|
Data Security : Strong encryption storage for forward-positioned applications using secure hardware keys for information assurance | ||
|
Smartronix, Decru, and Network Appliance today announced a secure storage solution designed for forward-deployed environments. The Expeditionary Encrypted Data Store (EEDS) combines storage systems and security appliances in a ruggedized, portable case. EEDS delivers reliable, intuitive storage functionality paired with powerful security features to support a broad range of missions. Increasingly, modern operations require forward deployment of computing systems. These net-centric systems provide tremendous strategic advantages, but also expose an increasing amount of sensitive or classified data to new security challenges. Forward-deployed computer systems present a particularly difficult challenge, because physical capture of mission data and software could expose vast amounts of actionable intelligence to adversaries. Due to the power of modern forensic tools, data stored on disk drives is essentially indelible, further complicating the task of sanitizing data on short notice. The Expeditionary Encrypted Data Store solution takes a simple approach: never store mission data in cleartext format. All data and applications are secured with strong encryption, and in the event of imminent capture, users can use Decru Crypto Shred features to instantly delete local encryption keys by pushing a button or turning a key. Because encryption keys are stored in secure hardware, and data is never written to disk in cleartext format, deleting the keys provides instant sanitization of the entire system. Backup encryption keys are securely stored at headquarters, and can be securely injected over the Global Information Grid, enabling rapid operational recovery from false alarms. EEDS also enables operators to temporarily lock down systems by removing a cryptographic ignition key stored on a smart card. This feature enables systems to be securely transported, serviced, and deployed without exposing mission data to physical or electronic breaches. For example, a forward-deployed data center could be provisioned with pre-staged mission data, but all data would remain in encrypted format until authorized personnel arrive with the appropriate smart cards. In addition to providing security against physical attempts, the EEDS solution provides the security and flexibility to support a broad array of operational missions. Examples include:
Powerful NetApp storage features ensure availability and simplicity. For example, NetApp Snap Mirror software enables automatic and network-efficient replication of data to ensure continuity of operations. Because the software mirrors encrypted data from one system to another, all replicated copies are secure by default. Encryption keys can be securely injected into a remote Data Fort on demand when a recovery event arises, but until then no user or application at the remote site can access data. "EEDS demonstrates the power of integrating best-of-breed technologies into a field-ready solution. Our experience deploying rugged tactical solutions combined with our lead roles on major information assurance initiatives makes us a natural choice to partner with NetApp and Decru to deliver this enhanced security solution"," said John Parris, vice president corporate strategy of Smartronix. "We predict that the days of cleartext data are numbered," said Carl Wright, vice president of federal operations at Decru, and former CISO of the U.S. Marine Corps. "The EEDS solution delivers transparent and rugged performance in the field without compromising security, performance or simplicity. We're very pleased to collaborate with Smartronix and NetApp on this project." "NetApp's high rate of adoption is a direct result of our customer and solution focus," said Mark Weber of Network Appliance. "Protection of data in harm's way is a major priority for our customers, and EEDS is the industry's first integrated solution to directly address these requirements." Decru DataFort has received FIPS 140-2 Level 3 certification, as well as NIST certification for AES-256 and SHA-256, and is underway with Common Criteria certification with a target assurance level of EAL-4+. NetApp and Decru received DoD 5015.2 certification in September 2003, including certification of CryptoShred functionality for document shredding. NetApp and Decru solutions have been deployed by customers in sectors including financial services, healthcare, high technology, aerospace, and government. Smartronix specializes in Enterprise Architecture, Engineering and Operations, Information Systems Security, System and Software Engineering, Specialized Hardware Engineering Solutions, and Program and Acquisition Management. Decru develops storage security solutions to address a range of business needs for enterprises and government, including intellectual property protection, regulatory compliance, privacy, and internal controls. Network Appliance is a world leader in unified storage solutions for today's data-intensive enterprise. | ||
| October 26, 2004 | Feedback | © Yenra | |