DNS allows the names of web servers, email addresses and VPNs to be mapped to server IP addresses. The DNSSEC specification enables the owners of these services to sign their domain name records and provide proof of the integrity and validity of their IP addresses. DNSSEC uses strong public key cryptography to significantly reduce the risk of an attacker spoofing DNS records and re-directing traffic to a server they control. Like any Public Key Infrastructure (PKI) based application, DNSSEC relies on the integrity of the private keys that underpin this process. The fact that domain name servers are typically deployed in hostile network environments with internet connectivity underscores how critical it is to protect these private keys throughout their lifecycle.
The Infoblox DNSSEC-enabled platform helps simplify IP address management (IPAM), increases reliability of DNS and IP address assignment (DHCP) services, and helps automate many manual and often error-prone network infrastructure related tasks. Infoblox IPAM solutions are designed to deliver highly reliable, manageable and secure DNS services with built-in, automated DNSSEC
When Infoblox systems are used together with a Thales nShield hardware security module (HSM)
“As a global authentication and validation schema, DNSSEC represents a new security frontier,” said Kevin Dickson, vice president of product management at Infoblox. “However, protecting access to the cryptographic keys that underpin the security framework is crucial. That’s why the Infoblox IPAM platform now offers support for the Thales HSM, which is both easy to integrate and well proven to protect DNSSEC key signing.”
“The number of recent high profile cyber attacks, such as Stuxnet and the DigiNotar hack demonstrate that crypto alone is not sufficient. Protecting cryptographic keys throughout their lifecycle is essential to achieve the benefits promised by DNSSEC and this joint Infoblox and Thales solution lowers the barriers to adopting DNSSEC,” says Cindy Provin, vice president of the Americas, Thales e-Security. “DNSSEC is an important method of securing the Domain Name System, protecting the integrity of an online presence and brand. Just as SSL became the standard mechanism for website authentication and encryption, DNSSEC is expected to become an integral component of Internet trust and a key element in enterprise security policies, further demonstrating the increasing value of encryption, digital signatures and key management in today’s ever-changing threat landscape.”
For more information about Thales, industry issues and comment, visit: www.keymanagementinsights.com
The Information Technology Security activities of Thales
Thales e-Security is a leading global provider of data encryption solutions to the financial services, high technology manufacturing, government and technology sectors. With a 40-year track record of protecting corporate and government information, Thales solutions are used by four of the five largest energy and aerospace companies, 22 NATO countries, and they secure more than 70 percent of worldwide payment transactions. Thales e-Security has offices in France, Hong Kong, Norway, United States and the United Kingdom. For more information, visit www.thales-esecurity.com
About Thales
Thales is a global technology leader for the defence & security and the aerospace & transport markets. In 2010 the company generated revenues of 13.1 billion, with 68,000 employees in 50 countries. With its 22,500 engineers and researchers, Thales has a unique capability to design, develop and deploy equipment, systems and services that meet the most complex security requirements. Thales has an exceptional international footprint, with operations around the world working with customers as local partners. www.thalesgroup.com
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. |
What's Next for Certificate Technology
A recent rash of certificate authority breaches has left a bad taste in many people's mouths. There is no one reason for the breaches. The compromises were the result of a breakdown in people, processes and technology, but not necessarily the certificates themselves. We take a look at what?s wrong with certificate technology, what can be done to fix it, and what's down the road for certificates and CAs.
Will Smartcards Live Up to Their Name?
Recent compromises of smartcard data have exacerbated concerns about the technology?s privacy, security and standards (or lack thereof). Yet the promise of smartcards is too compelling to ignore. New technologies and applications prompt us to take a fresh look.
Get The Best Of Biometrics
As data volume and sensitivity grow, companies cannot rely on password- and token-based authentication. Biometrics can be used to provide strong access control, but you must weigh added complexity and costs against assurance that users are who they say they are.
Other reports from the Authentication Tech Center:
MORE NEWSFEED >>>