Welcome Guest. | Log In | Register | Membership Benefits

RSA: Hashing Out Encryption

Vendors at RSA 2008 rolled out tools that make encryption easier to use and manage

Apr 14, 2008 | 09:50 AM | 

By Kelly Jackson Higgins

SAN FRANCISCO -- RSA 2008 Conference -- The conference that once was just a gathering of a few cryptographers is now a major event that drew more than 17,000 attendees last week. And the technology that started it all -- encryption -- showed it has grown a lot, too.

The big themes among encryption vendors exhibiting and rolling out new products here included managing encryption across the enterprise, making encryption easier to use, and a shifting focus from the nitty-gritty of encryption keys to the data itself. These themes aren't exactly new, but they were more front-burner than in years past, thanks to a busy year of high-profile data breaches, PCI mania, and laptop-theft paranoia.

With the pioneers of encryption chatting it up in the annual Cryptographer's Panel here as a backdrop, encryption vendors on the exhibit floor rolled out next-generation encryption management products and tools that help make encryption less a technology of complicated algorithms and key pairs and more of a mainstream business security strategy. But that doesn’t mean encryption is streamlined -- organizations today typically run a patchwork of separate encryption systems for various elements in their networks, from their files to their laptop hard drives.

Around 21 percent of U.S. enterprises surveyed in a Ponemon Institute and PGP study released this month say they currently have a consistent encryption strategy implemented across their organizations, which is an increase from last year, when only 16 percent did. Nearly 75 percent have an encryption strategy that's based on a type of data or application or is enterprise-wide, according to the study.

The number one reason for adding encryption: data breach prevention, with 71 percent of the vote, up from 66 percent last year, the study said. The most common encryption today is laptop encryption, which 20 percent of respondents use most of the time.

"Separate encryption systems all handle keys differently, and it's a policy" mess, says Gretchen Hellman, senior director of marketing for Vormetric, which specializes in policy-based encryption, access control, and auditing. Hellman is also the daughter of Martin Hellman of Diffie-Hellman algorithm fame.

RSA, the security division of EMC, here released its RSA Key Manager for the Datacenter product, which aims to centralize and integrate the lifecycle management of keys in the enterprise -- including in the database, file servers, and in storage systems.

"Multiple point encryption solutions, each with their own approach to encryption key management, increases management complexity and the risk of lost or stolen keys," said Dennis Hoffman, RSA's chief strategy officer, vice president, and general manager of its data security group, in a prepared statement.

According to the Ponemon-PGP study, organizations plan to spend 34 percent of their overall budget for encryption on key management (which includes key lifecycle, policy, and reporting), and 45 percent expect those systems to save them money on their data security costs.

Vormetric, meanwhile, rolled out what it calls the Key Security Expert, a tool for providing key security and access control for encryption keys across various encryption platforms in an enterprise. "It's a method to immediately address this ability to secure and control access to keys locally," Vormetric’s Hellman says. "Any third-party encryption key or homegrown solution -- we can control access to it."

Venafi, which sells what it calls systems management for encryption, demo'd its upcoming Encryption Manager V system at RSA, which will come with symmetric key support and enhanced auditing. Paul Turner, vice president of product and customer solutions for Venafi, says the new encryption management platform contains more policy-based management. It also integrates with existing key management tools.

"Most people are not key experts. So we had to make the policies simple," Turner says. Venafi doesn't provide encryption, just the systems management tools for it, he says.

BitArmor, meanwhile, upgraded its DataControl encryption software with support for Vista and Windows Server 2008, and plans to add management for Windows BitLocker Drive Encryption in the third quarter. "There are various types of encryption, but they are all separately focused on the device or app," says Patrick McGregor, BitArmor’s Chief Executive Officer. "We are taking an approach at the data level... we protect data at the core, and the keys are in the data itself. It's persistent encryption, a more elegant solution."

Other encryption announcements here included Voltage Security's new software-as-a-service model for its SecureFile encryption for documents and files, as well as increased systems integrator support for its format-preserving encryption technology, which encrypts data without changing the structure of the data. "Our goal is to make encryption usable," says Dan Beck, director of product management for Voltage, best known for its identity-based encryption technology for email encryption. The idea is to encrypt the data without changing the structure of the data, he says.

And Wave Systems demo'd strong authentication using its Embassy software for managing hardware security. "We don’t do encryption. We are protecting the data," says Lark Allen, executive vice president of Wave Systems.

Wave showed tools that support the next-generation Intel Centrino 2 with vPro, with TPM v 1.2. It also demonstrated management of the Seagate Momentus 5400 FDE.2 line of full-disk encryption drives.

So is encryption now considered mainstream? Bruce Schneier, chief security technology officer for BT, says encryption today is "surprisingly mainstream," even though you can't really see it. "People don’t buy encryption, they use it," he says of end users. "It's in their browser, their VPN" connections. "And when it becomes ubiquitous, it disappears" into tools and products, he says.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

  • PGP Corp.
  • RSA Security Inc. (Nasdaq: EMC)
  • Vormetric Inc.
  • Voltage Security Inc.



  • Currently we allow the following HTML tags in comments:

    Single tags

    These tags can be used alone and don't need an ending tag.

    <br> Defines a single line break

    <hr> Defines a horizontal line

    Matching tags

    These require an ending tag - e.g. <i>italic text</i>

    <a> Defines an anchor

    <b> Defines bold text

    <big> Defines big text

    <blockquote> Defines a long quotation

    <caption> Defines a table caption

    <cite> Defines a citation

    <code> Defines computer code text

    <em> Defines emphasized text

    <fieldset> Defines a border around elements in a form

    <h1> This is heading 1

    <h2> This is heading 2

    <h3> This is heading 3

    <h4> This is heading 4

    <h5> This is heading 5

    <h6> This is heading 6

    <i> Defines italic text

    <p> Defines a paragraph

    <pre> Defines preformatted text

    <q> Defines a short quotation

    <samp> Defines sample computer code text

    <small> Defines small text

    <span> Defines a section in a document

    <s> Defines strikethrough text

    <strike> Defines strikethrough text

    <strong> Defines strong text

    <sub> Defines subscripted text

    <sup> Defines superscripted text

    <u> Defines underlined text

    Dark Reading encourages readers to engage in spirited, healthy debate, including taking us to task. However, Dark Reading moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Dark Reading further reserves the right to disable the profile of any commenter participating in said activities.

    Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
    Subscribe to RSS












    Featured Webcasts
    Featured Whitepapers
    Featured Reports
    Bugs
    ENTERPRISE VULNERABILITIES
    Vulnerability:ssl-vpn end-point interrogator/installer activex control
    Published:2010-11-03
    Severity:High
    Description:Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method.
    Vulnerability:gvim
    Published:2010-11-03
    Severity:High
    Description:Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse User32.dll or other DLL that is located in the same folder as a .TXT file. NOTE: some of these details are obtained from third party information.
    Vulnerability:cforms
    Published:2010-11-03
    Severity:Medium
    Description:Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.
    Vulnerability:links, wsn links, wsn links
    Published:2010-11-03
    Severity:High
    Description:Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch parameter.
    Vulnerability:deluxebb
    Published:2010-11-03
    Severity:Medium
    Description:SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than CVE-2005-2989, CVE-2006-2503, and CVE-2009-1033.



    Briefing Centers
    POWERFUL INFORMATION
    AT YOUR FINGERTIPS
    (SPONSORED LINKS)