IBM®
Skip to main content
    Country/region [select]      Terms of use
 
 
   
     Home      Products      Services & industry solutions      Support & downloads      My IBM     
Security  >  Products

Security solutions

   
 
Crypto-based Transactions (CBT)
Security is vital when e-business is conducted over open networks such as the Internet. If security is not addressed properly businesses are exposed to severe risk.
In response to the needs expressed by customers IBM has developed a large set of security offerings. One of them is called Crypto Based Transactions (CBT) and is used for secure logon and signing of agreements using digital signatures. CBT is a family of products developed at the EMEA Crypto Compentence Center in Copenhagen. It has been developed during the last 8 years in tight cooperation with many banks and has been deployed in many countries world-wide.
CBT Thin Client Applets

The CBT Thin Client Applets is a collection of small Java applets which can be executed in a browser. They are primarily used as security components in client-server web applications to provide security mechanisms such as digital signatures and encryption. By using CBT, a web application will be able to establish the identity of end users, allow them to digitally sign transactions and achieve confidentiality and integrity of data sent between client and server.

The CBT applets can be used to secure many different kinds of web applications such as:

  • Internet banking applications - allowing users to manage their accounts, transfer money, buy and sell stocks etc.
  • E-government portals - allowing citizens to access services provided by governments and municipalities.
  • E-commerce sites - allowing customers to buy goods on-line from Internet shops.

CBT can be used both in open PKI environments where trusted third parties act as Certificate Authorities (CAs) and Registration Authorities (RAs), as well as more closed environments where no third parties are involved.

Main benefits of CBT Applets

  • The applets do not require installation on the client computer as the applets are downloaded on each access to the web application. This makes it possible for the end-users to be mobile and it removes the burden of handling installations, software updates etc. Automatic installation of the applets on the client system can be done via the Internet if desired.
  • Many different client platforms and browsers are supported including Windows, MacIntosh and Linux.
  • The applets have a very simple and user friendly graphical user interface (GUI).
  • All major Certificate Authorities can be supported.
  • Both key files and hardware tokens (e.g. smartcards) can be used with CBT.
  • Open standards are used for interoperability such as PKCS, PKIX, X.509, XML dig. sig., XML encryption etc.
  • CBT can achieve true end-to-end security which is not possible with normal SSL.

CBT Solution White Paper

The following white paper describes the CBT solution in more detail. It is targeted for solution architects who want to learn how CBT is used in a portal or web application. Read more in this white paper.

CBT and Phishing Attacks

Phishing is the fastest growing fraud on the Internet and has recently been given a lot of attention in the media. CBT and digital signatures can be used to secure Internet applications against phishing attacks. Read more in this white paper.

CBT and Tivoli Access Manager

CBT integrates well with the Tivoli Access Manager product. Specifically, CBT can extend the available authentication capabilities in TAM. For example, CBT plug-ins for TAM has been developed to support large authentication frameworks and ID services offered by governments and banks in the Nordic countries.

CBT Server components

The CBT Thin Client Applets are complemented by a set of server components which handle tasks such as verifying digital signatures, decryption of messages, communication with external CA's for e.g. revocation checks and other PKI related checks. The server components run on several platforms and they support IBM cryptographic hardware.

The server APIs are available as an integrated component which performs all necessary checks on signed messages, including status check of certificates via the CRL or OCSP protocols. This makes the CBT components easy to use from the service provider’s applications.

Related links
IBM Cryptographic Toolkits
IBM Tivoli Access Manager for Business Integration
WebSphere Everyplace Chip Operating System

Ready to buy?
Contact your local IBM representative or directly.
ccc@dk.ibm.com


    About IBM Privacy Contact