites. OnSite is simple to set up and configure: start issuing server certificates quickly via our intuitive Web-based process. Renewing IDs or buying additional IDs is just as easy. To find out more about OnSite for Multiple Server IDs, go to http://www.verisign.com/server/prd/m/index.html . Learn more about your customers through client authentication A Secure Server ID tells your customers exactly who you are. Suppose you want to learn who your customers are, or to restrict access to your content to certain consumers. You can set up your Web site to authenticate visitors’ identities with VeriSign Server IDs for Individual Users. Compared to asking customers to supply a user name and password, Server ID registration is more convenient for customers and more informative for your business. Visit http://www.verisign.com/clientauth/ for more information and a demonstration of client authentication. Deploy strong security for worldwide commerce
Until recently, strong 128-bit encryption was not exportable. The United States Department
of Commerce has approved VeriSign to issue certificates for 128-bit encrypted communications,
the highest level of encryption ever allowed across United States borders. With a VeriSign
Global Server ID, available from VeriSign as part of its Global Site and Global Site Plus
Services, your international customers can now enjoy unparalleled security when visiting
your Web site. Available to U.S. corporations and banks, financial institutions, insurance
companies, health care organizations and online merchants worldwide, the VeriSign Global
Server ID is a septillion times more secure than any other product. For more information
about VeriSign’s Global Server 128-bit ID, see
http://www.verisign.com/prd/g/index.html
|
| Try a VeriSign Secure Server ID for free
As part of a special offer from VeriSign, you can secure your Web site for a free two-week
trial. To apply immediately for your free trial Secure Server ID, please visit
http://www.verisign.com/server/trial/index.html now. You can complete the entire enrollment
process online in about 15 minutes and immediately begin using your trial Secure Server ID.
|
| Step-by-step instructions
|
|
You can purchase a one-year full-service Secure Server ID as part of VeriSign’s Secure
Site Service from VeriSign by visiting
http://www.verisign.com/server. The application process takes about 15 minutes. In
one to three days, after VeriSign has verified your credentials, you will receive your
Secure Server ID via e-mail. Simply install the Secure Server ID on your server, and then
immediately begin conducting transactions online—with the confidence that you and your
customers are protected.
The U.S. Department of Commerce requires your company to qualify before buying the 128-bit SSL encryption power of Global Server IDs, included with Global Site and Global Site Plus services. All companies within the United States are eligible for Global Server IDs. There are restrictions on certain international companies, which must fall into one of a series of specified categories:
Before you begin Before beginning VeriSign’s online enrollment, check to make sure you are ready to proceed:
To complete your Server ID enrollment, please visit http://www.verisign.com/server. There you will be instructed to complete the following steps.
Options for obtaining payment Congratulations! You can now offer secure transactions to your online customers.
|
|
Conclusion
|
|
With its worldwide reach, the Web is a lucrative distribution channel with
unprecedented potential. By setting up an online storefront, businesses can
reach the millions of people around the world already using the Internet for
transactions. And by ensuring the security of online payments, businesses can
minimize risk and reach a far larger market: the 85 percent of Internet users
who still hesitate to shop online because of security concerns.
|
|
|
|
Appendix: How digital certificates work
|
|
In physical transactions, the challenges of identification, authentication, and privacy
are solved with physical marks, such as seals or signatures. In electronic transactions,
the equivalent of a seal must be coded into the information itself. By checking that the
electronic “seal” is present and has not been broken, the recipient can confirm the
identity of the message sender and ensure that the message content was not altered in
transit. To create an electronic equivalent of physical security, VeriSign uses advanced
cryptography. Throughout history, most private messages were kept secret with single key cryptography. Single key cryptography is the way that most secret messages have been sent over the centuries. In single key cryptography, there is a unique code (or key) for both encrypting and decrypting messages. Single key cryptography works as follows: Suppose Bob has one secret key. If Alice wants to send Bob a secret message:
VeriSign Server ID technology employs the more advanced public-key cryptography, which does not involve the sharing of secret keys. Rather than using the same key to both encrypt and decrypt data, a Server ID uses a matched pair of keys that uniquely complement each other. When a message is encrypted by one key, only the other key can decrypt it. When a key pair is generated for your business, your “private key” is installed on your server; nobody else has access to it. Your matching “public key,” in contrast, is freely distributed as part of your Server ID. You can share it with anyone, and even publish it in directories. Customers or correspondents who want to communicate with you privately can use the public key in your Server ID to encrypt information before sending it to you. Only you can decrypt the information, because only you have your private key. Your VeriSign Server ID contains your name and identifying information, your public key, and VeriSign’s own digital signature as certification. It tells customers and correspondents that your public key belongs to you. For a detailed explanation of Public Key Infrastructure and cryptography, go to https://www.verisign.com/cgi-bin/clearsales_cgi/leadgen.htm?form_id=0152&toc=w028502570152000&email= on the Web.
|
|
|