Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

9/28/2006
03:00 AM
50%
50%

Multivendor Management Locked Up

Key management partnerships have yet to deliver the goods

NeoScale has teamed up with Symantec, Optica Technologies, and Entrust in an attempt to make good on its promise to manage encryption keys from different vendors. But whether this initiative can develop quickly enough to satisfy user demand remains to be seen.

Optica, which makes mainframe connectivity devices, and software specialist Symantec have agreed to share their encryption keys with NeoScale's KeyVault device at a time when users are clamoring for better key management from their technology suppliers. (See All Keyed Up With NeoScale and NeoScale Centralizes Management.)

At this stage, however, it is still unclear exactly when users will actually be able to make use of the key sharing features promised by NeoScale et al.

For its part, Optica is expected to offer joint key management to its customers sometime later this year, although the company did not return Byte and Switch's call for comment. Symantec has given no indication of when its customers will be able to store their keys on KeyVault, which handles the encryption keys associated with NeoScale's own CryptoStor appliances.

Back in March, NeoScale claimed to be the first vendor to open up its key management APIs to third parties, though archrival Decru (now part of NetApp) followed suit four months later with a similar initiative centered on its Lifetime Key Management appliance. (See Decru Picks Key Partners and File Security Gets All Cryptic.) At that time, Decru announced partnerships with Symantec and Quantum to share encryption keys -- but the vendors are still working to integrate their products.

Meanwhile, faced with a slew of compliance pressures, firms are crying out for the ability to share keys across different devices. At the same time, they face a potential crisis regarding those keys. A recent Byte and Switch Insider report, "Storage Encryption: State of the Art," warned that problems surrounding the enforcement of encryption could, ironically, threaten the security of many organizations. If keys wind up being manually managed, which is increasingly common, gaps can arise that expose data to security holes and errors. (See Insider: Encryption Means Planning.)

Clearly, there is a pressing need for vendors to start turning their key management efforts from marketing hype into product reality. "Key management is a worrying issue," says an IT manager from a New York-based financial firm, who asked not to be named, adding that regulatory requirements are forcing him to encrypt more and more applications.

"A centralized repository would make it easier to manage keys," adds an IT director from a Connecticut-based HR services firm, who also asked not to be named. "If you need a key quickly, having [keys]in a central location will speed up that process."

Against this backdrop, both users interviewed by Byte and Switch said they want to see more than just a handful of vendors involved in key management efforts. "Ideally, we would want to see more offerings, because that increases the functionality [available to us]," explains the IT director.

"I would like to have multiple vendors involved in key management," adds the IT manager from the financial sector. "It's common sense, and it could even drive the price of key management products down."

"For users, the more choices they have for [key] integration, the better," agrees Jon Oltsik, senior analyst at the Enterprise Strategy Group. "There are millions of encryption keys spread across the enterprise."

Both NeoScale and Decru, however, haven't delivered the goods on announced partnerships, let alone unannounced ones. Still, both suppliers insist they are courting additional partners. (No names are offered.)

NeoScale VP of marketing Dore Rosenblum, for instance, claims the firm is working with "20 plus" vendors, including companies active in Information Lifecycle Management (ILM) and identity management. More partner announcements will be made "in the next quarter or so," he told Byte & Switch.

Over at Decru, Michele Borovac, the firm's director of marketing, says the vendor is "in discussion with many, many, other companies," around the issue of key management.

At this stage, NeoScale has three announced partners to Decru's two. As well as the key-sharing deals with Optica and Symantec, PKI specialist Entrust plans to import its digital certificates onto the KeyVault device as part of an effort to lock down users' internal security. "By working with Entrust, we're able to validate that the device connecting into KeyVault is the device that it says it is," explains Rosenblum.

In reality, however, the ability to validate network devices is still some way off. Although NeoScale customers can currently use Entrust certificates for authenticating users accessing the device via the Web, Rosenblum told Byte & Switch that authentication of other network devices will probably be available early next year.

— James Rogers, Senior Editor, Byte and Switch

  • Decru Inc.
  • The Enterprise Strategy Group (ESG)
  • Entrust Inc.
  • NeoScale Systems Inc.
  • Network Appliance Inc. (Nasdaq: NTAP)
  • Symantec Corp. (Nasdaq: SYMC)

     

    Recommended Reading:

    Comment  | 
    Print  | 
    More Insights
  • Comments
    Newest First  |  Oldest First  |  Threaded View
    COVID-19: Latest Security News & Commentary
    Dark Reading Staff 8/3/2020
    'BootHole' Vulnerability Exposes Secure Boot Devices to Attack
    Kelly Sheridan, Staff Editor, Dark Reading,  7/29/2020
    Out-of-Date and Unsupported Cloud Workloads Continue as a Common Weakness
    Robert Lemos, Contributing Writer,  7/28/2020
    Register for Dark Reading Newsletters
    White Papers
    Video
    Cartoon Contest
    Current Issue
    Special Report: Computing's New Normal, a Dark Reading Perspective
    This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
    Flash Poll
    The Threat from the Internetand What Your Organization Can Do About It
    The Threat from the Internetand What Your Organization Can Do About It
    This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
    Twitter Feed
    Dark Reading - Bug Report
    Bug Report
    Enterprise Vulnerabilities
    From DHS/US-CERT's National Vulnerability Database
    CVE-2020-16271
    PUBLISHED: 2020-08-03
    The SRP-6a implementation in Kee Vault KeePassRPC before 1.12.0 generates insufficiently random numbers, which allows remote attackers to read and modify data in the KeePass database via a WebSocket connection.
    CVE-2020-16272
    PUBLISHED: 2020-08-03
    The SRP-6a implementation in Kee Vault KeePassRPC before 1.12.0 is missing validation for a client-provided parameter, which allows remote attackers to read and modify data in the KeePass database via an A=0 WebSocket connection.
    CVE-2020-8574
    PUBLISHED: 2020-08-03
    Active IQ Unified Manager for Linux versions prior to 9.6 ship with the Java Management Extension Remote Method Invocation (JMX RMI) service enabled allowing unauthorized code execution to local users.
    CVE-2020-8575
    PUBLISHED: 2020-08-03
    Active IQ Unified Manager for VMware vSphere and Windows versions prior to 9.5 are susceptible to a vulnerability which allows administrative users to cause Denial of Service (DoS).
    CVE-2020-12739
    PUBLISHED: 2020-08-03
    A vulnerability in the Fanuc i Series CNC (0i-MD and 0i Mate-MD) could allow an unauthenticated, remote attacker to cause an affected CNC to become inaccessible to other devices. The vulnerability is due to improper design or implementation of the Ethernet communication modules of the CNC. An attack...