Tech Talk: What is Public Key Infrastructure (PKI)?

  Рет қаралды 95,310

IBM Technology

IBM Technology

Күн бұрын

Learn more about encryption → ibm.biz/BdPu9v
Learn more about current threats → ibm.biz/BdPu9m
Check out IBM's data encryption solutions → ibm.biz/BdPu9K
Ever wondered how HTTPS actually works - or public key infrastructure, or symmetric and asymmetric cryptography?
Jeff Crume and Dan Kehn break it all down for you in this video.
Get started for free on IBM Cloud → ibm.biz/cloud-tier-gratis
Subscribe to see more videos like this in the future → ibm.biz/subscribe-now
#crytopgraphy #cybersecurity #encryption

Пікірлер: 133
@sofianeini
@sofianeini Жыл бұрын
4:47 secrets are encrypted with Public keys and decrypted by Private keys.... The other way around would expose the secret.
@homebarista
@homebarista Жыл бұрын
I wondered how long it would take for someone to point that out! 😅 You're correct, in the case of sending a symmetric encryption key I was responding to, the SENDER would encrypt it with the public key of the RECEIVER and then the receiver would decrypt it with THEIR private key. If the SENDER used their private key to encrypt it, then anyone could decrypt it using the [presumably well-known] public key of the sender.
@wizard_in_oz
@wizard_in_oz Жыл бұрын
Talking on a simplistic level, the problem is solved by the 1) client generating the symmetric key, 2) encrypting it with the server's public key and 3) sending it to the sever, which then can 4) decrypt the encrypted symmetric key with it's private key. 5) Thereafter, the communication can proceed in an encrypted manner (encrypted with the exchanged symmetric key)
@sofianeini
@sofianeini Жыл бұрын
@@wizard_in_oz absolutely, and this is exactly how SSL/TLS ,SSH tunnels are created for example.
@michaelf2646
@michaelf2646 Жыл бұрын
100% Correct. Wonder why none of these guys presenting caught that. 😂
@homebarista
@homebarista Жыл бұрын
​ @Michael F ​Sigh! When I'm speaking spontaneously and rapidly, I sometimes use the wrong word. Senior moment? Jeff obviously knows security - he even teaches it at our local university. Either he missed my error in the moment or was being kind.
@Dalai33
@Dalai33 2 ай бұрын
Why no one else in the earth has explained this to me this very simple way? 90k college loan and still watching youtube. Thank you IBM and the gentleman on the right. You are such an awesome free thinking teacher
@jeffcrume
@jeffcrume 2 ай бұрын
I’m glad this explanation made sense to you!
@earthling_parth
@earthling_parth Жыл бұрын
This was one of the best explanations of PKI that I've heard. Amazing job guys 👏
@jeffcrume
@jeffcrume Жыл бұрын
Thanks so much for the kind words of encouragement! It’s a complicated topic and I had to take some liberties with the explanations in order to fit the time constraints, but, hopefully, it shed some light on a really fascinating, but gorpy, topic
@nishantdalvi9470
@nishantdalvi9470 Ай бұрын
@@jeffcrume Hey in this video it is been said that any one key can be arbitrarily chosen as a public key but i was under the impression that once the key pairs are generated they are specifically private and public because of the derivation of one key from the another i.e. We can't derive the private via the help of public key if we possess it but we can derive public key with the help of private key which distinguishes these key from each other and we can't randomly select any one key as the public from the available pair
@15LVV
@15LVV 3 ай бұрын
Observation that I found amusing. In order for their writing to be read by us, they rendered the video horizontally reversed. But here's the cool thing. The guy on the left was so committed to the reversal process, he swapped his wedding ring to his right hand, so it would show left in the video. I pose this concept for discussion and debate. ;)
@NassimDhaher
@NassimDhaher Жыл бұрын
I know PKI but keep forgetting it, once or twice a year I come to these videos to remind me. Thanks for the objective content.
@angelotalabert4942
@angelotalabert4942 Жыл бұрын
this one was definitely great the conversation style makes it easy to digest
@Michaelno
@Michaelno Жыл бұрын
Studying Cyber Security, this video really helped me get a visual. The book was slow and dry.
@manawardhana
@manawardhana Жыл бұрын
Simplicity and brevity at their best! Thank you!
@SNDVeteran
@SNDVeteran Жыл бұрын
Learned this in network defense essentials and this is a execellent video for briefly explaining cyptography.
@REZAZIMohamedabdessamed
@REZAZIMohamedabdessamed 11 ай бұрын
This is really a good and clean approach of clarifying the term!
@s.gardner7576
@s.gardner7576 Жыл бұрын
This is some very clear and really exciting stuff. Haven't seen many people break this down in such a way making it so easy to understand. Good stuff guys!
@when_life_gives_you_limes
@when_life_gives_you_limes Жыл бұрын
A very concise talk about PKI. Awesome!
@StopWhining491
@StopWhining491 Жыл бұрын
Very clear explanation; thanks for somewhat demystifying PKI.
@user-hn8mr6yk8p
@user-hn8mr6yk8p 22 күн бұрын
Great explanation to clear any confusion with this topic, much appreciated!
@sitrakaforler8696
@sitrakaforler8696 Жыл бұрын
More pedagogy than during my bachelor 😭 Keep it up!!!!!
@michaelmorrison3614
@michaelmorrison3614 Жыл бұрын
Wow....this is amazing content!! Well done! Thank you
@1VArtt
@1VArtt 2 ай бұрын
A very clear audio simulation of nails on a chalkboard. Thank you
@AnujTechShorts
@AnujTechShorts Жыл бұрын
the best explanation , and the conversation is relatable
@lynnette2263
@lynnette2263 Жыл бұрын
Thank you!! I’m learning this in class right now!
@ahyi9350
@ahyi9350 Жыл бұрын
I used to learn this the hard way. This conversation is awesome and easy to digest!
@arthur_pendragon
@arthur_pendragon 11 ай бұрын
This really cool, concise and great talk
@andrewa3216
@andrewa3216 Жыл бұрын
It should be noted that once you establish an asymmetric connection with a website it then switches to symmetric. If it stayed asymmetric the entire time that would be a lot of bandwidth and SLOW
@jeffcrume
@jeffcrume Жыл бұрын
Exactly right. Asymmetric is used to solve the key distribution problem but symmetric is used to encrypt the bulk of the data
@ron46135
@ron46135 Жыл бұрын
Great video, look forward to more of these
@mahankrishnan3046
@mahankrishnan3046 Жыл бұрын
Very Well explained. Thanks a lot.
@Cyber_Jagat
@Cyber_Jagat 9 ай бұрын
Awesome explanation. Understandable
@jorge-hernandez-ramirez
@jorge-hernandez-ramirez Жыл бұрын
Thanks guys!!! great job!!
@dkRiseUp
@dkRiseUp 5 ай бұрын
Thank you for that vivid explanation
@jeffcrume
@jeffcrume 2 ай бұрын
You’re welcome!
@BOOSTEDDUDE
@BOOSTEDDUDE 28 күн бұрын
Great explanation. Thanks. I'm really interested in cryptography and certificates and learning a lot of valuable information.
@egyrapper
@egyrapper Жыл бұрын
Excellent explanation
@awaneendra
@awaneendra Жыл бұрын
Amazing stuff. Thanks!
@ikebipe
@ikebipe Ай бұрын
Are there any courses by him, this is freaking awesome. So clearly explained.
@i_am_dumb1070
@i_am_dumb1070 Жыл бұрын
Very informative thankyou 👍 😊
@joistaus
@joistaus Жыл бұрын
Thank you for this awesome explanation
@IBMTechnology
@IBMTechnology Жыл бұрын
Thanks! If you'd like to see other topics on Tech Talk, let us know!
@rsssl
@rsssl 2 ай бұрын
This conversational style is more educative than monologues.
@jeffcrume
@jeffcrume 2 ай бұрын
So glad you liked it!
@leebobtheblob87
@leebobtheblob87 6 ай бұрын
1:48 root user - key 2:01 hw : secure 2:40 public key is telling world how to coommunicate w me 3:10 : public / private is chosen
@aleksandrkubar6255
@aleksandrkubar6255 11 ай бұрын
Great video, thanks a lot!
@magneticalex9078
@magneticalex9078 Жыл бұрын
Guys this is awesome!
@jantoth4699
@jantoth4699 Жыл бұрын
Great video! Can you also do some video on a real world scenario and elaborate on private/public keys with let's say self signed certificate using your own CA by using openssl for example ? Thx
@homebarista
@homebarista Жыл бұрын
I haven't implemented my own CA, but a quick search "how to create certificate authority openssl" yielded step-by-step tutorials. For those following along, this is different than just creating a self-signed certificate (no CA) that you might do for testing. Most browsers will refuse to connect to a site using one, unless you specify a command line/configuration setting to disable it.
@Sulmanification
@Sulmanification Жыл бұрын
Very very good, thanks.
@AlbertLeng
@AlbertLeng Жыл бұрын
I like how you use interaction between novice and expert to make it more fun and understable
@mayureshbadgujar8312
@mayureshbadgujar8312 Жыл бұрын
Really helpful
@zamilmastaliyev6967
@zamilmastaliyev6967 11 ай бұрын
We want tmore content like this :)
@tioluwani6928
@tioluwani6928 7 ай бұрын
Thank you
@TamilonlineS-vh7bo
@TamilonlineS-vh7bo Ай бұрын
Thanks for sharing
@cur1ousss2047
@cur1ousss2047 Жыл бұрын
thanks a ton for content
@akashagarwal6390
@akashagarwal6390 4 ай бұрын
this is really good
@WartimeFriction
@WartimeFriction Жыл бұрын
Great video, really helped reinforce some concepts as I look to get certified and into the industry. Thanks!
@mohsenjebelli155
@mohsenjebelli155 3 ай бұрын
fantastic job !
@jeffcrume
@jeffcrume 2 ай бұрын
Thanks!
@AngryFox9
@AngryFox9 Жыл бұрын
What if i’d like to build a portal that is secured with multiple access levels on a private server?
@veraaesthetics
@veraaesthetics Жыл бұрын
I'm learning PKI for the first time and I'm having trouble with the explanation about encrypting the symmetric key using the private key and then having the recipient decrypt it using the sender's public key. Since the public key is public, can't an unintended recipient intercept the symmetric key and now decrypt it. I though we should always be encrypting with the public key and decrypting with the non-shared key (private) to prevent this problem...
@homebarista
@homebarista Жыл бұрын
First of all, be sure to read the pinned comment above as I misstated public/private in the video. That may be the source of your confusion. Sorry about that! But to clarify, there's two issues at play here: (1) How do you know the message you received is actually from who you think it is? (2) How do you establish secure communication with someone? For (1), you as the receiver of a message from SND know that *must* have originated from SND if you're able to decrypt it with SND's public key, because only SND has their [private] key that was used to encrypt it. Let's say for (2), SND wants to establish a secure connection with RCV. To start, SND creates a unique SND-to-RCV session ID "ZZZ" and wants to send it to RCV. So, SND uses RCV's public key to encrypt the session ID ZZZ, encrypts that with their own (SND's) private key, then sends the "package" to RCV. It's true that someone *could* intercept that package and use SND's public key to decrypt it, but all that would get them was RCV's (encrypted) session ID, which is worthless to the interceptor. On the other hand, RCV can decrypt the package using SND's public key *and* they can also decrypt the message to retrieve the session ID using their private key since SND used RCV's public key to encrypt it. Once this is complete, both SND and RCV share a session ID that nobody else knows; that can be used to establish a secure connection with both parties knowing the other end is who they claim to be. Another easier way to think of it is a message encrypted with a public key can only be decrypted with the associated private key. Thus you can use this asymmetry to prove that a message did in fact originate with the owner of the public/private key, because any tampering along the way would render the message gibberish when decrypted. Did I get it right, @jeffcrume?
@kennethcarvalho3684
@kennethcarvalho3684 11 ай бұрын
Wish I could understand things as quickly as the guy with glasses
@jeffcrume
@jeffcrume 10 ай бұрын
I do too! He’s a sharp guy, for sure!
@edwarddonatus5888
@edwarddonatus5888 Ай бұрын
If you are a Web developer it's sure you must understand faster because this is included in the day to day life of website developers.🎉
@alonbegin8044
@alonbegin8044 Жыл бұрын
a qustion more basic that I didn't felt answered..what problem this security answered to the end user? I felt like an example (or story) of daily use with secure key and the one without that can finalize my understanding on the topic
@homebarista
@homebarista Жыл бұрын
Here's a simple end user example: Programs like email and browsers use encryption in order to ensure that communications cannot be read by anyone other than the intended party. Symmetric cryptography is how we secure the message and asymmetric crytography/PKI is how we exchange the symmetric keys so that the only the intended parties can read the messages [thanks to Jeff Crume for improving on my initial answer].
@user-sh2cr8hp5v
@user-sh2cr8hp5v 10 ай бұрын
In GPG you can create multiple public keys for encrypting, signing and sth else based on ONE private key. If so why do you say in video, that both can be used as for en/decrypt the other. And there can be only two of them?
@jeffcrume
@jeffcrume 6 ай бұрын
I was giving a single, theoretical example. You’re referring to a very legitimate practical example which implements the same concepts as multiple instances. “In theory, there is difference between theory and practice. In practice, there is.” 😊
@dollarblitz
@dollarblitz 3 ай бұрын
Great video, is it relevant to ask where SSL certificates come into play within this context?
@jeffcrume
@jeffcrume 2 ай бұрын
Yes, SSL (now TLS) encryption is based on these concepts as well
@khari83637
@khari83637 3 ай бұрын
my understanding: so a digital signature can only be created by encrypting the hash with pvt key? its a way of affirming that this is last known hash for a message/file. encryption during the digital signature process has nothing to do with protecting a secret. since the key pair is mathematically related , the only pub key that can used to decrypt the hash is the pub key related to the pvt key that encypted it, thereby verifying integrity of sender and hash.
@nishantdalvi9470
@nishantdalvi9470 Ай бұрын
Hey in this video it is been said that any one key can be arbitrarily chosen as a public key but i was under the impression that once the key pairs are generated they are specifically private and public because of the derivation of one key from the another i.e. We can't derive the private via the help of public key if we possess it but we can derive public key with the help of private key which distinguishes these key from each other and we can't randomly select any one key as the public from the available pair
@leonnetto9725
@leonnetto9725 8 ай бұрын
8:30 I'm pretty sure you're not decrypting the Digital Signature with the public key, or at all for that matter. It's just there for verification purposes.
@jeffcrume
@jeffcrume 6 ай бұрын
In order to verify, you do need to decrypt the dig sig so that you can compare the hash value from the sender (encrypted with their private key) and compare it to your calculated value using the same hashing algorithm
@leonnetto9725
@leonnetto9725 6 ай бұрын
@@jeffcrume thanks Jeff. I looked it up after I commented and you're right. Probably should have deleted my comment lol.
@kwreck0022
@kwreck0022 Жыл бұрын
Nice!!!!!!
@fidelpalma6629
@fidelpalma6629 Жыл бұрын
This is awesome. Like, suscribe, click on the bell and whatever else you want. I'm going to watch more of your videos.
@nikoruhe54
@nikoruhe54 Жыл бұрын
Does IBM offer any type of managed PKI products?
@IBMTechnology
@IBMTechnology Жыл бұрын
No. However, IBM does have tools that do encryption and use PKI (Guardium Data Encryption plus all the PKI that is baked into our products and OSs).
@jeffcrume
@jeffcrume Жыл бұрын
IBM offers crypto capabilities of this sort on the mainframe as part of the security services in the OS. Also, crypto accelerator cards from IBM help speed up operation and keep keys secure
@random-characters4162
@random-characters4162 Жыл бұрын
the line at 8:26 confuses me a bit. Because CA uses his Private Key. But the line goes from the user's Private Key
@IBMTechnology
@IBMTechnology Жыл бұрын
See the pinned comment above for a discussion of the correction.
@UrMomExpressed
@UrMomExpressed 9 ай бұрын
after all these videos im confused. are you writing backwards? do you have to rehearse?
@IBMTechnology
@IBMTechnology 8 ай бұрын
See ibm.biz/write-backwards for details
@UrMomExpressed
@UrMomExpressed 8 ай бұрын
aaahahah thank you @@IBMTechnology
@xiaofei5556
@xiaofei5556 Жыл бұрын
It seems not right at the last step, isn't it? The final signature should be signed by CA private key instead of any end users', right?
@moitanka947
@moitanka947 Жыл бұрын
That is correct.
@TheMaxKids
@TheMaxKids Жыл бұрын
What are you writing on??? That looks 👍
@homebarista
@homebarista Жыл бұрын
We're writing on a glass pane that is directly in front of us. Since we're on the other side of the glass, the writing is backwards from the viewpoint of the camera, so we flip the image in post-production. That's why it appears that I'm left-handed when in fact I'm right-handed.
@TheMaxKids
@TheMaxKids Жыл бұрын
@@homebarista thanks, mate!
@abinthomas6390
@abinthomas6390 2 ай бұрын
The second guy got caught in the weeds of asymmetric vs symmetric keys. Those are two completely different systems. No one uses symmetric keys anymore because RSA became popularized by Rivest, Shamir, and Aldman in their algorithm. RSA broadcasts the public keys and a message can be encoded so the private key can decode the message. The private key is not broadcasted. But anyone can send a message using the public keys to the server which can be decoded by the private key.
@jeffcrume
@jeffcrume 2 ай бұрын
Every time you login to a secure web site, you use symmetric encryption as well as asymmetric
@marspark6351
@marspark6351 11 ай бұрын
I understand the certificate can be trusted because it was issued by the CA. But how does the CA evaluate that the public key is legit in the first place to create the certificate? Aren't we back to the initial question of "how do we know that the public key is trustworthy?"
@jeffcrume
@jeffcrume 10 ай бұрын
The CA is responsible to issue the certs (and sign them with its private key). The public keys for trusted, well known CAs are hardcoded into browsers and other software so that they can verify that certificates are authentic and have been signed by a trusted third party
@m4heshd
@m4heshd Жыл бұрын
The guy with the glasses listened very carefully and still got things wrong. The other guy just went with it.
@homebarista
@homebarista Жыл бұрын
This is the guy with glasses. When I speak spontaneously, I sometimes make verbal mistakes like this. Sorry! I realized it was incorrect in the playback, but decided to leave it as-is. It took a few days for a viewer to correct me. 😉Another viewer pointed out a misstatement (?) by Jeff w.r.t. asymmetric keys. See the pinned comment for the viewers calling out these misstatements and our corrections.
@m4heshd
@m4heshd Жыл бұрын
@@homebarista I understand. I'm sorry for leaving a rude comment. It took a response from you to realize my own bitterness.
@moonmalik7932
@moonmalik7932 11 ай бұрын
At time 4:45, I think there is a mistake. The message should never be decrypted with the sender's public key as the public key is known to all on the network, it's public :). So it works like this... to send the symmkey. First, the sender encrypts the symmkey with the receiver's public key and then the receiver decrypts the message using its own private key.
@IBMTechnology
@IBMTechnology 11 ай бұрын
Yes, you're correct and this is noted in the pinned comment.
@babthooka
@babthooka 2 ай бұрын
Wow guys! You're BOTH left handed - what are the odds!!
@Cooliofamily
@Cooliofamily 14 күн бұрын
And they’re writing backwards!!
@edwarddonatus5888
@edwarddonatus5888 Ай бұрын
As a web developer you will understand faster the explanation of PKI.
@nishantdalvi9470
@nishantdalvi9470 Ай бұрын
Hey in this video it is been said that any one key can be arbitrarily chosen as a public key but i was under the impression that once the key pairs are generated they are specifically private and public because of the derivation of one key from the another i.e. We can't derive the private via the help of public key if we possess it but we can derive public key with the help of private key which distinguishes these key from each other and we can't randomly select any one key as the public from the available pair but yes both can use for encryption as well as decryption at the same time
@danielgx83
@danielgx83 6 ай бұрын
my problem with IBM explanations is that they never really gives examples from AD on prem environment in windows server or ubuntu server, they will just give you the theory behind it , i would eve dare to say its a metaphor because nobody can really see how it is done in AD CA Environment in enterprise levels . they only give you the concept because they themself never actually done that.
@jeffcrume
@jeffcrume 2 ай бұрын
My goal with the video was to cover the concepts that would be applicable across all platforms. Vendor-specific implementations may be better explained by those vendors
@kozlovskyi
@kozlovskyi Жыл бұрын
bad microphones or audio post-processing.
@IBMTechnology
@IBMTechnology Жыл бұрын
Sorry about that! It was one of the first two-person mic setups we've done and the sound mixer wasn't dialed in yet. Our audio guy fixed it the next day, so future Tech Talks should be clearer.
@hendrixansel9750
@hendrixansel9750 Жыл бұрын
That's a lie, you can't choose which one is private key and which one is public. The public key is always the one derived from the other. Never the other way around.
@homebarista
@homebarista Жыл бұрын
Jeff said that once you designated one key as public, the other is then deemed private and vice versa. in other words, it's a mathematical property between the two keys and calling one or the other public/private is arbitrary up until the point that you make the decision. Obviously once you decide, you can't change your mind later.
@hendrixansel9750
@hendrixansel9750 Жыл бұрын
You you can't choose arbitrary which key is private and which key is public. That's not how math works. If you choose the private key to be the key derived from the other than anybody can hack/decrypt your message. People in this video are just wrong.
@IBMTechnology
@IBMTechnology Жыл бұрын
Jeff confirmed that you're right, the keys cannot be arbitrarily assigned. This discussion elaborates on why: security.stackexchange.com/questions/74325/does-it-matter-which-key-is-considered-private-and-which-public
@hendrixansel9750
@hendrixansel9750 Жыл бұрын
@@IBMTechnology I appreciate the clarification. Keep up the good work.
@schillaci5590
@schillaci5590 8 ай бұрын
It is a horrifically ugly topic made even more unsavory by IT management politics and misprioritization.
@jeffcrume
@jeffcrume 6 ай бұрын
I’d say that crypto is an “acquired taste” and certainly not everyone “acquires” it 😂
@Hybrid_Netowrks
@Hybrid_Netowrks 2 ай бұрын
On timeline 4:40 to 4:47 the guy is wrongly interpreting the usecase. The client actually generates a session key / Sym key and encrypt it with the public key of the peer end and then the peer end decrypt it with it's private key to acquire the session key/Sym key. Additionally, the peer generates a session key/Sym key and encrypt it with the session/Sym key that it just decrypted and send that key to the other side. Now, what happens is that one side use its own Session/Sym key for decryption and the other side key for encryption.
@nishantdalvi9470
@nishantdalvi9470 Ай бұрын
Hey i even noted one more thing i.e. It is been said in that video that any one key can be arbitrarily chosen as a public key but i was under the impression that once the key pairs are generated they are specifically private and public because of the derivation of one key from the another i.e. We can't derive the private via the help of public key if we possess it but we can derive public key with the help of private key which distinguishes these key from each other and we can't randomly select any one key as the public from the available pair but yes both can use for encryption as well as decryption at the same time
@utubmediasucks
@utubmediasucks 4 ай бұрын
how they managed to reverse writing is also remarkable
@jeffcrume
@jeffcrume 2 ай бұрын
Search the channel for a video of me explaining “how we make them” and you’ll learn the secret
@Shailendrashail
@Shailendrashail Жыл бұрын
Excellent explanation
@Arpan_Vala
@Arpan_Vala Жыл бұрын
Thank you
FIDO Promises a Life Without Passwords
9:58
IBM Technology
Рет қаралды 386 М.
FOOTBALL WITH PLAY BUTTONS ▶️ #roadto100million
00:24
Celine Dept
Рет қаралды 139 МЛН
ФОКУС С ЧИПСАМИ (секрет)
00:44
Masomka
Рет қаралды 3,8 МЛН
одни дома // EVA mash @TweetvilleCartoon
01:00
EVA mash
Рет қаралды 2,7 МЛН
PKI Bootcamp - What is a PKI?
10:48
Paul Turner
Рет қаралды 187 М.
Cybersecurity Architecture: Five Principles to Follow (and One to Avoid)
17:34
Introduction to Public Key Infrastructure (PKI) | Basics of PKI | Encryption Consulting
4:08
Containers vs VMs: What's the difference?
8:08
IBM Technology
Рет қаралды 730 М.
Understanding Hackers
10:41
IBM Technology
Рет қаралды 29 М.
CompTIA Security+ Full Course: Public Key Infrastructure (PKI)
43:48
Certify Breakfast
Рет қаралды 9 М.
Denial of Service Attacks Explained
9:52
IBM Technology
Рет қаралды 47 М.
What are Digital Signatures? - Computerphile
10:17
Computerphile
Рет қаралды 313 М.
What is a REST API?
9:12
IBM Technology
Рет қаралды 1,4 МЛН
FOOTBALL WITH PLAY BUTTONS ▶️ #roadto100million
00:24
Celine Dept
Рет қаралды 139 МЛН