product and technology news

18
Product and Technology News Georg Bommer, Inter-Networking AG (Switzerland)

Upload: michel

Post on 18-Jan-2016

19 views

Category:

Documents


3 download

DESCRIPTION

Product and Technology News. Georg Bommer, Inter-Networking AG (Switzerland). Content. Control of SSL Connections Document Security Management Mail Encryption without PKI. Control of SSL Connections. Valid Certificate? Who decides?. Control of SSL Connections. Content Scanner - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: Product and Technology News

Product and Technology News

Georg Bommer, Inter-Networking AG (Switzerland)

Page 2: Product and Technology News

Content

Control of SSL Connections Document Security Management Mail Encryption without PKI

Page 3: Product and Technology News

Control of SSL Connections

Valid Certificate? Who decides?

Page 4: Product and Technology News

Public

CA

Public

CA

Content ScannerAnti-Virus, Malicious Code, URL

Filter, Attachment Restrictions

IDS Sensor

Content SecurityPolicy Enforcement

Control of SSL Connections

Page 5: Product and Technology News

Control of SSL Connections Certificate Management

– Relying on CA List of Browser– No CRL checking possible– User decision to accept or not a certificate

Policy Enforcement– Services used can not be controlled– Content Scanning/Inspection is not possible– Policy for up- and download of data and attachments can not be enforced

Other Problems– Web-Server can enforce encrypted connection

Solution– Central Certificate Management– Content Inspection of SSL Traffic

Plattform Support Windows, Solaris, Linux Proxy Mode and ICAP Support

Page 6: Product and Technology News

Public

CA

Public

CA

Content ScannerAnti-Virus, Malicious Code, URL

Filter, Attachment Restrictions

IDS Sensor

Microdasys SCIP

Decryption SSL to HTTPCertificate CheckEncryption HTTP to SSLContent ScanningSSL Tunneling

Microdasys SCIP - Solution

Page 7: Product and Technology News

Microdasys SCIP - Summary

Functionality– Central Certificate Management– Decryption of SSL Connections– Control of SSL Connections

Features– Support for Windows, Solaris, Linux– High Availablity / Clustering– Proxy Mode and ICAP Support

www.microdasys.com

Page 8: Product and Technology News

Document Security Management

Control sensitive documents while they are in use

Enforce proper handling when in use• Printing• Copying • Pasting• Screen Capturing• Saving• Forwarding

Audit user activity

Page 9: Product and Technology News

Document Security ManagementMirage Server- Management- Interceptor- Document Proc.- Print Server- Key Server- Web Server

Documents - HTML - MS Word - MS Excel - Plaint Text - PDF

File ServerDocument Mgmt System

Mirage Client- Document Decryption- Controls Document Handling

Secure Printer

HTMLSecure Display Technology

Page 10: Product and Technology News

Step 2Server determines that requested document is protected

Step 3Document is converted to HTML and encrypted (AES 128bit)

Finjan Mirage - Solution

Mirage Server Key Server

MirageClient

Step 1 Users requests secure document from web server (HTTP Request)

Step 4 Encrypted document is sent back to user (HTML)

Step 5 Client requests key from Key Server (PKCS#7 + HTTP)

Step 6 User is authenticated and document key is returned

Page 11: Product and Technology News

Finjan Mirage Enterprise - Summary

Functionality– Protection of sensitive documents– Control + audit document handling – Enforce information security policy

Features– Unique „Secure Display“ Technology– Supported formats; MS Word, Excel, HTML

Pages, Plain Text, PDF Files – Integration with Document Management Systems

such as LiveLink

www.finjan.com

Page 12: Product and Technology News

Mail Encryption without PKI

Requirements for mail encryption– Ease of use– Policy enforcement– Open standards– Quick and easy deployement

Problems PKI– Roll-out of certificates – Management of keys (recovery, revocation)– Exchange keys with third parties– Validate external keys

Page 13: Product and Technology News

Mail Encryption without PKIEncryption Gateway Automatic Key Generation for Mail User, Encryption/De-cryption, Management of Private Keys

Internal Key Server Customers + Partners Public Keys

Public Key Server Employees Public Key

Key Administrator Validates Public Keys from Customer/Partners

<

Pu

bli

cMail Server

Content Scanner

Private

Mail User

Mail User

Key Administrator

External Key Server

Internal Key Server

Encryption Gateway

Private KeyRepository

Mail Userwith any OpenPGPor S/Mime Client

Mail Userwith any OpenPGPor S/Mime Client

Page 14: Product and Technology News

<

Pu

bli

cMail Server

Content Scanner

Private

Mail User

Mail User

Key Administrator

External Key Server

Internal Key Server

Encryption Gateway

Private KeyRepository

Mail Userwith any OpenPGPor S/Mime Client

Mail Userwith any OpenPGPor S/Mime Client

Automatic Key Generation

Page 15: Product and Technology News

<

Pu

bli

cMail Server

Content Scanner

Private

Mail User

Mail User

Key Administrator

External Key Server

Internal Key Server

Encryption Gateway

Private KeyRepository

Mail Userwith any OpenPGPor S/Mime Client

Mail Userwith any OpenPGPor S/Mime Client

Key Exchange + Validation

Page 16: Product and Technology News

<

Pu

bli

cMail Server

Content Scanner

Private

Mail User

Mail User

Key Administrator

External Key Server

Internal Key Server

Encryption Gateway

Private KeyRepository

Mail Userwith any OpenPGPor S/Mime Client

Mail Userwith any OpenPGPor S/Mime Client

Mail Encryption + SigningMail Policy

Page 17: Product and Technology News

CryptoEx Summary Functionality

– Gateway based encryption and signing of e-mails with individual user keys

– Fully automated key generation and management of users private keys

– Decentralized key validation Features

– No PKI needed– Support for OpenPGP + S/Mime (Q4/03)– Support for multiple HTTP + LDAP key store– Policy enforcement at the gateway– Fully transparent to the user

www.cryptoex.com

Page 18: Product and Technology News

Thank you !Georg Bommer

Inter-Networking AG (Switzerland)

[email protected]