Monday, November 25, 2024

Chips

 



                                                        -: SEMICONDUCTOR CHIPS :-

Today, semiconductor is heart of technology, beating possibilities. Growth of the semiconductor production revolutionize the growth of technology like Artificial Intelligence, Machine learning, cloud and Edge Computing, Data & Cyber security.  Today we have totally integrated manufacturing facility, starts from a needle to car or airplane manufacturing.


The Commercial Chip manufacturing involves 


1. System definition

2. Architecture design and optimization 

3. RTL (register transfer language) coding (pre- and post-synthesis) simulation        and verification, synthesis, place and route, timing

    analyses and timing closure, and 

4. Multi-step semiconductor device fabrication including wafer processing, die            preparation, IC packaging and testing, et al. 

ASIC:

The invention of ASIC (Application Specific Integrated Services) has caused a tremendous change in our daily lives. Today, we have different types and configurations of IC’s. But these ASICs can be limited only for one specific application while some ICs can be reprogrammed and used for various applications, but these cannot be reprogrammed or neither can be used for general application as they are customized. Moreover, these chips have to be designed from the basic level as they are designed to perform particular task which are highly costly per unit and takes larger time to market margin. The main advantage ASIC chip offers is, it minimizes the size of a chip as it enables to perform the various number of functions of a circuit over a single chip. It includes a 32-bit microprocessor, memory blocks, and network circuits.

Such type of ASICs is known as System on Chip (SoC). With the enhancement in the manufacturing and research technology ASIC chips are developed customizable, due to which they provide low flexibility for programming.The global ASIC chip market is analyzed by type, application, and region. Based on type, the market is analyzed across full custom, semi-based custom and programmable logic devices. On the basis of application, the market is divided into aerospace subsystem & sensor, wireless communication, medical instrumentation, telecommunication products, consumer electronics, and others. Based on region, it is analyzed across North America, Europe, Asia-Pacific, and LAMEA along with their prominent countries. The key players profiled in the report include AMD, Texas Instruments, On Semiconductor, Xilinx Inc., Samsung Electronics Ltd., TSMC, Intel Corporation, Infineon Technologies, Bit main Technologies Ltd., and NVIDIA Corporation. These key players have adopted strategies, such as product portfolio expansion, mergers & acquisitions, agreements, geographical expansion, and collaborations, to enhance their market penetration.

DSP:

​A digital signal processor (DSP) is a specialized microprocessor chip, with its architecture optimized for the operational needs of digital signal processing. DSPs are fabricated on MOS integrated circuit chips. They are widely used in audio signal processing, telecommunications, digital image processing, radar, sonar and speech recognition systems, and in common consumer electronic devices like, mobile phones, disk drives and high-definition television (HDTV) products. The goal of a DSP is usually to measure, filter or compress continuous real-world analog signals. Most general-purpose microprocessors can also execute digital signal processing algorithms successfully. but may not be able to keep up with such processing continuously in real-time. Also, dedicated DSPs usually have better power efficiency, thus they are more suitable in portable devices such as mobile phones because of power consumption constraints. DSPs often use special memory architectures that are able to fetch multiple data or instructions at the same time. DSPs often also implement data compression technology, with the discrete cosine transform (DCT) in particular being a widely used compression technology in DSPs. Digital Signal Processing is used everywhere. DSP is used primarily in arenas of audio signal, speech processing, RADAR, seismology, audio, SONAR, voice recognition, and some financial signals. For example, Digital Signal Processing is used for speech compression for mobile phones, as well as speech transmission for mobile phones. DSP is also used in elite headset equipment to protect users from hearing damage the same suppression and enhancement concept is equally important here. Leading industries in the field of hearing protection and on-the-job communication such as Sensear use Digital Signal Processing to create a safe, quality communication experience. Other applications include Mp3 file manipulation, CAT scans, computer graphics, MRI, and even amplifiers for certain electric guitars.The purpose of Digital Signal Processing is, as mentioned before, to filter the analog signals from current time and space. It is used in a wide variety of technology equipment but, is an especially critical aspect of noise suppression and voice enhancement communication equipment.

Components of Digital Signal ProcessingThere are a handful of different “parts” that make up a successful DSP system:  * Input and Output. This is the interface to the physical world and other devices. In short, analog signals are converted to digital, processed, and then converted back to the analog domain to interact once again with headset users.

  * DSP chip. The “brain” of a DSP system. All of the necessary calculations and algorithms are performed here.  * Memory. This is where DSP algorithms are stored. 

 * Program memory. Like any memory program, the program memory of a DSP stores the programs needed for data to be translated.  * Computer Engine. This is the part of DSP that 

computes all of the mathematical functions that take place during communication.  * Data memory. Storage space for any information that may need to be processed.

FPGA:

Field Programmable Gate Arrays (FPGA) was invented in 1984 by Xilinx. These are integrated circuits that contain millions of logic gates that can be electrically configured (i.e., the gates are field programmable) to perform certain tasks. Any computer like microcontroller, microprocessor, graphic processor or Application Specific Integrated Circuit (ASIC) is basically a digital electronic circuit that can perform certain tasks based on an instruction set. The instruction set contains the machine codes that can be implemented by the digital circuitry of the computer on some data where the data is stored and manipulated on registers or memory chips.

The FPGA takes the design to hardware level where an engineer can design a (simple) computing device from the architecture level and this simple computer is designed  and fabricated to perform a specific application. Though, FPGA can be used to design an ALU and other digital circuitry to perform simple computational tasks, it is in fact no match to a microcontroller or microprocessor in computing terms. A microprocessor or microcontroller is a true computing device with complex architecture. 

However, FPGA is quite comparable to Application Specific Integrated Circuits where any ASIC function can be custom designed and fabricated on FPGA.Mid-range field programmable gate arrays (FPGA) can be defined as those with a logic density count in the range of 100K to 500K as compared to higher density FPGAs with logic densities ranging from 1M to 9M. High-range FPGAs are popularly used in applications such as advanced driver-assistance systems and data centers, while mid-range FPGAs deploy into a variety of embedded applications such as surveillance, gateway deices, small cell wireless applications, medical and industrial imaging, and unmanned aerial vehicle (UAV) monitoring. Microcontrollers let an engineer expertise in high level language or assembly language to design software for a computer, but FPGA let an engineer to design a computer (a simple computing device) by own. This hardware based embedded design requires detailed knowledge of digital circuit design and computer architecture. Like microcontrollers are programmed using Assembly Language or a High-Level Language (like C), FPGA chips are programmed using Verilog or VHDL language. Like C Code or assembly code is converted to machine code for execution on respective CPU, VHDL language converts to digital logic blocks that are then fabricated on FPGA chip to design a custom computer for specific application. Using VHDL or Verilog, an engineer designs the data path and ALU hardware from root level. Even a microprocessor or microcontroller can be designed on FPGA provided it has sufficient logic blocks to support such design.

Static RAM:

Volatile memory devices are types of storage devices which hold their content till power is applied to them. When power is switched off, these memories lose their content. The RAM memory chip, referred to as a main memory, is a storage location that allows information to be stored and accessed quickly from random location withmemory module. The memory cell which can be accessed for information transfer to or from any desired random location is called a Random-Access Memory. A RAM memory is designed with a collection of storage cells. Each cell contains either BJT or MOSFET based on type of memory module.

Dynamic RAM:

The Dynamic Random-Access Memory is a type of RAM module that stores each bit of data within a separate capacitor. This is an efficient way to store the data in memory because it requires less physical space to store the data.A particular size of DRAM can hold more amounts of data than a SRAM chip with the same size. The capacitors in DRAM need to be constantly recharged to keep their charge. This is the reason why DRAM requires more power. Each DRAM memory chip consists of a storage locations or memory cells. It is made up of capacitor and transistor which can hold either active or inactive state. Each DRAM cell is referred to as a bit. When the DRAM cell holds a value at active state ‘1’, the charge is at high state. When the DRAM cell holds a value at inactive state ‘0’, the charge is below a certain level.

​ROM:

Non-volatile memories are permanent storage types of memory chips which can get back stored information even when the power is switched off. An example of non-volatilememory device is Read Only Memory (ROM). The ROM stands for Read Only Memory. ROM can only be used to read from but cannot be written upon. These memory devices are non-volatile. The information is stored permanently in such memories during manufacture. The ROM can store instructions which are required to start computer when power is given to the computer. This operation is referred to as bootstrap. A ROM memory cell is designed with a single transistor. The ROM memory is not only used in the computers but also in other electronic devices like controllers, micro-ovens, washing machines etc. A ROM family is designed with collection of storage cells. Each memory cell contains either bipolar or MOSFET transistor based on types of memory.

PROM:

The Programmable read only memory (PROM) can be modified only once by the user. The PROM is manufactured with series of fuses. The chip is programmed by the PROM programmer wherein some fuses are burnt. The open fuses are read as ones, while the burned fuses are read as zeros.

EPROM:

The erasable programmable read only memory is one of the special types of memory modules that can be programmed any number of times to correct the errors. It can retain its contents until exposed to ultraviolet light.The ultraviolet light erases its contents making It is possible to program the memory. To write and erase the EPROM memory chip, we need a special device called PROM programmer. The EPROM is programmed by forcing electrical charge on a small piece of poly silicon metal known as floating gate, which is located in the memory cell. When charge is present in this gate the cell is programmed, i.e. memory contains ‘0’. When charge is not present in the gate, the cell is not programmed, i.e. memory contains ‘1’.

EEPROM:

EEPROM is a user modified read only memory chip that can be erased and programmed for a number of times. These memory devices are used in computers and other electronic devices to store small amount of data that must be saved when the power supply is removed. The content of EEPROM is erased by exposing it to an electrical charge. The EEPROM data is stored and removed 1 byte of data at a time. The EEPROM does not need to be removed from the computer to be modified. 

The changing the content does not require the additional equipment.The modern EEPROM allows multi byte page operations and has limited life. The EEPROM can be designed 10 to 1000 write cycles. When the number of write operations is completed, the EEPROM stops working. EEPROM is a storage device that can be implemented with fewer standards in cell design. The more common cell is composed of two transistors. The storage transistor has a floating gage similar to EPROM. The EEPROMs has two families which are serial EEPROM and parallel EEPROM. The parallel EEPROM is faster and cost effective then serial memory.

FLASH MEMORY:

The flash memory is the most widely used device for electronics and computer devices. The flash memory is among the special types of memory that can be erased and programmed with a block of data. The flash memory keeps its data even with no power at all. The flash memory is popular because it works fast and efficiently than EEPROM. The flash memory module is designed for about 100000 -10000000 write cycles. The main constraint with the flash memory is number of times data can be written to it. The data can be read from flash memory as many times as desired, but after a certain number of write operations, it will stop working. On-Chip Memory The On-Chip memory is referred to any memory module like RAM, ROM or other memories but that physically exits on the microcontroller itself. Different microcontrollers -types like 8051 micro-controllers has limited On-Chip ROM memory. However, it has a capability of expanding to a maximum of 64KB of external ROM memory and 64KB external RAM memory.

MICROCONTROLLER:

A microcontroller is also called an embedded controller because the microcontroller and its support circuits are often built into or embedded in the devices they control. In this system. When developing an embedded system, one of the options is to base the computational hardware around a microcontroller, MCU rather than a microprocessor, MPU. Both approaches have their attractions, but generally they will be found in different applications. Typically, the microcontroller, MCU, is found in applications where size, low power and low cost are key requirements. The MCU, microcontroller is different to a microprocessor in that it contains more elements of the overall processing engine within the one chip.The majority of microcontrollers in use today are embedded in other machinery, such as automobiles, telephones, appliances, and peripherals for computer systems. While some embedded systems are very sophisticated, many have minimal requirements for memory and program length, with no operating system, and low software complexity. Typical input and output devices include switches, relays, solenoids, LED's, small or custom liquid-crystal displays, radio frequency devices, and sensors for data such as temperature, humidity, light level etc. Embedded systems usually have no keyboard, screen, disks, printers, or other recognizable I/O devices of a personal computer and may lack human interaction devices of any kind.

MICROPROCESSOR:

Embedded processors can be broken into two broad categories. Ordinary microprocessors (μP) use separate integrated circuits for memory and peripherals.

Microcontrollers (μC) have on-chip peripherals, thus, reducing power consumption, size and cost. Modern embedded systems are often based on microcontrollers (i.e., microprocessors with integrated memory andperipheral interfaces), but ordinary microprocessors (using external chips for memory and peripheral interface circuits) are also common, especially in more complex systems. In either case, the processor(s) used may be types ranging from general purpose to those specialized in a certain class of computations, or even custom designed for the application at hand. A microprocessor control program (embedded software) can be easily tailored to different needs of a product line, allowing upgrades performance with minimal redesign of the product. Different features can be implemented in different models of a product line at negligible production cost. An embedded microprocessor is a computer chip used inside several devices and equipment to provide added functionality.

 A microprocessor is a digital electronic component with transistors integrated on a single semiconductor IC that is small and consumes less power. A microprocessor chip is built by using semiconductor devices wherein thousands of transistors are integrated into a single chip for better performance. When we look at microprocessor’s history, the Pentium 4 processors have around 40-50 million transistors. The major microprocessor’s parts include:  * ALU (Arithmetic Logic Unit)  * Memory unit  * Control Unit  * Registers  * System Bus Types of Microprocessors The classification of embedded-microprocessor depends on several factors like computing performance, availability of memory, type of application, etc., and some of these microprocessors include:  * Complex instruction set microprocessors  * Reduced instruction set microprocessors  * Superscalar microprocessors  * Application specific integrated circuit         (ASIC)  * Digital signal microprocessors (DSPs)Microprocessor based

 embedded system has various kind of utility like in home and industrial PC’s, super computers, server and work-station, robotic computers, Satellite and Navigation system, aerospace and defense system.

Power management ICs or PMIC:  

Are the unsung heroes behind sleek smartphones, cars with advanced driver-assistance systems (ADAS), and the highly diverse Internet of Things (IoT) designs. And these power companions to chipset, processor, and memory have constantly been evolving over the decade to optimize power consumption and boost energy efficiency. PMICs regulate, manage, and protect power using a variety of semiconductor devices, including voltage converters and regulators, battery chargers, load switches, sequencers, etc. While PMICs have been a staple in electronics design for many years. It’s because the amount of computation is continuously rising in system-on-chip (SoC) designs

to add more functionality via hardware accelerators running machine vision and other deep learning algorithms. At the same time, however, these powerful chips with multi-core CPUs and GPUs demand circuitry that further enhance energy efficiency and create more flexible power sequencing.Three major factors driving innovation in PMICs and new in power management footprint in embedded computing systems. 1. Greater Integration 2. Adaptable PMICs3. Automotive and Industrial IoT.












Monday, December 4, 2023

Dark Matter



DARK MATTER:

Dark matter hypothesis, we can try to justify using newtons universal law of gravity: There is a stronger gravitational field at larger distances. Also, additional unseen mass is provided to understand the hypothesis. Both Milgrom’s modified Newtonian dynamics (MOND) theory and Robson’s recent quantum theory of gravity provided by the generation model (GM) of particle physics is used to understand dark matter hypothesis.

Phenomenon:

The notion of “dark matter” emerged from several astronomical observations concerning the structure of galaxies, the rotation of stars and neutral hydrogen gas in spiral galaxies, the motions of clusters of galaxies, and so on. The cosmological discontinuity with Newtons Universal Law of Gravity described as dark matter.

Here cluster contained considerably more “dark matter” than the visible galactic matter in order to account for the fast motions of the galaxies within the cluster and also to hold the cluster together. 

One explanation for dark energy is that it is a property of space. Albert Einstein was the first person to realize that empty space is not nothing. Space has amazing properties, many of which are just beginning to be understood. The first property that Einstein discovered is that it is possible for more space to come into existence.

One version of Einstein's gravity theory is that contains a cosmological constant, makes a second prediction: "empty space" can possess its own energy. Because this energy is a property of space itself, it would not be diluted as space expands. As more space comes into existence, more of this energy-of-space would appear. As a result, this form of energy would cause the universe to expand faster and faster.

First, it is dark, meaning that it is not in the form of stars and planets that we see. Observations show that there is far too little visible matter in the universe to make up the 27% required by the observations. Second, it is not in the form of dark clouds of normal matter, matter made up of particles called baryons. We know this because we would be able to detect baryonic clouds by their absorption of radiation passing through them. Third, dark matter is not antimatter, because we do not see the unique gamma rays that are produced when antimatter annihilates with matter. Finally, we can rule out large galaxy-sized black holes on the basis of how many gravitational lenses we see. High concentrations of matter bend light passing near them from objects further away, but we do not see enough lensing events to suggest that such objects to make up the required 25% dark matter contribution.

Standard model of cosmology assumes that the universe is now composed of about 5% ordinary matter, 27% dark matter, and 68% dark energy, so that dark matter constitutes about 84% of the total mass, while dark energy plus dark matter constitute about 95% of the total mass-energy content of the universe. 

The existence of dark matter in the universe suggests that one requires new physics beyond the SM. Three such particles have been searched for without success: 

(1) axions 

(2) weakly interacting massive particles (WIMPS), and 

(3) sterile neutrinos. 

These three particles are all hypothetical particles

Expansion of the Universe:

Unlike normal matter, dark matter does not interact with the electromagnetic force. This means it does not absorb, reflect or emit light, making it extremely hard to spot. In fact, researchers have been able to infer the existence of dark matter only from the gravitational effect it seems to have on visible matter. 

The distribution of dark matter, galaxies, and hot gas in the core of the merging galaxy cluster Abell 520. The result could present a challenge to basic theories of dark matter. It might have so little energy density that it would never stop expanding, but gravity was certain to slow the expansion as time ticking on. the expansion of the universe has not been slowing due to gravity, as everyone thought, it has been accelerating. The universe is full of matter and the attractive force of gravity pulls all matter together. Roughly 68% of the universe is dark energy. Dark matter makes up about 27%. The rest - everything on Earth, everything ever observed with all of our instruments, all normal matter - adds up to less than 5% of the universe.

Neutrinos:

Neutrinos could be key particles to unravel the nature of the DM in the Universe. It is clear, though, that massive neutrinos and dark matter are both part of nature and should be incorporated in models of physics beyond the standard model. It may be that they are related to each other and that, in addition, both originate from new physics at the TeV scale.

Astrophysical and cosmological evidence implies that neutrinos have masses, neutrinos provide only a small cosmic dark matter component. The study of solar neutrinos provides important information on nuclear processes inside the Sun as well as on matter densities. Moreover, supernova neutrinos provide sensitive probes for studying supernova explosions, neutrino properties and stellar collapse mechanisms. Neutrino-nucleus reactions at energies below 100 MeV play essential roles in core-collapse supernovae, explosive and r-process nucleosynthesis.

With this we also consider Milgrom MOND theory, Robson quantum theory of gravity to emphasize the dark matter hypothesis. The possible mass discrepancy within a galaxy led to the dark matter hypothesis whereby each spiral galaxy is embedded within a huge spherical halo of dark matter. The only alternative to dark matter was considered to be an appropriate modification of Newtonian gravity to provide the required extra gravitational field at large (galactic) distances.

One theory suggests the existence of a “Hidden Valley”, a parallel world made of dark matter having very little in common with matter we know.

Wednesday, June 21, 2023

Network Security

 


Network Security:

1. How does it works?

 

When a single computer connects to the other computer in network for data exchange it becomes member of computer network. Computer network is made up of number of different computer and components. There are different type of computer networks like LAN, WAN, MAN, ETHERNET, Fibre Optic etc. It runs on different communication protocol. An end user can connect to World Wide Web using internet connectivity. For that end user first connects to Area ISP (Internet Service Provider) and after providing their login details it connects to the web.

 

2. How do we get benefited?

 

When net communication happens there are chances of different type of damages and losses happens to the network. Network security ensures and prevent this type of losses and provides solution to prevent and minimise the damages to the network. Network security monitors communication and connectivity runs throughout the network. Also it looks for Data flow control, speed control, Timing and error free communication. For that security software applies different checksum and algorithms. 

There could be Data loss, Connectivity loss, loss due to failure of hardware and software. As soon we overcome this basic situation, we secure fast, reliable & error proof computer network.

 

3. Types of Network Security:

Network security problems can be divided roughly into four closely intertwined areas: secrecy, authentication, nonrepudiation, and integrity control. There are different kind of networks as we mentioned, so as different kind and level of security we requires for the network. Security we require within and outside network for inbound and outbound data movements. Also when we are connected to the internet we require online security of our system and connectivity.

 

     Network Access Control

Network Access Control is about user’s login to network and exploring the resources of network. For that user have to go through secured login process and their credential in detail. We require some of following network protocols while accessing network resources like,

Protocol Use

20, 21 FTP File transfer

22 SSH Remote login, replacement for Telnet

25 SMTP Email: Simple Mail Transfer Protocol

80 HTTP World Wide Web: Hyper Text Transfer Protocol

110 POP-3 Remote email access: Post office Protocol Version 3

143 IMAP Remote email access Internet Message Access Protocol

443 HTTPS Secure Web (HTTP over SSL/TLS)

543 RTSP Media player control: Remote Transfer Server Protocol

631 IPP Printer sharing

 

 

SSL/TLS: SECURE SOCKETS LAYER/TRANSPORT LAYER SECURITY

 

SSL builds a secure connection between two sockets, including

1. Parameter negotiation between client and server.

2. Authentication of the server by the client.

3. Secret communication.

4. Data integrity protection.

So using the secured protocols we can allow or restrict network resource’s access to user. We can restrict hackers attempt for data hacking, program interrupting, Network attacking etc. And so this way we can secure our Banking and Financial organization, Atomic and Space Premises, Scientific Laboratories etc.

 

b. Antivirus and Anti malware software 

Antivirus is only a computer generated specific program like other computer programs. Which allows routine program functioning properly without any errors. It removes unwanted harmful data bytes and malware bytes from functioning which causes disturbances not only to program software but also to operating system. Antivirus programs follows strict routine, it could be while system boots up for first time or periodically on fix time routine. It finds out bad bytes and delete its registry, remove it thoroughly from the system.

Antivirus program provides protection against Malware, Spyware, Theft, Intrusion and Ransomware. Also it provides parental guidance security for students. This kind of security available for Offline as well for online systems.

 

c. Application security

When we concern about Application Security in Network, it starts with what kind of network it is serving. Because the network is wide spread made of different smaller network inside of it. Also it growing rapidly. So application is driving force to the data flow through the network. So its functionality and availability at particular time is real issue to deal with. Because today all the network is application oriented and application dependent. In early days data resource was accessed from local data base like LAN network. But now a day’s network has become more complicated and same data base is access from number of resources. So the same data base should available to different resource at the same time. So the dedicated application which can avail all the data resources at the same time should be there, on both the end i.e. client & server. So the new network architecture should be able to adapt, manage and deploy the complicated application. So this requirement prompting the transition from traditional network to software defined network (SDN). Juniper Networks is building network infrastructure that will enable organizations to effectively make the transition to virtualized networks, while maintaining access to existing data and applications and preserving investments in network hardware infrastructure.   

These days’ data centres are migrated to cloud based infrastructure and so the applications used are cloud based only. The single product sale consumes whole cloud network, which includes a barcode marked product at sale terminal, which belongs to cloud base data centre and card swiping POS machine which tally the financial data of consumer with the store data centre which includes inventory and finance section. Also company sales online. This way this infrastructure becomes three tier which includes web front end, a business logic tier and backend data store. All running on rack of servers. T

he multi-tiered nature of the applications required additional network services ms to secure these applications. Which takes care of application security, its functionality and availability.

d. Behavioural analytics 

Behaviour of network should be very tactile towards its compatibility and adaptability to a new environment. I.E. Computer hardware/software devices & program added to the network. It should be quick responsive when incompatible part or malicious software program is added to network. Which discard it immediately. That way only balanced network maintained only.

There are multitier security concern over network behaviour, which starts from higher end network products Like VSAT, Mainframe computers, Servers, Routers, Modems, IPV4 & IPV6 devices to end user computer. These components belongs to different network like LAN, WAN, MAN, WIFI, FIBRE OPTIC, ETHERNET, CLOUD network.  These networks runs over different network communication protocols. Existing present network is only outcome of evolution. The major issue of network is its global presence and which requires large scale maintenance & care and its nature of expanding broad way. Which raises its compatibility issue towards existing network. The smallest incompatibility of cable can raise issue of communication malfunctioning throughout the network.

In 21st century Network and Datacentre belongs to private, Public, Corporate, Defence, Educational Institution, Space organization or Scientific Laboratories migrates to Cloud based network. When these networks migrate to Cloud based network, issues like Data security, Data Integrity, Data Resource, Communication security, Cost Effectiveness is raised. Both network existing one and Cloud based have to go through compatibility issues which conclude behavioural analytics only.

                      

e. Data loss prevention

Computer Network is made of number of computer & network components. All they have common work function is secured loss less data flow. Network administrator do everything to overcome data loss problem. The data security requires multilevel counselling of network representative who is actually responsible to answer the kind of data, where data is traveling, type and level of data security breach should be stop. It includes different territory people belongs to different service networks and of different hierarchy. They belongs to Seller network and Buyer network and intermediate Service Provider network. In short with General Data Protection System we can secure the data. And Assessing security risks, Preventing attacks, Monitoring to detect breaches and Quality of protection is key ingredients of protection system. By reducing access to data by employing Privileged and Fine grained users where persons and purpose oriented data access is carried out, we can protect data. Also minimize data exposure we reduce chance of data loss. Data auditing can be fruitful to protect data.

To prevent the communication and data loss they employed various methods like Encryption of data to secure it from Hecker. By employing data scramble and less links we can hide data partially. So intentionally or accidentally we can make data less visible or invisible to entity. They employ different communication protocols, algorithm, topologies to prevent communication and data loss. They employ different transmission media and methods to speed up the network communication and to overcome communication loss. This way only we can obtain key security objectives. Three categories assessment, detection and prevention can reduce data theft and data loss. The data security should be inbuilt or by default in system and security should be centralized and comprehensive throughout the system.

Threats to data base is arises from some of entry points like Operating System, Database itself and applications. So threats arises need no to be from outside, also people associated to the organization can damage from inside of system through entry points. By locating personal data to secure, by creating security profile and by employing privileged users to data base we can secure the database perimeter. With data masking and sub-setting the address of data we can edit the data base for outside user to access. We provide them a copy of data base with tailored personal details in database.

Thus by securing our data base servers, application servers, data base firewalls, network encryptions, gateways and other devices we can restrict the data loss.

 

f. Email security 

E-mail is sent between two points. When e-mail is sent over network it is go through various computers before reaching to its destination. So various computer resources can read it. So it is not secured communication way. To make it secure we should find out secured way to handle it. By using PGP (Pretty Good Privacy) or S/MIME (Secure – Multipurpose Internet Mail Extension) protocol we can secure e-mail between two end points. I.E. Sender and Receiver.

PGP:

It is complete secure package for e-mail which provides security measure for e-mail like, Authentication, Privacy, Digital Signature and Compression. It is simple and open source, so comes with source code and no price available on internet. It is available for UNIX, LINUX, and WINDOWS & MAC OS.

PGP encrypts data by using a block cipher called IDEA (International Data Encryption Algorithm), which uses 128-bit keys. PGP supports four RSA key lengths. It is up to the user to select the one that is most appropriate. The lengths are:

1. Casual (384 bits): Can be broken easily today.

2. Commercial (512 bits): Breakable by three-letter organizations.

3. Military (1024 bits): Not breakable by anyone on earth.

4. Alien (2048 bits): Not breakable by anyone on other planets, either.

 

S/MIME:

It provides Authentication, Data Integrity, Secrecy and Non- Repudiation. It also is quite flexible, supporting a variety of cryptographic algorithms. Not surprisingly, given the name, S/MIME integrates well with MIME, allowing all kinds of messages to be protected. A variety of new MIME headers are defined.

 

 

g. Firewalls 

 

There are number of computers added to network every moment, in Corporate Houses, MNC’s, Government Organizations, Educational Institutions, Defence Organizations, and Scientific Laboratories etc. Adding of single new computer to network or LAN brings Virus or Bug threats to whole network. Any single computer can be responsible to destroy the whole network or LAN inside a company. Even IPSec cannot secure the bad bytes entering the network. It has nothing to do with it.

Firewall system protection is nothing but modern adaption of old medieval security standby. Digging a deep moat around a castle. Everyone passes through in or out of castle has to pass through a bridge where they inspected by I/O police. Same way in a company all LANs connected arbitrary way but the inbound and out bound traffic is passes through firewall only. Firewall is used as Packet Filter. Filter is designed with some rules where which bytes should allow go in or out. Also a table entry for source/destination location. Like TCP/IP protocol, where port number is allotted in IP address. We can define particular port address with data packets are allowed in or out to travel through firewall.

The other practice is like implementing Demilitarized zone. Where web server is put outside secured LAN. Then firewall is configured to block the requested data packets particular port number. And now webserver’s request to contact particular port number is turned down by firewall. This way firewall system is implemented. This is network layer filter for firewalls. Firewall can see into transport and application layer data for filtering. Where some peer to peer applications selects the port dynamically to avoid easily being spotted. And this way firewall security breach happens. So firewall has to see into data packets what they carry. And firewall is entry level check point only, but each system belongs network turned on their own firewall security.

Some time there is security breach carried out not to steal data but for shutting down the network. It is called Denial of Service (DOS) attack. Also there is Distributed Denial of Service attack is carried out where number of already hacked computers attacks common target computer. And in this case it is hard to find out attackers as they are unsuspecting user.

 

h. Intrusion prevention system

 

Intrusion detection and prevention is key ingredient of network security. In any network data availability, data security and data flow defines the network efficiency. When it comes to data security, it is bit or byte level. Security of data in various layers of OSI model. Also different data security protocol e.g. IPSec and secure login procedure like SSL/TLS is employed for entry point security. Where data integrity and security with secure data communication between client and server is carried out. This type of communication is carried out after secured authentication only.

Also we design and define special firewall system dedicated to intrusion prevention system. Where inbound and outbound data traffic is checked at bit level. Data auditing is carried out with operating system and system database. Alert is being issued to firewall system by this kind of auditing system if malicious software is trying intrude the database.

Also Data encryption, data encapsulation, data scrambling and data hiding program is being employed. And data is assorted in Public, Private and Protected class. That way we can restrict direct access to the database. We partially hide data to end user.  This kind of protection is necessary because threat is not from only outside but people associated to the system also brings or sends bad bytes through system. By enforcing privilege access level to priority database. We have to develop the intrusion counter measure system. Where we have to define the system rules and regulation. Also we can enforce penalties to the responsible, engaging in unlawful and suspicious activities. These days antivirus software is available which is capable handling malware byte, network intrusion, data theft for domestic and commercial users. But when we talk about large infrastructure we require security system is by default or within and throughout the system comprehensively. A security module within a network system.

 

I. Mobile device security

 

When we talk about mobile devices, as their name they are identified with mobile network only. These devices can be wireless Smart Cell phones, Smart Watches, Laptops, Printers, Telephony or Gaming devices. They can be connected to network wirelessly with cell phone network (3G/4G) or 802.11 Wi-Fi hotspot. Which is available at Malls, Theatres, Stadium, Offices, and Institutions etc. So one can get online or stay connected by staying away from home or offices. Where one is travel by Road, Air or Sea.

The Electronic Reader device downloads daily Newspapers, subscribed newsletter and articles. Mobile devices are GPS enabled and E-Cars and Taxi companies line UBER and other runs over Wi-Fi network through mobile applications. Even parking meter payments done with Wi-Fi enabled electronic parking meter. Today Web network becomes big online market where every small and big companies are selling their products online with Mobile Applications. We can order grocery through application. Even we can do the payment and get the receipt for the payment. So with the Wi-Fi networks we can do business, banking, financial transaction, stock purchase etc.,  in embedded system piece of computer hardware monitors data of system like Air conditioner or Geyser and communicate with mobile phone to turn it On/Off or update the status. In automation industry we can operate and monitor the data of the system even when we are away from the system. Also Wi-Fi network used in military and defence where single message or command can wedge a war in fraction of seconds. So the security measures taken to survive with this network is of very high level. We can track these device over network using their IP address under IPV4 and IPV6 devices.

We have 2G/3G/4G mobile network and with Wi-Fi hot spot for wireless communication. They are basically belongs to Advanced Mobile Phone system (AMPS), Global System for Mobile communication (GSM), Universal Mobile Telecommunication  System (UMTS), General Packet Radio Services (GPRS) , Long Term Evolution (LTE). Also Wi-Fi network like 802.11 and WiMAX network (Worldwide Interoperability for Microwave Access) 802.16 (Broadband Wireless). Which uses Orthogonal Frequency Division Multiple Access (OFDMA 802.16e mobile WiMAX, and OFDM 802.16a Fixed WiMAX).  To speed up the communication Wi-Fi network transmit four stream of data with four antennas at a time and can be managed at receiver side using Multiple Input Multiple Out (MIMO) techniques Security threat to these network arises as data transmitted through these devices can easily receive by other computers. So using Wi-Fi Protected Access (WPA2) advanced encrypted communication can be carried out. Using SSL/TLS, IPSec protocol we can carry out authenticated secure communication. In earlier days of Web, there were simple web pages with web sites. Now a days there are Java Applets, ActiveX control and JavaScript to download. So be the security issues arises with the downloading and executing the mobile application codes.

 

j. Network segmentation

 

Computer Network is made up of number of network components. All the network has their own identity, work function, priority, privilege and hierarchy. They all have role to play to make network run.  If we can differentiate network inside of network then we can also identify network components inside of that network.  We can differentiate them to bit or byte level data frames. We can call them Network Segments.

The environment of network segments changes as network infrastructure changes. Networks segments have one common goal i.e. speed up the data flow and error free data communication. And for that it is distributed throughout the network for data processing. We have different kind of networks like, Personal Area Network, Local Area Network, Wide Area Network, Metropolitan Area Network, Internet network and Cloud base network. Among Cloud base network is latest and state of art network infrastructure. Where each Repeater, Hub, Bridge, Switch, Router and Gateway is network segments. Each of this segment in network is well defined. Also different communication method is employed. Like Ethernet, Fibre Optic, DSL, VSAT etc. Each of this communication carried out with their own different communication protocols.

When it comes to cloud base infrastructure there is basically three types of cloud services 1. Public 2. Private and 3. Hybrid. Also three basic cloud service models are there. They are 1. Software as Service (SaaS) 2. Platform as service (PaaS) and 3. Infrastructure as service (IaaS). When we bring this infrastructure into practice and start doing business it is very costly. Because here each of segment or device belongs to network is charged on hourly basis for monthly billing cycle. Where Each CPU is counted for the services. E.G. if we look for IaaS, the network segment is Standard CPU and High speed CPU in virtual server, and with virtual private server at least two host is required. Same way it is employed for virtual server for SAP and Virtual private server for SAP. There is Operating system, Middleware, Storage and Networking component or segments are counted on hourly basis. Cloud service is very safe, secure and reliable data communication infrastructure.

It is good each segment of network is identical to each other. They have their own work definition. Due to network segments this property only, network becomes self-sustain once configured. As network is growing in nature, network maintenance & care is routine requirement. All the future model of network is designed in such a manner they can complement the existing network. They should be compatible. So each network segment can become a key to define the future networks.

 

k. Security information and event management

 

Event Management in the context of network security includes the securing data and data flow at particular point. For securing network data we employ different algorithm, topologies, protocols and communication media and methods. With modern equipment we implement layer based communication. We employ the peer to peer communication. And so we have to secure the data bit/byte level. We have to manage the event of data security and data communication where actually it is carried out. That way only we can do effective communication.

We have different communication junction where we carry out communication like routers, switches, bridges, tunnels, firewalls, gateways etc. So we are managing event ingredients like protocols, algorithms, topologies etc. at particular node. We may have security breach by intruder who can crack our data and to secure our data we have to take counter measure at basic level. We have IPSec protocol which do have security information in its frame header. Also using cryptography we can secure our data. We have encryption key and decryption key at sender and receiver end. The cipher text we transmit is being protected by these keys which have to change every time we use cryptography. We have antivirus software which can provide operating system level security.

As soon we draw a tunnel in Metropolitan Area Network where a company is having corporate offices at various location. Here office employee can stay in touch of office while he is roaming. So secure data login through SSL/TLS is employed. With firewall we can monitor inbound and outbound data and restrict unwanted data communication.

Thus security information and event management is a key parameter to efficient network communication & data protection.

 

l. VPN

 

The term VPN (Virtual Private Network) is highlighted for its functionality and features available of network security of Private Network while running over a Public Network. A private network is made up of computers and dedicated communication Leased Line across the company’s wide spread or global office network. Here data security is prime but it is very costly. While in case of Virtual Private Network we design or overlay our secured private network over a web or internet. I.E. Public Network a network is made up of Firewalls, Tunnels, IPSec and ESP (Encapsulating Secure payload) with Tunnels.

 We can dig a Tunnel between pair of Firewalls of office network. Where data has to pass through Firewalls Including services, modes, algorithms and keys. When system turns on each Firewall have to negotiate with the parameters of its SA. Using IPSec for Tunnelling we can manage all aggregate traffic between pair of firewalls over single, authenticated encrypted SA of office network. This provides integrity control, secrecy and even considerable immunity for data analysis. Using IPSec followed by IP in data frame separates data flowing through public network to a private network.

The other feature is laying a VPN across ISP network to pair of firewall point of office network. A network administrator can configure and monitor the VPN gateways, while ISP administrator configure MPLS (Multipoint Label Switching) path. Here VPN runs over internet with completely isolated security software. Which is transparent to all user software.

 

m. Web security

 

There are three major issues related to Web Security.

1.       How are objects and resources named securely?

2.       How can secure and authenticated connections be established?

3.       What happens when Web site sends client executable codes?

Web security is major chaos in web world. The problem arises with day to day expansion and upgradation of network. Major corporate houses like Cisco, SAP, Oracle, Citrix etc., publishes Whitepapers over the issue. They organizes Workshop and Seminars to overcome the threat provided by the network invaders. They are called hackers and more sophisticated word is Crackers. In their world they are more sophisticated programmers or ingenious.

Threat they provide is like changing of Web Pages of Web Sites, Slowing Down network traffic by flooding particular web site over number of computer with data packets. They Spoof into secured data base of the company, they crack the banking system codes and clear the account balance, and they can be responsible for fall of stock prizes of company.

Area related to Web Security is, a. Secure Naming b. DNS Spoofing c. DNSsec

Here DNSsec conceptually is extremely simple and based on public key Cryptography. DNSsec offers fundamental services.

1.       Proof of where the data originated

2.       Public key distribution

3.       Transaction and request authentication

Secure Sockets Layer (SSL)

After Secure Naming it is about secure connection. Netscape Communication Corp. come up with SSL solution where security of banking and financial data transaction is carried out. NETSCAPE, MOZZILA, INTERNET EXPLORER is using SSL.

SSL build a secure connection between two socket including

1.       Parameter negotiation between client and server

2.       Authentication of server by client

3.       Secret communication

4.       Data integrity protection

A browser uses SSL is going through following layers.

Application (HTTP)

Security (SSL)

Transport (TCP)

Network (IP)

Data link (PPP)

Physical (modem, ADSL, cable TV)

TLS is Transport Layer Security derived over SSL Version 3.

 

Mobile Code Security:

In earlier days of Web, there were simple web pages with web sites. Now a days there are Java Applets, ActiveX control and JavaScript to download. So be the security issues arises with the downloading and executing the mobile application codes.

Browser Extension:

There are Browser Extension, Add-ons and Plugins which provides the browser’s Compatibility with applications like PDF, Flash animations etc. There could be malicious software add-ons and plugins. They should be downloaded from trusted sources only.

Virus:

Virus is simple program which executes itself when it is called upon. It is unwanted element come up with unreliable web applications, e-mail attachments or malicious software program. When any application in system runs, next moment control transfers to virus program. Which infects other applications like e-mail and try to spread over other computer system. Some virus starts on booting of computer and destroy the computer system. So now the OS are come up with secure microkernels and tight compartmentalization of users, processes and resources.

 

n. Wireless security

 

System we design with VPN and Firewalls are secured ones. It provides enhance features of safe system. But when it comes to Wireless communication the wireless system transmit Radio packets right over fire wall in both direction. Wireless is snooper’s dream come true. It is free data without having to do any work. There for wireless system requires more security then wired systems.

Now 802.11 provides data link level security. 802.11i‘s function is to prevent receiving or interfering communication carried out by the another two nodes. It is also knows by its trade name WPA2. I.E. WIFI Protected Access 2. Plain WPA is interim scheme that implements subset of 802.11i. It should be avoided in favour of WPA2. 802.11i is used for corporate network as well for home use. While it is used for corporate use it is using client server application using 802.1x secure protocol. We can check the client-server authentication using Extensible Authentication Protocol. While we use 802.11i for home purpose we don’t use server instead single password issued to client for authentication. This way home use of 802.11i has less secured authentication and communication.

Bluetooth Security

Bluetooth security can also be breached. Bluetooth V2.1 on ward Bluetooth devices are protected with 4 security modes. It is starting from nothing to full data Integrity and Encryption control. Before Bluetooth V2.1 arrive, new device to Bluetooth allotted channel with predictable passcode like 1234 to enter in both devices. Which was less secured and breakable. After Bluetooth V2.1 master slave device allotted only a channel which is secured, integrity controlled and encrypted. Before communication starts master/slave make sure there is no other device is getting passkey.

                                                  


Chips

                                                                       -:  SEMICONDUCTOR CHIPS :- Today, semiconductor is heart of technolog...