Deliverable D2.2: Specification of security services incl. virtualization and firewall mechanisms

Size: px
Start display at page:

Download "Deliverable D2.2: Specification of security services incl. virtualization and firewall mechanisms"

Transcription

1 Project acronym: OVERSEE Project title: Open Vehicular Secure Platform Project ID: Call ID: FP7-ICT Programme: 7th Framework Programme for Research and Technological Development Objective: ICT : ICT for Safety and Energy Efficiency in Mobility Contract type: Collaborative project Duration: to (30 months) Deliverable D2.2: Specification of security services incl. virtualization and firewall mechanisms Authors: Reviewers: Dissemination level: Deliverable type: Jan Holle (Uni Siegen) André Groll (Uni Siegen) Alfons Crespo (UPVLC) Hakan Cankaya (escrypt) Thomas Enderle (escrypt) Nicholas Mc Guire (OpenTech) Andreas Platschek (OpenTech) Hakan Cankaya (escrypt) Thomas Enderle (escrypt) Florian Friederici (FOKUS) Public Version: 1.4 Report Submission date: 3 rd June 2011

2 Abstract This document specifies all capabilities and services of OVERSEE, which are related to security. Thus, it defines a large part of the OVERSEE design since the project has a strong focus on security. Security services that are part of the generic OVERSEE implementation will be depicted. These services are offered to the partitions through an appropriate API and are reused by other OVERSEE components, too. Additionally, the following security related features are specified: Whole virtualization concept, OVERSEE firewall, secure assurance of prioritized resource access and internal communication requirements in the virtualized environment. ii

3 Contents Abstract... ii Contents... iii List of Figures... vi List of Tables... vii List of Acronyms and Abbreviations... viii Document History... xi 1 Introduction Scope and Objectives of the Document Definitions Document Outline Security Services Overall Structure of Security Services Hardware Security Module HSM Cryptographic Functions HSM Secure Key Storage HSM Secure Boot Registers HSM Hardware Interface Security Services Partition Security Partition Binding Hardware Security Module I/O Driver Cryptographic Services Module Key Management Module Secure Storage Certificate Handler Security Services Configuration Table Security Services Provider Module Cryptographic Services API Key Management API Secure Storage API Alternative Secure Storage Secure Communication API iii

4 2.5 Secure Boot Guideline for Providing Secure Boot in OVERSEE User Authentication and Authorization User Model of OVERSEE Authentication Methods for OVERSEE Extended Authorization Capabilities Secure Software Load Requirements for a Secure Software Load Specification of the Whole Virtualization Concept Partitions Virtualized Resources Configuration and Deployment Overview Concepts Subjects, Objects and Privileges Subject Identification Exported Resource Identification Partitions and the Partitioned Information Flow Policy Auditable Events Secure States Concepts Operations TOE Attestation Health Monitor Events Traces and Logs OVERSEE Firewall Communication Paths and Interfaces Security Methods Concerning the Communication Paths to be Considered for the OVERSEE Firewall Specification of the OVERSEE firewall Role Model for Definition of Firewall Policies Policy language for the OVERSEE firewall Secure Assurance of Prioritized Resource Access Classes of Resources Concerning Prioritized Resource Access Time shared resources iv

5 5.1.2 Resources capacity shared resources Classification of OVERSEE Resources Concerning Prioritized Resource Access Special Issues concerning Prioritization in SVAS Concepts for Prioritized Resource Access in OVERSEE Resources shared over time Resources with shared Capacity Change of Resource Sharing During Operation Policy Language for Definition of Prioritized Resource Access Security Challenges for Assurance of Prioritized Resources Access Residual Risks Specification of internal communication requirements in the virtualized environment High-Level Requirements Available Communication Mechanisms Sampling Ports Queuing Ports Compliance with RTE API Shared Memory Design Discussion - Robust SHM: Requirements on the Internal Communication Scenario1: Secure Communication - Dedicated Partition Scenario2: Non/low-secure device access - integrate in guest OS partition Scenario3: Device Multiple Access - Virtual Multiplexing Scenario 4 - Virtual Device - Interpartition Communication Scenario 5 - Scalability of the Architecture Next Steps References v

6 List of Figures Figure 1: Structure of Security Services... 2 Figure 2: Key for OVERSEE communication paths Figure 3: OVERSEE communication paths Figure 4: Example of prioritized capacity resource sharing Figure 5: Asymmetric Bi-directional mapping (ABM) Figure 6: Exchange Page Table Entry (XPTE) Figure 7: Secure Communication - Dedicated Partition Figure 8: Non/low-secure device access - integrate in guest OS partition Figure 9: Device Multiple Access - Virtual Multiplexing Figure 10: Virtual Device - Interpartition Communication Figure 11: Scalability of the Architecture vi

7 List of Tables Table 1: Security Service General Command Structure... 5 Table 2: Internal Key Structure... 6 Table 3: Key Structure for Export/Import... 7 Table 4: Cipher API... 9 Table 5: Cipher API, Output... 9 Table 6: CMAC API Table 7: CMAC API, Output Table 8: Hash and HMAC API Table 9: Hash and HMAC API, Output Table 10: Signature Generation API Table 11: Signature Generation API, Output Table 12: Signature Verification API Table 13: Signature Verification API, Output Table 14: Random Number Generator API Table 15: Random Number Generator API, Output Table 16: Counter API, Create counter Table 17: Counter API, Delete counter Table 18: Counter API, Output value create counter Table 19: Counter API, Increment counter Table 20: Counter API, Read counter Table 21: Counter API, Output value read counter Table 22: File encryption API Table 23: File encryption API, Output Table 24: File decryption API Table 25: File decryption API, Output Table 26: Content of software download configuration file Table 27: Captured errors, TOE and partition operation Table 28: Captured errors, Partition operation Table 29: Predefined actions Table 30: Security issues to be handled by the OVERSEE firewall Table 31: Classification of resources concerning prioritized resource access vii

8 List of Acronyms and Abbreviations 2G 3G ABM AES AMT API ARINC BIOS CA CAM CAN CBC CBC-MAC CC CCM CEN CMAC CPU CRL DENM DoS DSRC DTD ecall ECB ECC ECR ECU FiFo FPU GCM Second generation mobile phone system Third generation mobile phone system Asymmetric Bi-directional mapping Advanced Encryption Standard Abstract Machine Test Application Programming Interface Aeronautical Radio Incorporated Basic Input Output System Certification Authority Cooperative Awareness Message Controller area Network Cipher Block Chaining Cipher Block Chaining Message Authentication Code Common Criteria Counter with CBC-MAC European Committee for Standardization Cipher based MAC Central Processing Unit Certification revocation list Decentralized Environmental Notification Message Denial of Service Dedicated Short-Range Communications Document Type Definition Emergency Call Electronic Code Book Elliptic Curve Cryptography ECU configuration registers Electronic Control Unit First in First out Floating point unit Galois/Counter Mode viii

9 GNU GPS HAL HMAC HMI HSM HW I/O ICT IMA IP IPC ITS LDM MAC MILS MMU NIC NIST OEM OS OSEK PIFP PKCS PKI PoS POSIX PRNG PSAP QoS RAM RTE RTEMS RTOS GNU's not Unix Global Positioning System Hardware Abstraction Layer Hash based MAC Human Machine Interface Hardware Security Module Hardware Input Output Information and Communication Technology Modular Avionics Internet Protocol Inter Process Communication Intelligent Transportation System Local Dynamic Map Message Authentication Code Multiple Independent Levels of Security and Safety Memory Management Unit Network Interface Card National Institute of Standards and Technology Original Equipment Manufacturer Operating System Offene Systeme und deren Schnittstellen für die Elektronik im Kraftfahrzeug Partitioned Information Flow Policy Public Key Cryptography Standards Public Key Infrastructure Positioning Service Portable Operating System Interface (for Unix) Pseudo Random Number Generator Public-Safety Answering Point Quality of Service Random-access memory Runtime Environemnt Real-Time Operating System for Multiprocessor Systems Real-time Operating System ix

10 SecS SKPP SSL SSPM SVAS TLS TOE TSF USB V2X VDX VFB VM VMA VMM Wi-Fi XEX XML XPTE XTS Security Services Separation Kernel Protection Profile Secure Sockets Layer Security Services Provider Module Secure Vehicle Access Service Transport Layer Security Target Of Evaluation TOE Security Functions Universal Serial Bus Vehicle-to-X Vehicle Distributed executive Virtual Function Bus Virtual Machine/Virtual Machine Manager Virtual Memory Area Virtual Machine Manager/Monitor Wireless Fidelity Xor-Encrypt-Xor Extensible Markup Language Exchange Page Table Entry XEX-based Tweaked CodeBook x

11 Document History Version Date Changes Final version xi

12 1 Introduction The Open Vehicular Secure Platform (OVERSEE) project has produced this deliverable; therefore it contains contributions from all partners, while the main contributors are: escrypt, UPVLC, OpenTech and University of Siegen. The present document contains the specification of the security relevant features and capabilities of OVERSEE, hence a large part of the overall specification, since OVERSEE has a dedicated focus on security for open platforms. 1.1 Scope and Objectives of the Document The scope of this document is the specification of the security related features and capabilities of OVERSSE. Since OVERSEE is a project focusing on security from secure communication aspects to secure parallel execution of applications, this document contains a large part of the overall OVERSEE design. The objective of the actual document is to provide a global description for the implementation of the security related parts of OVERSEE. Thus, the document would be used as a kind of functional specification for the implementation phase and also a reference book concerning the security capabilities of the platform during usage. 1.2 Definitions For the purpose of the present document, the terms and definitions given in [1], [4] and [6] apply, if not otherwise noted. 1.3 Document Outline The document is structured as follows: Section 1 gives an introduction on the scope and intentions. Section 2 specifies the security services provided by OVERSEE. Section 3 is concerned with the description of the overall virtualization concept. Section 4 contains the specification of the OVERSEE firewall concept. Section 5 is dedicated to the secure assurance of prioritized access on shared resources and finally section 6 specifies the internal communication requirements in the virtualised environment. 1

13 2 Security Services 2.1 Overall Structure of Security Services Figure 1: Structure of Security Services Two main facts play a key role defining the requirements of the security services. First of all OVERSEE aims to provide a platform for ICT applications, which require a set of dependable security services. The second aspect is that OVERSEE provides multiple isolated runtime environments. This demands a strong level of isolation, which also has an impact on the security services. The OVERSEE security architecture basically consists of three parts. The first part is the hardware security module (HSM). The HSM provides accelerated cryptographic function execution, secure key and certificate storage, and registers for secure boot services. The second part is a dedicated partition for the security services. This partition owns exclusive rights to access the HSM and also hosts building blocks for further security services. The last part is the so-called security service provider module (SSPM). This module is a high level client located at the user partitions (or any other partition if needed) providing the link between user applications and security services. 2.2 Hardware Security Module The HSM is not part of the OVERSEE design however a crucial element in the security architecture. This part of the document will still list some requirements for the HSM on which the security services of OVERSEE will be build on. 2

14 Furthermore it is also possible to implement most of the functionality of a HSM in the security partition as a software version, though respectively in a less secure way. The design of OVERSEE is based on the existence of a HSM but the structure of the security partition will be specified in a flexible way to enable also a software implementation of HSM functionalities HSM Cryptographic Functions The cryptographic functions provided by the HSM are hardware-accelerated implementations of the algorithm thus offering higher performance than software implementations. In addition the HSM enables a secure environment for the cryptographic functions making any tampering attempts practically impossible. Furthermore key data used for the algorithms are also handled internally in the HSM, thus assuring security of key data. In order to satisfy the requirements to sign, verify and encrypt messages for V2X communications and PKI Infrastructure communications the following minimum set of functions are proposed by the OVERSEE design to be supported by the HSM: ECC-256: Asymmetric cryptographic engine based on elliptic curve arithmetic. Whirlpool: A hash function proposed by NIST. AES-128: A symmetric block encryption standard with a key length of 128 bits. It should support standard block encryption modes as ECB and CBC but also advanced modes as GCM and CCM. PRNG: A pseudo random number generator. Counters: Counter management with authorization. An implementation of further needed cryptographic functions into the security services partition would be a solution for creating a flexible and expandable design but is not a very secure method regarding key security. Therefore the HSM should also provide enhancement capabilities regarding cryptographic functions. That is the firmware of the HSM should enable realization of further cryptographic functions, even if supporting hardware blocks do not exist in the HSM. This would enable the implementation of cryptographic functions in software, e.g., ECC-224 as a candidate for cryptography in the upcoming ITS standards for Europe HSM Secure Key Storage The HSM features an internal storage for keys and certificates. The internal storage is not accessible directly over any interface, hence creating a secure storage for security relevant data. The exportation of a key from the HSM depends on the configuration of the relevant key. For further information on the security of key material and key management refer to Deliverable 2.4 [8]. 3

15 2.2.3 HSM Secure Boot Registers The HSM features so called ECU configuration registers (ECR) and assigned functions on which a secure and/or authenticated boot process can be built on. The following functionalities are provided in this context. Further information on secure boot process can be found in chapter 2.5. Extend ECR: This function is used for updating the ECR with a new (hash) value. The new value is pro-vided as input and chained together with the existing value stored in the ECR using a hash update function. Retrieve ECR: For any ECR, this function may be used to retrieve and verify its actual value. The ECR value is signed by a certification key whose usage authorization data needs to be presented as input. Furthermore, a nonce value, possibly obtained as a challenge from an external verifier, may be included to be able to prove the freshness of the signature. The ECR value together with its signature are returned as output Preset ECR: This function is used to manage references to ECR values by ECR indices in the context of secure boot. The function provides the possibilities to directly update an ECR with a new value, to set a new reference to an ECR index ("inherit") or to remove an existing reference ("clear"). Compare ECR: This function allows the direct comparison of the current ECR with a reference. If match fails, an automatic secure boot alarm may be activated. As a precondition, a reference must be set for the given ECR index, and an internal secure boot failure mechanism must be given HSM Hardware Interface The HW interface provided by the HSM is the dedicated interface to reach the functionality of the HSM. The interface depends on the HSM and the OVERSEE platform and will not be specified any further in the OVERSEE design. The proof of concept implementation will use any interface provided by the HSM without concerning any security aspects although the HW interface is an important communication path in the design respective security. Later implementations of the platform have to assure a secure interface; for further information refer to the document D2.4 [8]. 2.3 Security Services Partition The security services partition provides a secure and isolated runtime for the shared security services. Multiple partitions thus multiple applications will access the security functions of the platform. The security partition provides a trustable anchor in the whole security architecture and a controlled access to the security services as user partitions (and applications) have only restricted access to the security partition and services provided by the partition. In this section of the document the building blocks of the security partition are listed and described. Further specification of the building blocks is left to the implementation phase of the platform. The API to the security services are listed in section 2.4 where the client module for user partitions is specified. 4

16 2.3.1 Security Partition Binding The security services partition binding module is the first instance interfacing requests from the other partitions. The connection between the other partition and the security partition binding module exists of a queue in each direction for the commands and a shared memory for exchanging large chunks of data. The command structure received by the binding module can be seen in Table 1. The request ID is a unique label defined by the other partition for internal use at the other partition. This ID is followed by the command id and the parameters of the command. The security partition binding module handles the incoming command by adding the origin of the request and a unique handling id to the command before forwarding the command to the appropriate module. No. Name Description 1 Request ID A unique ID given by the user partition for the request. 2 Command ID ID of requested command. 3 Command parameters Parameters needed for the command. Details are specified in every method. Table 1: Security Service General Command Structure Hardware Security Module I/O Driver The HSM I/O driver is the interface to the HSM module. The driver is provided by the HSM manufacturer and therefore is out of scope of the OVERSEE design. The driver should provide a seamless integration of the HSM services into the runtime environment and function as a non-blocking device Cryptographic Services Module Any request for a cryptographic function is handled by the cryptographic functions module. The request is forwarded from the security services partition binding module and handled basically in this sequence: Check for authorization of requesting partition for requested service. Check for authorization of requested key and key usage. Subsequently the cryptographic service on the HSM is triggered or a software implementation of the requested cryptographic function is executed with the needed parameters Key Management Module The Key Management Module plays an important role in the security architecture of the OVERSEE design. Issues as authenticity, integrity and encryption are closely coupled to ownership of key information as the isolation of the security services for the multiple 5

17 partitions is mainly provided by defining different access rights to the key material. A key request is strictly handled by the key management module. The requesting partition has to be authorized for the requested key and the requested usage of the key. Only in this case the key data may be used for the requested security service by the user partition. The reliability of the origin of the request is assumed to be provided by the virtualization layer. Information regarding key management can be found in D2.4 Specification of Secure Communication [8]. An important role of the key management module is to integrate the key management functionality of the HSM with the virtualized environment of OVERSEE. Basically the key management of the HSM is not aware of the multiple runtime environments. The key management module builds an extra management stage between the user partition and the HSM providing the needed access control. The key management module also handles key export, import and creation requests from the other partitions. The API for the functionality is specified in chapter 2.4 Security Services Provider Module. Table 2: Internal Key Structure shows the internal key structure used in OVERSEE, Table 3 shows the encrypted key blob structure which is used in case of key importation/exportation. No Name Description 1 Algorithm Identifier This parameter determines the algorithm to be used with the key 2 Use Flags This parameter indicates the operations that may be performed with the key. 3 Key ID Identifier of the key. 4 Validity Indicates the last valid date the key can be used. 5 Certification Data This parameter is optional and may be used to certify the origin and/or properties of the key (e.g., by MVK). It may consist of, but is not limited to a digital signature. 6 Authorization Data This vector represents the authorization data items for each individual. (Passwords, list of authorized partitions) 7 Public Key Data Public key data bytes. 8 Private Key Data Private key data bytes. 9 Key handle Internal handle. Table 2: Internal Key Structure 6

18 No Name Description 1 Algorithm Identifier This parameter determines the algorithm to be used with the key 2 Use Flags This parameter indicates the operations that may be performed with the key. 3 Key ID Identifier of the key. 4 Validity Indicates the last valid date the key can be used. 5 Public Key Data Public key data bytes. 6 Encrypted Blob This part of the key structure includes all confidential key material encrypted with corresponding transport key. 7 Authentication Code This parameter is used to protect the integrity and authenticity of the key data. It may be either a MAC created by the symmetric transport key or a digital signature w/ IDK. Table 3: Key Structure for Export/Import Secure Storage The secure storage module is responsible for encrypting and decrypting files. The encryption procedure is described in the following steps. 1. The file to be encrypted arrives at the module from the user partition. 2. A random key K R is generated. 3. K R is used to encrypt the file. 4. K R is encrypted with the requested storage key K S. The user partition has to have the usage rights of this key. 5. The encrypted file, the encrypted key K R and the applied encryption parameters are bundled together as a file and sent back to the user partition. The API for the functionality is specified in chapter Certificate Handler The certificate handler is responsible for creating new certificates and handling incoming certificates. Certificates can be stored by this module. Additionally, the access control management for certificates is also done within the certificate handler module Security Services Configuration Table As mentioned before access to security services and key data requires proper access rights of the partitions. The security service configuration table provides a configuration tool to manage the access rights of the partitions. 7

19 Accessing and changing the table have to be done in a secure way to avoid any unauthorized changes in the table. The user has to prove authorization by a challenge-response process. Furthermore the table should also be not accessible offline. The table is either stored in the HSM or is encrypted before storing. The content of table should also be signed to avoid any offline changes in the table. 2.4 Security Services Provider Module The security services provider module (SSPM) is located at the user partition and is the client for accessing the security services provided by the security services partition. Furthermore, the SSPM provides high-level functionality for several services like communication protocols and secure storage. This means that only when services provided by the security services partition have to be accessed the client contacts the security services partition and requests the required service. The SSPM is an application level service running in the user partition. The connection to the security services partition is provided by the virtualization layer and consists of a queue for the requests and a shared memory area for exchanging larger chunks of data. The general command structure between the SSPM and security partition is described in section Security Partition Binding of this document. The next sections describe different services and the associated API s provided by the SSPM Cryptographic Services API Following are the methods provided by the cryptographic services module Cipher The cipher API provides the required method for general encryption/decryption. The algorithm and operation mode can be defined with the parameters. 8

20 No Name Description 1 Algorithm identifier Reference to associated symmetric algorithm 2 Cipher mode Indicate decryption or encryption mode 3 operation mode Indicate cipher mode of operation {ECB CBC GCM EAX..} 4 padding_scheme Indicate padding scheme {none bit byte pkcsx..} 5 IV_SIZE Size of given initialization vector (can be 0) 6 Key handle Handle (internal ID) of the requested key 7 Key Authorization Size Size of authorization value of the key 8 Key Authorization Value Authorization value of key 9 Input Data Pointer to input data 10 Input Data Size Size of input data Table 4: Cipher API No Name Description 1 Output Data Pointer to Output data 2 Output Data Size Size of Output data Table 5: Cipher API, Output CMAC The CMAC API provides the required method for cipher based MAC calculation. The algorithm and operation mode can be defined with the parameters. 9

21 No Name Description 1 Algorithm identifier Reference to associated symmetric algorithm 2 MAC mode Indicate MAC mode: sign, timestamped sign or verify 3 operation mode Indicate cipher mode of operation {CMAC/OMAC/ } 4 padding_scheme Indicate padding scheme {none bit byte pkcsx..} 5 Key handle Handle (internal ID) of the requested key 6 Key Authorization Size Size of authorization value of the key 7 Key Authorization Value Authorization value of key 8 Input Data Pointer to input data 9 Input Data Size Size of input data Table 6: CMAC API No Name Description 1 Output Data Pointer to Output data 2 Output Data Size Size of Output data Table 7: CMAC API, Output Hash and HMAC The HMAC API provides the required method for general hash calculation and hash based MAC calculation. The algorithm and operation mode can be defined with the parameters. No Name Description 1 Requesting Partition ID of partition requesting the service 2 Algorithm identifier Reference to associated symmetric algorithm 3 Hash mode Indicate hash or HMAC creation mode 4 Key handle Handle (internal ID) of the requested key 5 Key Authorization Size Size of authorization value of the key 6 Key Authorization Value Authorization value of key 7 Input Data Pointer to input data (to be verified MAC, or Data for creating MAC) 8 Input Data Size Size of input data Table 8: Hash and HMAC API 10

22 No Name Description 1 Output Data Pointer to Output data 2 Output Data Size Size of Output data Table 9: Hash and HMAC API, Output Signature Generation The following method is used to handle the generation of signatures with a private key. This method is applied to the complete message to be signed. No Name Description 1 Requesting Partition ID of partition requesting the service 2 Algorithm identifier Reference to associated asymmetric algorithm 3 Hash algorithm identifier Reference to associated hash algorithm 4 padding_scheme Indicate padding scheme {none bit byte pkcsx..} 5 Time stamp Indicate additional timestamp creation 6 Key handle Handle (internal ID) of the requested key 7 Key Authorization Size Size of authorization value of the key 8 Key Authorization Value Authorization value of key 9 Input Data Pointer to input data (to be verified MAC, or Data for creating MAC) 10 Input Data Size Size of input data Table 10: Signature Generation API No Name Description 1 Output Data Pointer to Output data 2 Output Data Size Size of Output data Table 11: Signature Generation API, Output Signature Verification The following method is used for signature verification. These functions are applied to the complete message whose signature shall be verified. 11

CycurHSM An Automotive-qualified Software Stack for Hardware Security Modules

CycurHSM An Automotive-qualified Software Stack for Hardware Security Modules CycurHSM An Automotive-qualified Software Stack for Hardware Security Modules Dr. Frederic Stumpf, ESCRYPT GmbH Embedded Security, Stuttgart, Germany 1 Introduction Electronic Control Units (ECU) are embedded

More information

Security Technical. Overview. BlackBerry Enterprise Service 10. BlackBerry Device Service Solution Version: 10.2

Security Technical. Overview. BlackBerry Enterprise Service 10. BlackBerry Device Service Solution Version: 10.2 BlackBerry Enterprise Service 10 BlackBerry Device Service Solution Version: 10.2 Security Technical Overview Published: 2014-09-10 SWD-20140908123239883 Contents 1 About BlackBerry Device Service solution

More information

NEXT GENERATION OF AUTOMOTIVE SECURITY: SECURE HARDWARE AND SECURE OPEN PLATFORMS

NEXT GENERATION OF AUTOMOTIVE SECURITY: SECURE HARDWARE AND SECURE OPEN PLATFORMS NEXT GENERATION OF AUTOMOTIVE SECURITY: SECURE HARDWARE AND SECURE OPEN PLATFORMS André Groll, Jan Holle University of Siegen, Institute for Data Communications Systems {andre.groll,jan.holle}@uni-siegen.de

More information

Hardware Security Modules for Protecting Embedded Systems

Hardware Security Modules for Protecting Embedded Systems Hardware Security Modules for Protecting Embedded Systems Marko Wolf, ESCRYPT GmbH Embedded Security, Munich, Germany André Weimerskirch, ESCRYPT Inc. Embedded Security, Ann Arbor, USA 1 Introduction &

More information

RELEASE NOTES. Table of Contents. Scope of the Document. [Latest Official] ADYTON Release 2.12.9 - corrections. ADYTON Release 2.12.

RELEASE NOTES. Table of Contents. Scope of the Document. [Latest Official] ADYTON Release 2.12.9 - corrections. ADYTON Release 2.12. Table of Contents Scope of the Document... 1 [Latest Official] ADYTON Release 2.12.9... 1 ADYTON Release 2.12.4... 1 ADYTON Release 2.9.3... 3 ADYTON Release 2.7.7... 3 ADYTON Release 2.6.2... 4 ADYTON

More information

7 Network Security. 7.1 Introduction 7.2 Improving the Security 7.3 Internet Security Framework. 7.5 Absolute Security?

7 Network Security. 7.1 Introduction 7.2 Improving the Security 7.3 Internet Security Framework. 7.5 Absolute Security? 7 Network Security 7.1 Introduction 7.2 Improving the Security 7.3 Internet Security Framework 7.4 Firewalls 7.5 Absolute Security? 7.1 Introduction Security of Communications data transport e.g. risk

More information

Chapter 11 Security+ Guide to Network Security Fundamentals, Third Edition Basic Cryptography

Chapter 11 Security+ Guide to Network Security Fundamentals, Third Edition Basic Cryptography Chapter 11 Security+ Guide to Network Security Fundamentals, Third Edition Basic Cryptography What Is Steganography? Steganography Process of hiding the existence of the data within another file Example:

More information

Overview. SSL Cryptography Overview CHAPTER 1

Overview. SSL Cryptography Overview CHAPTER 1 CHAPTER 1 Note The information in this chapter applies to both the ACE module and the ACE appliance unless otherwise noted. The features in this chapter apply to IPv4 and IPv6 unless otherwise noted. Secure

More information

VICTORIA UNIVERSITY OF WELLINGTON Te Whare Wānanga o te Ūpoko o te Ika a Māui

VICTORIA UNIVERSITY OF WELLINGTON Te Whare Wānanga o te Ūpoko o te Ika a Māui VICTORIA UNIVERSITY OF WELLINGTON Te Whare Wānanga o te Ūpoko o te Ika a Māui School of Engineering and Computer Science Te Kura Mātai Pūkaha, Pūrorohiko PO Box 600 Wellington New Zealand Tel: +64 4 463

More information

UM0586 User manual. STM32 Cryptographic Library. Introduction

UM0586 User manual. STM32 Cryptographic Library. Introduction User manual STM32 Cryptographic Library Introduction This manual describes the API of the STM32 cryptographic library (STM32-CRYP-LIB) that supports the following cryptographic algorithms: AES-128, AES-192,

More information

FIPS 140-2 Non- Proprietary Security Policy. McAfee SIEM Cryptographic Module, Version 1.0

FIPS 140-2 Non- Proprietary Security Policy. McAfee SIEM Cryptographic Module, Version 1.0 FIPS 40-2 Non- Proprietary Security Policy McAfee SIEM Cryptographic Module, Version.0 Document Version.4 December 2, 203 Document Version.4 McAfee Page of 6 Prepared For: Prepared By: McAfee, Inc. 282

More information

SecureDoc Disk Encryption Cryptographic Engine

SecureDoc Disk Encryption Cryptographic Engine SecureDoc Disk Encryption Cryptographic Engine FIPS 140-2 Non-Proprietary Security Policy Abstract: This document specifies Security Policy enforced by SecureDoc Cryptographic Engine compliant with the

More information

Overview of Cryptographic Tools for Data Security. Murat Kantarcioglu

Overview of Cryptographic Tools for Data Security. Murat Kantarcioglu UT DALLAS Erik Jonsson School of Engineering & Computer Science Overview of Cryptographic Tools for Data Security Murat Kantarcioglu Pag. 1 Purdue University Cryptographic Primitives We will discuss the

More information

FIPS 140 2 Non Proprietary Security Policy: Kingston Technology DataTraveler DT4000 Series USB Flash Drive

FIPS 140 2 Non Proprietary Security Policy: Kingston Technology DataTraveler DT4000 Series USB Flash Drive FIPS 140 2 Non Proprietary Security Policy Kingston Technology Company, Inc. DataTraveler DT4000 G2 Series USB Flash Drive Document Version 1.8 December 3, 2014 Document Version 1.8 Kingston Technology

More information

Overview of CSS SSL. SSL Cryptography Overview CHAPTER

Overview of CSS SSL. SSL Cryptography Overview CHAPTER CHAPTER 1 Secure Sockets Layer (SSL) is an application-level protocol that provides encryption technology for the Internet, ensuring secure transactions such as the transmission of credit card numbers

More information

Sync Security and Privacy Brief

Sync Security and Privacy Brief Introduction Security and privacy are two of the leading issues for users when transferring important files. Keeping data on-premises makes business and IT leaders feel more secure, but comes with technical

More information

Entrust Managed Services PKI. Getting started with digital certificates and Entrust Managed Services PKI. Document issue: 1.0

Entrust Managed Services PKI. Getting started with digital certificates and Entrust Managed Services PKI. Document issue: 1.0 Entrust Managed Services PKI Getting started with digital certificates and Entrust Managed Services PKI Document issue: 1.0 Date of issue: May 2009 Copyright 2009 Entrust. All rights reserved. Entrust

More information

KeyStone Architecture Security Accelerator (SA) User Guide

KeyStone Architecture Security Accelerator (SA) User Guide KeyStone Architecture Security Accelerator (SA) User Guide Literature Number: SPRUGY6B January 2013 Release History www.ti.com Release Date Description/Comments SPRUGY6B January 2013 Added addition engine

More information

Chapter 17. Transport-Level Security

Chapter 17. Transport-Level Security Chapter 17 Transport-Level Security Web Security Considerations The World Wide Web is fundamentally a client/server application running over the Internet and TCP/IP intranets The following characteristics

More information

SHE Secure Hardware Extension

SHE Secure Hardware Extension SHE Secure Hardware Extension Data Security for Automotive Embedded Systems Workshop on Cryptography and Embedded Security Embedded World @ Nuremberg, February 2012 Content Data Security - What does it

More information

Introducing etoken. What is etoken?

Introducing etoken. What is etoken? Introducing etoken Nirit Bear September 2002 What is etoken? Small & portable reader-less Smartcard Standard USB connectivity Logical and physical protection Tamper evident (vs. tamper proof) Water resistant

More information

SPC5-CRYP-LIB. SPC5 Software Cryptography Library. Description. Features. SHA-512 Random engine based on DRBG-AES-128

SPC5-CRYP-LIB. SPC5 Software Cryptography Library. Description. Features. SHA-512 Random engine based on DRBG-AES-128 SPC5 Software Cryptography Library Data brief SHA-512 Random engine based on DRBG-AES-128 RSA signature functions with PKCS#1v1.5 ECC (Elliptic Curve Cryptography): Key generation Scalar multiplication

More information

Table of Contents. Bibliografische Informationen http://d-nb.info/996514864. digitalisiert durch

Table of Contents. Bibliografische Informationen http://d-nb.info/996514864. digitalisiert durch 1 Introduction to Cryptography and Data Security 1 1.1 Overview of Cryptology (and This Book) 2 1.2 Symmetric Cryptography 4 1.2.1 Basics 4 1.2.2 Simple Symmetric Encryption: The Substitution Cipher...

More information

THE BCS PROFESSIONAL EXAMINATIONS BCS Level 6 Professional Graduate Diploma in IT. April 2009 EXAMINERS' REPORT. Network Information Systems

THE BCS PROFESSIONAL EXAMINATIONS BCS Level 6 Professional Graduate Diploma in IT. April 2009 EXAMINERS' REPORT. Network Information Systems THE BCS PROFESSIONAL EXAMINATIONS BCS Level 6 Professional Graduate Diploma in IT April 2009 EXAMINERS' REPORT Network Information Systems General Comments Last year examiners report a good pass rate with

More information

Vehicular On-board Security: EVITA Project

Vehicular On-board Security: EVITA Project C2C-CC Security Workshop 5 November 2009 VW, MobileLifeCampus Wolfsburg Hervé Seudié Corporate Sector Research and Advance Engineering Robert Bosch GmbH Outline 1. Project Scope and Objectives 2. Security

More information

GE Measurement & Control. Cyber Security for NEI 08-09

GE Measurement & Control. Cyber Security for NEI 08-09 GE Measurement & Control Cyber Security for NEI 08-09 Contents Cyber Security for NEI 08-09...3 Cyber Security Solution Support for NEI 08-09...3 1.0 Access Contols...4 2.0 Audit And Accountability...4

More information

Bit Chat: A Peer-to-Peer Instant Messenger

Bit Chat: A Peer-to-Peer Instant Messenger Bit Chat: A Peer-to-Peer Instant Messenger Shreyas Zare shreyas@technitium.com https://technitium.com December 20, 2015 Abstract. Bit Chat is a peer-to-peer instant messaging concept, allowing one-to-one

More information

How To Use Cmk On An Ipa (Intralinks) On A Pc Or Mac Mac (Apple) On An Iphone Or Ipa On A Mac Or Ipad (Apple Mac) On Pc Or Ipat (Apple

How To Use Cmk On An Ipa (Intralinks) On A Pc Or Mac Mac (Apple) On An Iphone Or Ipa On A Mac Or Ipad (Apple Mac) On Pc Or Ipat (Apple Intralinks Customer Managed Keys Technical Overview Version 2.0 October 2014 Copyright 2014 Intralinks, Inc. 1 Intralinks Customer Managed Keys, Technical Overview January 5, 2015 About This Document...

More information

Recommended 802.11 Wireless Local Area Network Architecture

Recommended 802.11 Wireless Local Area Network Architecture NATIONAL SECURITY AGENCY Ft. George G. Meade, MD I332-008R-2005 Dated: 23 September 2005 Network Hardware Analysis and Evaluation Division Systems and Network Attack Center Recommended 802.11 Wireless

More information

Chapter 10. Cloud Security Mechanisms

Chapter 10. Cloud Security Mechanisms Chapter 10. Cloud Security Mechanisms 10.1 Encryption 10.2 Hashing 10.3 Digital Signature 10.4 Public Key Infrastructure (PKI) 10.5 Identity and Access Management (IAM) 10.6 Single Sign-On (SSO) 10.7 Cloud-Based

More information

Data Protection: From PKI to Virtualization & Cloud

Data Protection: From PKI to Virtualization & Cloud Data Protection: From PKI to Virtualization & Cloud Raymond Yeung CISSP, CISA Senior Regional Director, HK/TW, ASEAN & A/NZ SafeNet Inc. Agenda What is PKI? And Value? Traditional PKI Usage Cloud Security

More information

FIPS 140-2 Non-Proprietary Security Policy. IBM Internet Security Systems SiteProtector Cryptographic Module (Version 1.0)

FIPS 140-2 Non-Proprietary Security Policy. IBM Internet Security Systems SiteProtector Cryptographic Module (Version 1.0) FIPS 140-2 Non-Proprietary Security Policy IBM Internet Security Systems SiteProtector Document Version 2.3 August 5, 2010 Document Version 2.3 IBM Internet Security Systems Page 1 of 24 Prepared For:

More information

Secure Sockets Layer (SSL ) / Transport Layer Security (TLS) Network Security Products S31213

Secure Sockets Layer (SSL ) / Transport Layer Security (TLS) Network Security Products S31213 Secure Sockets Layer (SSL ) / Transport Layer Security (TLS) Network Security Products S31213 UNCLASSIFIED Example http ://www. greatstuf f. com Wants credit card number ^ Look at lock on browser Use https

More information

Digital Certificates (Public Key Infrastructure) Reshma Afshar Indiana State University

Digital Certificates (Public Key Infrastructure) Reshma Afshar Indiana State University Digital Certificates (Public Key Infrastructure) Reshma Afshar Indiana State University October 2015 1 List of Figures Contents 1 Introduction 1 2 History 2 3 Public Key Infrastructure (PKI) 3 3.1 Certificate

More information

That Point of Sale is a PoS

That Point of Sale is a PoS SESSION ID: HTA-W02 That Point of Sale is a PoS Charles Henderson Vice President Managed Security Testing Trustwave @angus_tx David Byrne Senior Security Associate Bishop Fox Agenda POS Architecture Breach

More information

Accellion Secure File Transfer Cryptographic Module Security Policy Document Version 1.0. Accellion, Inc.

Accellion Secure File Transfer Cryptographic Module Security Policy Document Version 1.0. Accellion, Inc. Accellion Secure File Transfer Cryptographic Module Security Policy Document Version 1.0 Accellion, Inc. December 24, 2009 Copyright Accellion, Inc. 2009. May be reproduced only in its original entirety

More information

PRIME IDENTITY MANAGEMENT CORE

PRIME IDENTITY MANAGEMENT CORE PRIME IDENTITY MANAGEMENT CORE For secure enrollment applications processing and workflow management. PRIME Identity Management Core provides the foundation for any biometric identification platform. It

More information

BlackBerry Enterprise Service 10. Secure Work Space for ios and Android Version: 10.1.1. Security Note

BlackBerry Enterprise Service 10. Secure Work Space for ios and Android Version: 10.1.1. Security Note BlackBerry Enterprise Service 10 Secure Work Space for ios and Android Version: 10.1.1 Security Note Published: 2013-06-21 SWD-20130621110651069 Contents 1 About this guide...4 2 What is BlackBerry Enterprise

More information

Security Guide. BlackBerry Enterprise Service 12. for ios, Android, and Windows Phone. Version 12.0

Security Guide. BlackBerry Enterprise Service 12. for ios, Android, and Windows Phone. Version 12.0 Security Guide BlackBerry Enterprise Service 12 for ios, Android, and Windows Phone Version 12.0 Published: 2015-02-06 SWD-20150206130210406 Contents About this guide... 6 What is BES12?... 7 Key features

More information

Chapter 10. Network Security

Chapter 10. Network Security Chapter 10 Network Security 10.1. Chapter 10: Outline 10.1 INTRODUCTION 10.2 CONFIDENTIALITY 10.3 OTHER ASPECTS OF SECURITY 10.4 INTERNET SECURITY 10.5 FIREWALLS 10.2 Chapter 10: Objective We introduce

More information

White Paper How Noah Mobile uses Microsoft Azure Core Services

White Paper How Noah Mobile uses Microsoft Azure Core Services NoahMobile Documentation White Paper How Noah Mobile uses Microsoft Azure Core Services The Noah Mobile Cloud service is built for the Microsoft Azure platform. The solutions that are part of the Noah

More information

Network-Enabled Devices, AOS v.5.x.x. Content and Purpose of This Guide...1 User Management...2 Types of user accounts2

Network-Enabled Devices, AOS v.5.x.x. Content and Purpose of This Guide...1 User Management...2 Types of user accounts2 Contents Introduction--1 Content and Purpose of This Guide...........................1 User Management.........................................2 Types of user accounts2 Security--3 Security Features.........................................3

More information

Security Policy Revision Date: 23 April 2009

Security Policy Revision Date: 23 April 2009 Security Policy Revision Date: 23 April 2009 Remote Desktop Support Version 3.2.1 or later for Windows Version 3.1.2 or later for Linux and Mac 4 ISL Light Security Policy This section describes the procedure

More information

Part I. Universität Klagenfurt - IWAS Multimedia Kommunikation (VK) M. Euchner; Mai 2001. Siemens AG 2001, ICN M NT

Part I. Universität Klagenfurt - IWAS Multimedia Kommunikation (VK) M. Euchner; Mai 2001. Siemens AG 2001, ICN M NT Part I Contents Part I Introduction to Information Security Definition of Crypto Cryptographic Objectives Security Threats and Attacks The process Security Security Services Cryptography Cryptography (code

More information

Connected from everywhere. Cryptelo completely protects your data. Data transmitted to the server. Data sharing (both files and directory structure)

Connected from everywhere. Cryptelo completely protects your data. Data transmitted to the server. Data sharing (both files and directory structure) Cryptelo Drive Cryptelo Drive is a virtual drive, where your most sensitive data can be stored. Protect documents, contracts, business know-how, or photographs - in short, anything that must be kept safe.

More information

Configuring Security Features of Session Recording

Configuring Security Features of Session Recording Configuring Security Features of Session Recording Summary This article provides information about the security features of Citrix Session Recording and outlines the process of configuring Session Recording

More information

Cisco Trust Anchor Technologies

Cisco Trust Anchor Technologies Data Sheet Cisco Trust Anchor Technologies Overview Cisco Trust Anchor Technologies provide the foundation for trustworthy systems across Cisco. The Cisco Trust Anchor and a Secure Boot check of signed

More information

SecureAge SecureDs Data Breach Prevention Solution

SecureAge SecureDs Data Breach Prevention Solution SecureAge SecureDs Data Breach Prevention Solution In recent years, major cases of data loss and data leaks are reported almost every week. These include high profile cases like US government losing personal

More information

EVITA-Project.org: E-Safety Vehicle Intrusion Protected Applications

EVITA-Project.org: E-Safety Vehicle Intrusion Protected Applications EVITA-Project.org: E-Safety Vehicle Intrusion Protected Applications 7 th escar Embedded Security in Cars Conference November 24 25, 2009, Düsseldorf Dr.-Ing. Olaf Henniger, Fraunhofer SIT Darmstadt Hervé

More information

Symantec Corporation Symantec Enterprise Vault Cryptographic Module Software Version: 1.0.0.2

Symantec Corporation Symantec Enterprise Vault Cryptographic Module Software Version: 1.0.0.2 Symantec Corporation Symantec Enterprise Vault Cryptographic Module Software Version: 1.0.0.2 FIPS 140 2 Non Proprietary Security Policy FIPS Security Level: 1 Document Version: 1.1 Prepared for: Prepared

More information

Legal Notes. Regarding Trademarks. Models supported by the KX printer driver. 2011 KYOCERA MITA Corporation

Legal Notes. Regarding Trademarks. Models supported by the KX printer driver. 2011 KYOCERA MITA Corporation Legal Notes Unauthorized reproduction of all or part of this guide is prohibited. The information in this guide is subject to change without notice. We cannot be held liable for any problems arising from

More information

SENSE Security overview 2014

SENSE Security overview 2014 SENSE Security overview 2014 Abstract... 3 Overview... 4 Installation... 6 Device Control... 7 Enrolment Process... 8 Authentication... 9 Network Protection... 12 Local Storage... 13 Conclusion... 15 2

More information

Notes and terms of conditions. Vendor shall note the following terms and conditions/ information before they submit their quote.

Notes and terms of conditions. Vendor shall note the following terms and conditions/ information before they submit their quote. Specifications for ARINC 653 compliant RTOS & Development Environment Notes and terms of conditions Vendor shall note the following terms and conditions/ information before they submit their quote. 1.

More information

2.4: Authentication Authentication types Authentication schemes: RSA, Lamport s Hash Mutual Authentication Session Keys Trusted Intermediaries

2.4: Authentication Authentication types Authentication schemes: RSA, Lamport s Hash Mutual Authentication Session Keys Trusted Intermediaries Chapter 2: Security Techniques Background Secret Key Cryptography Public Key Cryptography Hash Functions Authentication Chapter 3: Security on Network and Transport Layer Chapter 4: Security on the Application

More information

Plain English Guide To Common Criteria Requirements In The. Field Device Protection Profile Version 0.75

Plain English Guide To Common Criteria Requirements In The. Field Device Protection Profile Version 0.75 Plain English Guide To Common Criteria Requirements In The Field Device Protection Profile Version 0.75 Prepared For: Process Control Security Requirements Forum (PCSRF) Prepared By: Digital Bond, Inc.

More information

Key & Data Storage on Mobile Devices

Key & Data Storage on Mobile Devices Key & Data Storage on Mobile Devices Advanced Computer Networks 2015/2016 Johannes Feichtner johannes.feichtner@iaik.tugraz.at Outline Why is this topic so delicate? Keys & Key Management High-Level Cryptography

More information

Authentication Types. Password-based Authentication. Off-Line Password Guessing

Authentication Types. Password-based Authentication. Off-Line Password Guessing Authentication Types Chapter 2: Security Techniques Background Secret Key Cryptography Public Key Cryptography Hash Functions Authentication Chapter 3: Security on Network and Transport Layer Chapter 4:

More information

Patterns for Secure Boot and Secure Storage in Computer Systems

Patterns for Secure Boot and Secure Storage in Computer Systems Patterns for Secure Boot and Secure Storage in Computer Systems Hans Löhr, Ahmad-Reza Sadeghi, Marcel Winandy Horst Görtz Institute for IT Security, Ruhr-University Bochum, Germany {hans.loehr,ahmad.sadeghi,marcel.winandy}@trust.rub.de

More information

Complying with PCI Data Security

Complying with PCI Data Security Complying with PCI Data Security Solution BRIEF Retailers, financial institutions, data processors, and any other vendors that manage credit card holder data today must adhere to strict policies for ensuring

More information

Security Guide. BlackBerry Enterprise Service 12. for BlackBerry. Version 12.0

Security Guide. BlackBerry Enterprise Service 12. for BlackBerry. Version 12.0 Security Guide BlackBerry Enterprise Service 12 for BlackBerry Version 12.0 Published: 2014-11-12 SWD-20141106140037727 Contents Introduction... 7 About this guide...8 What is BES12?...9 Key features of

More information

Security Technical. Overview. BlackBerry Enterprise Server for Microsoft Exchange. Version: 5.0 Service Pack: 4

Security Technical. Overview. BlackBerry Enterprise Server for Microsoft Exchange. Version: 5.0 Service Pack: 4 BlackBerry Enterprise Server for Microsoft Exchange Version: 5.0 Service Pack: 4 Security Technical Overview Published: 2014-01-17 SWD-20140117135425071 Contents 1 New in this release...10 2 Overview...

More information

Advanced Authentication

Advanced Authentication White Paper Advanced Authentication Introduction In this paper: Introduction 1 User Authentication 2 Device Authentication 3 Message Authentication 4 Advanced Authentication 5 Advanced Authentication is

More information

Snow Agent System Pilot Deployment version

Snow Agent System Pilot Deployment version Pilot Deployment version Security policy Revision: 1.0 Authors: Per Atle Bakkevoll, Johan Gustav Bellika, Lars, Taridzo Chomutare Page 1 of 8 Date of issue 03.07.2009 Revision history: Issue Details Who

More information

CRYPTOGRAPHY AS A SERVICE

CRYPTOGRAPHY AS A SERVICE CRYPTOGRAPHY AS A SERVICE Peter Robinson RSA, The Security Division of EMC Session ID: ADS R01 Session Classification: Advanced Introduction Deploying cryptographic keys to end points such as smart phones,

More information

VASCO Data Security International, Inc. DIGIPASS GO-7. FIPS 140-2 Non-Proprietary Cryptographic Module Security Policy

VASCO Data Security International, Inc. DIGIPASS GO-7. FIPS 140-2 Non-Proprietary Cryptographic Module Security Policy VASCO Data Security International, Inc. DIGIPASS GO-7 FIPS 140-2 Non-Proprietary Cryptographic Module Security Policy Security Level: 2 Version: 1.7 Date: August 12, 2015 Copyright VASCO Data Security

More information

EXAM questions for the course TTM4135 - Information Security May 2013. Part 1

EXAM questions for the course TTM4135 - Information Security May 2013. Part 1 EXAM questions for the course TTM4135 - Information Security May 2013 Part 1 This part consists of 5 questions all from one common topic. The number of maximal points for every correctly answered question

More information

ERserver. iseries. Secure Sockets Layer (SSL)

ERserver. iseries. Secure Sockets Layer (SSL) ERserver iseries Secure Sockets Layer (SSL) ERserver iseries Secure Sockets Layer (SSL) Copyright International Business Machines Corporation 2000, 2002. All rights reserved. US Government Users Restricted

More information

McAfee Firewall Enterprise 8.2.1

McAfee Firewall Enterprise 8.2.1 Configuration Guide FIPS 140 2 Revision A McAfee Firewall Enterprise 8.2.1 The McAfee Firewall Enterprise FIPS 140 2 Configuration Guide, version 8.2.1, provides instructions for setting up McAfee Firewall

More information

Content Teaching Academy at James Madison University

Content Teaching Academy at James Madison University Content Teaching Academy at James Madison University 1 2 The Battle Field: Computers, LANs & Internetworks 3 Definitions Computer Security - generic name for the collection of tools designed to protect

More information

WIND RIVER SECURE ANDROID CAPABILITY

WIND RIVER SECURE ANDROID CAPABILITY WIND RIVER SECURE ANDROID CAPABILITY Cyber warfare has swiftly migrated from hacking into enterprise networks and the Internet to targeting, and being triggered from, mobile devices. With the recent explosion

More information

Authenticity of Public Keys

Authenticity of Public Keys SSL/TLS EJ Jung 10/18/10 Authenticity of Public Keys Bob s key? private key Bob public key Problem: How does know that the public key she received is really Bob s public key? Distribution of Public Keys!

More information

12/3/08. Security in Wireless LANs and Mobile Networks. Wireless Magnifies Exposure Vulnerability. Mobility Makes it Difficult to Establish Trust

12/3/08. Security in Wireless LANs and Mobile Networks. Wireless Magnifies Exposure Vulnerability. Mobility Makes it Difficult to Establish Trust Security in Wireless LANs and Mobile Networks Wireless Magnifies Exposure Vulnerability Information going across the wireless link is exposed to anyone within radio range RF may extend beyond a room or

More information

Functional diagram: Secure encrypted data. totally encrypted. XOR encryption. RFID token. fingerprint reader. 128 bit AES in ECB mode Security HDD

Functional diagram: Secure encrypted data. totally encrypted. XOR encryption. RFID token. fingerprint reader. 128 bit AES in ECB mode Security HDD Secure encrypted data Encryption Access Control XOR encryption RFID token 128 bit AES in ECB mode Security HDD fingerprint reader enter password by keyboard 256 bit AES in CBC mode 1-2-3-4-5-6-7-8 PIN

More information

M-Shield mobile security technology

M-Shield mobile security technology Technology for Innovators TM M-Shield mobile security technology making wireless secure Overview As 3G networks are successfully deployed worldwide, opportunities are arising to deliver to end-users a

More information

Client Server Registration Protocol

Client Server Registration Protocol Client Server Registration Protocol The Client-Server protocol involves these following steps: 1. Login 2. Discovery phase User (Alice or Bob) has K s Server (S) has hash[pw A ].The passwords hashes are

More information

Securing Data on Microsoft SQL Server 2012

Securing Data on Microsoft SQL Server 2012 Securing Data on Microsoft SQL Server 2012 Course 55096 The goal of this two-day instructor-led course is to provide students with the database and SQL server security knowledge and skills necessary to

More information

Whitepaper Enhancing BitLocker Deployment and Management with SimplySecure. Addressing the Concerns of the IT Professional Rob Weber February 2015

Whitepaper Enhancing BitLocker Deployment and Management with SimplySecure. Addressing the Concerns of the IT Professional Rob Weber February 2015 Whitepaper Enhancing BitLocker Deployment and Management with SimplySecure Addressing the Concerns of the IT Professional Rob Weber February 2015 Page 2 Table of Contents What is BitLocker?... 3 What is

More information

Skoot Secure File Transfer

Skoot Secure File Transfer Page 1 Skoot Secure File Transfer Sharing information has become fundamental to organizational success. And as the value of that information whether expressed as mission critical or in monetary terms increases,

More information

Certification Report

Certification Report Certification Report EAL 4 Evaluation of SecureDoc Disk Encryption Version 4.3C Issued by: Communications Security Establishment Certification Body Canadian Common Criteria Evaluation and Certification

More information

How To Encrypt Data With Encryption

How To Encrypt Data With Encryption USING ENCRYPTION TO PROTECT SENSITIVE INFORMATION Commonwealth Office of Technology Security Month Seminars Alternate Title? Boy, am I surprised. The Entrust guy who has mentioned PKI during every Security

More information

Security vulnerabilities in the Internet and possible solutions

Security vulnerabilities in the Internet and possible solutions Security vulnerabilities in the Internet and possible solutions 1. Introduction The foundation of today's Internet is the TCP/IP protocol suite. Since the time when these specifications were finished in

More information

DRAFT Standard Statement Encryption

DRAFT Standard Statement Encryption DRAFT Standard Statement Encryption Title: Encryption Standard Document Number: SS-70-006 Effective Date: x/x/2010 Published by: Department of Information Systems 1. Purpose Sensitive information held

More information

Archived NIST Technical Series Publication

Archived NIST Technical Series Publication Archived NIST Technical Series Publication The attached publication has been archived (withdrawn), and is provided solely for historical purposes. It may have been superseded by another publication (indicated

More information

SMPTE Standards Transition Issues for NIST/FIPS Requirements v1.1

SMPTE Standards Transition Issues for NIST/FIPS Requirements v1.1 SMPTE Standards Transition Issues for NIST/FIPS Requirements v1.1 Contents 2010.8.23 DRM inside, Taehyun Kim ETRI, Kisoon Yoon 1 Introduction NIST (National Institute of Standards and Technology) published

More information

YubiKey Integration for Full Disk Encryption

YubiKey Integration for Full Disk Encryption YubiKey Integration for Full Disk Encryption Pre-Boot Authentication Version 1.2 May 7, 2012 Introduction Disclaimer yubico Yubico is the leading provider of simple, open online identity protection. The

More information

Kaspersky Lab s Full Disk Encryption Technology

Kaspersky Lab s Full Disk Encryption Technology Kaspersky Lab s Full Disk Encryption Technology In the US alone, an estimated 12,000 laptops are lost or stolen each week. According to the Ponemon Institute, a laptop is stolen every 53 seconds; more

More information

Secure Network Communications FIPS 140 2 Non Proprietary Security Policy

Secure Network Communications FIPS 140 2 Non Proprietary Security Policy Secure Network Communications FIPS 140 2 Non Proprietary Security Policy 21 June 2010 Table of Contents Introduction Module Specification Ports and Interfaces Approved Algorithms Test Environment Roles

More information

Exploring ADSS Server Signing Services

Exploring ADSS Server Signing Services ADSS Server is a multi-function server providing digital signature creation and signature verification services, as well as supporting other infrastructure services including Time Stamp Authority (TSA)

More information

Savitribai Phule Pune University

Savitribai Phule Pune University Savitribai Phule Pune University Centre for Information and Network Security Course: Introduction to Cyber Security / Information Security Module : Pre-requisites in Information and Network Security Chapter

More information

Certification Report

Certification Report Certification Report EAL 4+ Evaluation of Entrust Authority Security Manager and Security Manager Administration v8.1 SP1 Issued by: Communications Security Establishment Canada Certification Body Canadian

More information

INTRODUCTION to CRYPTOGRAPHY & CRYPTOGRAPHIC SERVICES on Z/OS BOSTON UNIVERSITY SECURITY CAMP MARCH 14, 2003

INTRODUCTION to CRYPTOGRAPHY & CRYPTOGRAPHIC SERVICES on Z/OS BOSTON UNIVERSITY SECURITY CAMP MARCH 14, 2003 INTRODUCTION to CRYPTOGRAPHY & CRYPTOGRAPHIC SERVICES on Z/OS BOSTON UNIVERSITY SECURITY CAMP MARCH 14, 2003 History of Cryptography The concept of securing messages through cryptography has a long history.

More information

CHANCES AND RISKS FOR SECURITY IN MULTICORE PROCESSORS

CHANCES AND RISKS FOR SECURITY IN MULTICORE PROCESSORS CHANCES AND RISKS FOR SECURITY IN MULTICORE PROCESSORS Prof. Dr.-Ing. Georg Sigl Institute for Security in Information Technology Technical University Munich sigl@tum.de Fraunhofer Research Institution

More information

BlackBerry Enterprise Server 5.0 SP3 and BlackBerry 7.1

BlackBerry Enterprise Server 5.0 SP3 and BlackBerry 7.1 BlackBerry Enterprise Server 5.0 SP3 and BlackBerry 7.1 Version: 5.0 Service Pack: 3 Security Technical Overview Published: 2012-01-17 SWD-1936256-0117012253-001 Contents 1 Document revision history...

More information

Single Sign-On Secure Authentication Password Mechanism

Single Sign-On Secure Authentication Password Mechanism Single Sign-On Secure Authentication Password Mechanism Deepali M. Devkate, N.D.Kale ME Student, Department of CE, PVPIT, Bavdhan, SavitribaiPhule University Pune, Maharashtra,India. Assistant Professor,

More information

Authentication Application

Authentication Application Authentication Application KERBEROS In an open distributed environment servers to be able to restrict access to authorized users to be able to authenticate requests for service a workstation cannot be

More information

Secure Shell SSH provides support for secure remote login, secure file transfer, and secure TCP/IP and X11 forwarding. It can automatically encrypt,

Secure Shell SSH provides support for secure remote login, secure file transfer, and secure TCP/IP and X11 forwarding. It can automatically encrypt, Secure Shell SSH provides support for secure remote login, secure file transfer, and secure TCP/IP and X11 forwarding. It can automatically encrypt, authenticate, and compress transmitted data. The main

More information

Dashlane Security Whitepaper

Dashlane Security Whitepaper Dashlane Security Whitepaper November 2014 Protection of User Data in Dashlane Protection of User Data in Dashlane relies on 3 separate secrets: The User Master Password Never stored locally nor remotely.

More information

Chapter 1: Introduction

Chapter 1: Introduction Chapter 1 Introduction 1 Chapter 1: Introduction 1.1 Inspiration Cloud Computing Inspired by the cloud computing characteristics like pay per use, rapid elasticity, scalable, on demand self service, secure

More information

Technical Description. DigitalSign 3.1. State of the art legally valid electronic signature. The best, most secure and complete software for

Technical Description. DigitalSign 3.1. State of the art legally valid electronic signature. The best, most secure and complete software for Technical Description DigitalSign 3.1 State of the art legally valid electronic signature The best, most secure and complete software for Adding digital signatures to any document, in conformance with

More information

WICKSoft Mobile Documents for the BlackBerry Security white paper mobile document access for the Enterprise

WICKSoft Mobile Documents for the BlackBerry Security white paper mobile document access for the Enterprise WICKSoft Mobile Documents for the BlackBerry Security white paper mobile document access for the Enterprise WICKSoft Corporation http://www.wicksoft.com Copyright WICKSoft 2007. WICKSoft Mobile Documents

More information