Welcome Guest. | Log In | Register | Membership Benefits
  • |   Email this page E-mail
  • |  Print Print
  • |   Bookmark and Share

StrongAuth Secures Data In Public Clouds

StrongAuth CryptoEngine encrypts and decrypts files and transfers them to public cloud storage services

Oct 10, 2011 | 11:08 AM | 


CUPERTINO, CA October 8, 2011

StrongAuth, Inc. announced the general availability of the StrongKey CryptoEngineTM, an open-source Java library/web-service that helps software developers leverage cloud-storage by automatically encrypting files and transferring them to public cloud storage services such as Amazon's S3, Microsoft's Azure and Eucalyptus Walrusm with minimal programming effort. The free software is available for immediate downloads.

The StrongAuth CryptoEngineTM includes the following features:

• Encrypts and decrypts files by calling the library's functions when embedded within Java applications or when calling a web-service from any application; the files may be of any type and size;

• Automatically generates an encryption key based on NIST-approved algorithms and defined policies, and escrowing the key with the StrongAuth KeyApplianceTM for key-management;

• Leverages Public Clouds for storing the encrypted data; the product supports the use of Amazon's S3, Microsoft's Azure and Eucalyptus Walrus;

• Saves encrypted files in the W3C XMLEncryption standard format, making it completely portable across platforms;

• Integrates to existing identity management systems, such as Active Directory or other LDAP-based identity management systems; and

• A command-line-based tool to enable immediate use of the library to encrypt, decrypt and move files to public clouds.

StrongAuth announced the CryptoEngineTM, with its unprecedented blend of features, is available at no cost, in source andbinary form, at SourceForge (http://sourceforge.net/projects/skce/). More information on the CryptoEngineTM can be found at

http://www.cryptoengine.org.

“Cloud-computing and cloud-storage have the ability to transform the IT landscape dramatically. However, the obligation to protect sensitive data does not diminish with cloud-computing or storage.” said Arshad Noor, CTO of StrongAuth. “We created the world's first integrated encryption, tokenization and key-management appliance in January 2010 to manage sensitive data and keys on a very large scale. With the release of the CryptoEngineTM, we've delivered another major component of our Regulatory Compliant Cloud Computing (RC3) architecture (http://www.strongauth.com/pdf/RC3-WebAppArch-1.2-2.pdf): the ability to leverage public-clouds to secure sensitive data while proving compliance to datasecurity regulations!”.

Since the state of California first passed a Breach Disclosure law – also known as Senate Bill 1386 – in 2003, more than 2700 breaches to sensitive data have been disclosed that have affected more than 540 Million sensitive data-records, according to www.privacyrights.org. Retail merchants such as TJX have paid out more than $115M in fines and settlements for a single data-breach that exposed 45M consumers' credit card numbers, while Heartland Payment Systems' breach of 130M recordscaused it to pay more than $110M for settlements.

Security regulations have consequently focused on data-protection through the use of encryption. When implemented properly, encryption has the ability to secure data; however, the challenge has always been with the protection and management of the cryptographic keys responsible for decrypting sensitive data. Leveraging the advanced key-management features of StrongAuth's KeyApplianceTM users of the CryptoEngineTM will be able to take advantage of public-clouds without violating regulations such as PCI-DSS and HIPAA.

About StrongAuth, Inc.

StrongAuth is the leader in Enterprise Key Management Infrastructure, bringing new levels of capability and data security at a price point significantly lower than other solutions on the market. Providing solutions in Symmetric Key Management and PKI, StrongAuth is focused on securing data in the areas of Cloud Computing, E-Commerce, Healthcare, Finance and other sectors mandating protection of sensitive data. StrongAuth's solutions are installed at customer sites around the world and are key components of mission-critical business operations. More information on StrongAuth and its products can be found at http://www.strongauth.com.



Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Dark Reading encourages readers to engage in spirited, healthy debate, including taking us to task. However, Dark Reading moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Dark Reading further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS



Authentication Reports

report Will Smartcards Live Up to Their Name?
Recent compromises of smartcard data have exacerbated concerns about the technology?s privacy, security and standards (or lack thereof). Yet the promise of smartcards is too compelling to ignore. New technologies and applications prompt us to take a fresh look.

report Get The Best Of Biometrics
As data volume and sensitivity grow, companies cannot rely on password- and token-based authentication. Biometrics can be used to provide strong access control, but you must weigh added complexity and costs against assurance that users are who they say they are.

report Proof of Identity: How to Choose Multifactor Authentication
User names and passwords are no longer sufficient authentication. In a time when so much business depends on the Internet, security requirements and regulatory mandates are putting pressure on business to adopt strong, multifactor authentication methods. In this Tech Center report, we explain how to weigh cost vs. risk to select the Web authentication method for your high-risk applications.

Other reports from the Authentication Tech Center:

Related Content

Effective and Painless Multi-factor Authentication
When the information age was young, authentication was simple-assign the user a password. Today, user populations have expanded and users access numerous distinct systems with each system requiring credentials. That said, it is no surprise that users have reverted to tactics that invalidate the security strength of passwords. Yet, the use of passwords as the only means to certify a user's identity still remains prevalent among SMBs. There is a new, multi-factor authentication approach that strengthens identity authentication and does not introduce extra cost, user inconvenience, and administrative. This white paper describes why multi-factor authentication is rising in importance and reviews the pros and cons of different multi-factor authentication approaches.

Man-in-the-Browser Attacks Explained
Cybercriminals are using more advanced methods to target online users. One of the fastest growing threats today is the man-in-the-browser (MITB) Trojan attack - an attack designed to intercept data as it passes over a secure communication between a user and an online application. Propagation of man-in-the-browser attacks is being helped by spear phishing attacks, the popularity of social networking sites, and the increase in drive-by downloads. In the last year, there has been an exponential increase in the number of these attacks against financial institutions. This white paper introduces the MITB attack, explains the infection rate, features and functionality of the attack and provides advice on how financial institutions can mitigate the threat.

How to: Select the Best Authentication Solution for Your Business
With the number of new and emerging security products being denoted by analysts as the "silver bullet" solution, it is critical to recognize that there are many authentication choices available on the market. The Authentication Decision Tree is a comprehensive tool that helps organizations understand, evaluate and select the most appropriate authentication solution to meet the needs of their users and their business. This white paper provides an overview of the Authentication Decision Tree, examines the five factors critical to selecting an authentication solution, and offers a clear guide to selecting the right solution that effectively balances risk, cost and end user convenience.

Strong Authentication for SMBs
Small and mid-sized businesses authenticate their end-users primarily with passwords, in spite of the fact that passwords are less secure, inconvenient and more expensive then stronger forms of authentication. This white paper reveals recent research conducted by Aberdeen on the drivers, inhibitors and technology adoption trends among SMBs. Find out what authentication solutions are well-designed to address the needs of SMBs.

How to Make the Case for Strong Authentication
With today's threat landscape and the increased value placed on the information created and stored, systems that rely on static passwords for security are left vulnerable and at high risk of being breached. This paper examines the need for strong authentication and explores the return on investment in order to help organizations make an informed decision when contemplating their strategic move toward more effective security.