Showing posts with label cryptography. Show all posts
Showing posts with label cryptography. Show all posts

Saturday, December 28, 2019

Greenliant SATA 2.5-inch EnduroSLC industrial enterprise SSDs deliver SLC data storage that provide ultra high endurance

Greenliant is currently sampling its SATA 2.5-inch EnduroSLC Industrial Enterprise EX Series solid state drives (SSDs) for primary storage applications that require ultra high endurance under extreme temperature conditions. 

Designed with Greenliant’s EnduroSLC technology, SATA 2.5-inch Industrial Enterprise EX Series SSDs provide ultra robust data retention and ultra high system-level lifetime endurance of 30 drive writes per day (DWPD) for 5 years. EnduroSLC is a proprietary 3D NAND management technology that delivers high reliability applications requiring superior data retention and endurance in extreme temperature, high stress environments. 



With advanced hardware ECC capabilities and NAND flash management algorithms, EnduroSLC Technology significantly extends the write endurance of 1-bit-per-cell (SLC) SSDs reaching industry leading 250K+ program-erase (P/E) cycles. EnduroSLC enabled products meet robust data retention requirements under complex temperature conditions and support wide cross-temperature ranges between data programming and reading. Further, due to its substantially lower bit error rate, an EnduroSLC SSD provides better consistency in read/write performance throughout product lifetime. 

The SATA 2.5-inch EnduroSLC industrial enterprise SSDs with 1-bit-per-cell (SLC) NAND include ultra high endurance that reaches 30 DWPD for five years; high capacity offered from 800 gigabytes to 1.92 terabytes; on-chip adaptive RAID that improves SSD reliability; power interrupt data protection that helps prevent data corruption during power failures; industrial temperature that operates between -40 and +85 degrees Celsius; and data security supports AES 256-bit encryption and crypto erase.

By leveraging over 25 years of solid state storage design expertise, Greenliant is dedicated to developing durable, reliable and secure storage solutions for embedded systems and enterprise data centers. The company is headquartered in Silicon Valley with product development centers in Santa Clara, Beijing, Shanghai, Xiamen and Hsinchu.


“Greenliant has brought its SLC NAND expertise to the enterprise with its new line of EnduroSLC Industrial Enterprise EX Series SSDs,” said Xuanhui Li, vice president of business development for datacenter products, Greenliant. “With high reliability and outstanding quality of service, Greenliant’s industrial enterprise storage products are ideal for mission critical, I/O intensive applications in aerospace, defense, transportation, energy and power, communications and industrial control.”

The SATA 2.5-inch Industrial Enterprise EX Series expands the EnduroSLC product family, which also includes SATA M.2 2242/2280, mSATA, SATA 2.5-inch and CFast ArmourDrive, and SATA 6Gb/s NANDrive and 100-ball/153-ball eMMC NANDrive ball grid array (BGA) SSDs.

Greenliant is sampling its new G3200 Industrial Enterprise EX Series SSDs to customers now, and expects to start shipping in volume production by end of this year. Greenliant is also shipping its 3-bit-per-cell (3D TLC NAND) G3100 Enterprise PX Series SSDs in capacities from 480 GB to 3.84 TB. 

Tuesday, December 24, 2019

Keyfactor researchers discover RSA certificate vulnerability, break nearly 250,000 distinct RSA keys

Keyfactor released research findings identifying a vulnerability across active RSA certificates. RSA certificates and the RSA algorithm are commonly used to securely transmit data to a remote source. Using minimal computing resources, researchers were able to collect and analyze 175 million RSA certificates and keys used to protect real-world Internet traffic.


The active and publicly available RSA keys (which consist of the product of two large, randomly chosen primes) were mined to identify common factors. Any keys sharing one of their prime factors with another key are compromised by this technique. The analysis found over 435,000 certificates with a shared factor, with researchers able to rederive the private key.

“The findings are alarming,” said Ted Shorter, chief technology officer and co-founder at Keyfactor. “The research finds inordinate rates of compromise impacting IoT devices with design constraints and limited entropy. These devices could include cars, medical implants and other critical devices, that if compromised, could result in life-impacting harm.”


“In a real-world attack scenario, a threat actor with a re-derived private key for an SSL/TLS server certificate could impersonate that server when devices attempt to connect,” said JD Kilgallin, senior integration engineer and researcher at Keyfactor. “The connecting user or device cannot distinguish the attacker from the legitimate certificate holder, opening the door to critical device malfunction or exposure of sensitive data.”

When these devices include medical implants and cars, the impact of the malfunction can be devastating. The research stresses the importance of security best practices, random number generation for connected systems and use of cryptography to securely install firmware and software updates through the lifecycle of the device.

“Security at design is paramount for device manufacturers,” said Shorter. “Current-generation connected devices and systems must be equipped to defend against a new generation of security risks. Cryptography is essential in ensuring new and emerging devices are able to adhere to and scale with security best practices.”


Researchers built a database of 75 million active RSA keys using Keyfactor’s proprietary SSL/TLS certificate discovery capabilities. The dataset was augmented using 100 million certificates available through certificate transparency logs and analyzed on a single virtual machine in Microsoft Azure, using Keyfactor’s scalable GCD algorithm to find shared factors. 


Wednesday, December 11, 2019

Red Hat extends security profile of its Enterprise Linux platform, renews FIPS 140-2 validation for Red Hat Enterprise Linux 7.6

Red Hat announced Tuesday the renewal of the Federal Information Processing Standard 140-2 (FIPS 140-2) security validations for Red Hat Enterprise Linux 7.6. Driven by the National Institute of Standards and Technology (NIST), FIPS 140-2 is a computer security standard that specifies the requirements for cryptographic modules -- including both hardware and software components -- used within a security system to protect sensitive information.


This renewed validation maintains and extends Red Hat’s leadership in providing mission-critical-ready open source technologies to government agencies and regulated industries, such as healthcare and telecommunications. 

With Red Hat’s FIPS 140-2 validated solutions, these industries can better meet necessary information security guidelines without compromising on the need for flexible software solutions. Red Hat maintains a strong commitment to providing open, more secure IT innovation to the public sector, with the company’s technologies now holding more than 20 active FIPS validations that meet the criteria for use by U.S. government agencies.


FIPS 140-2 validation is needed when agencies determine that specific information systems should use cryptography to protect data; if cryptography is required, then it must be validated. In order to achieve FIPS 140-2 validation, cryptographic modules are subject to testing by NIST-accredited independent Cryptographic and Security Testing Laboratories. 

The validation for Red Hat Enterprise Linux 7.6 was performed by Atsec information security corporation’s Cryptographic and Security Testing Laboratory in Austin, Texas. Atsec is an independent organization with long-standing experience in IT security standards.


In addition to the renewed certification of Red Hat Enterprise Linux 7.6, Red Hat Enterprise Linux 7.7 and Red Hat Enterprise Linux 8.1 are currently on the NIST "Implementation Under Test" list with the intent to extend FIPS 140-2 validation to the latest releases of the Red Hat Enterprise Linux 7 and Red Hat Enterprise Linux 8 platforms.

Monday, November 25, 2019

Utimaco strengthens data protection by releasing quantum-safe hardware security module for blockchain solutions

Utimaco has launched its Block-safe, its new hardware security module (HSM) designed for use with blockchain-based platforms that feature distributed ledger technology. An HSM is crucial to securing blockchain systems in order to cryptographically protect the information stored in them, maintain information integrity and ensure audit compliance. 


Utimaco Block-safe enables companies to generate, manage and protect cryptographic keys for blockchain applications. For example, private keys can be securely stored in accordance with PSD2 and GDPR security requirements. In addition, Block-safe allows for easy integration of new deployments in highly regulated environments, such as “Know Your Customer” (KYC) processes in accordance with the Money Laundering Act or smart payment methods based on blockchain.

Utimaco Block-safe generates private and public key pairs according to common blockchain-specific elliptic curves such as Secp256k1 (Bitcoin) or Stellar Ed25519 (Ethereum). Transactions can also be secured with MultiSign, whereby Block-safe allows the number of keys required for a valid transaction to be specified and verified (M from N-consensus procedure). 


Key pairs can be derived from a single master key in a secure environment according to BIP-32. The hierarchically deterministic wallets are also secured by using two-factor authentication with smart cards, and role-based access controls and separation of functions can be configured to secure the keys even further.


A software development kit enables Utimaco Block-safe to be configured to meet the individual requirements of companies. Furthermore, Block-safe has built-in post-quantum secure cryptographic random number generators in accordance with the SP 800-90 recommendation of the National Institute of Standards and Technology (NIST).

Wednesday, October 30, 2019

Vault12 introduces personal cryptocurrency security offering, engages friends and family to safeguard crypto assets

Vault12 launched its initial personal cryptocurrency security solution to provide distributed, decentralized backup of crypto assets for individual users. Vault12 uses the principles of Hierarchical Threshold Shamir's Secret Sharing and advanced proprietary technology to enable an individual's network of trusted friends and family, known as Guardians, to safeguard their crypto assets. 

Vault12 is a cryptographic security platform to provide end-to-end management of encrypted shards, ensuring that no one has to manually deal with cryptographic components. To incentivize Guardians to help secure users' Vaults, Guardians will be paid in Ethereum. The company is backed by Winklevoss Capital, True Ventures, Naval Ravikant and Data Collective. 


Cryptocurrency assets are routinely stored in local hardware and software wallets or in centralized online accounts. Unfortunately, these approaches have significant drawbacks and weaknesses. Exchanges are vulnerable to hacks and theft, while wallets are often lost or keys are forgotten by owners, resulting in billions of dollars in lost cryptocurrency that will never be retrieved. 

Designed to be used alongside traditional hardware, software and online wallets, Vault12 helps cryptocurrency owners, ICO investors, professional cryptocurrency traders, and high net worth investors safeguard their assets without storing anything in the cloud.

Instead of leaving recovery phrases or private keys centralized in a single place, with a single person, on a single device or within a single organization, the platform conveniently enables users to store crypto assets in a storage system that is not located on any cloud server, but only on a distributed network of people and devices. 

Vault12 marries decentralized cryptography with a decentralized storage network to form an infrastructure that protects cryptocurrencies with full owner control, complete privacy, reliability, and high availability. Owners of crypto assets can quickly set up digital Vaults that are quantum-resistant and highly resilient to attacks on any part of the cryptostorage infrastructure. Users will be able to access their assets by requesting approval from their Guardians, who will be paid in Ethereum for their services. 


"Safeguarding money is necessary for the crypto economy to flourish," said Cameron Winklevoss of Winklevoss Capital. "Vault12's distributed, decentralized, and server-less approach to security helps reduce friction associated with securing crypto assets. We look forward to seeing the company continue to innovate in the crypto security space." 

"One of the unresolved challenges for the mass adoption of cryptocurrency and the blockchain economy is the continued challenge and burden associated with securing crypto assets," said Max Skibinksy, co-founder and CEO of Vault12. "Previously, to keep our digital money safe, we had to keep our extremely valuable cryptographic backups on pieces of paper and store them in traditional banks. It was ironic. We built Vault12 to be an innovative, convenient solution that replaced this cumbersome process." 

"Security is the lifeblood of industry, commerce and leisure," said Jon Callaghan, co-founder of True Ventures. "As more people use decentralized applications, they will need a way to back up their crypto wallets and exchange accounts. Vault12 provides a simple and natural way to reduce risks and combat the fear of forgetting seed phrases and private keys."

"Today's world relies heavily on our social circle in both our personal lives and our professional lives. That's why we're taking a more social approach to cryptography and entrusting our loved ones to guard our assets," said Blake Comagere, co-founder and COO of Vault12. "Today we're safeguarding crypto. In the future, we plan to safeguard everything from legal documents to house keys and more." 

Sunday, October 27, 2019

Fortanix gets FIPS 140-2 Level 3 certification enabling businesses to update to a more modern encryption platform

Fortanix Inc. announced that the Fortanix Self-Defending Key Management Service (SDKMS) has earned the Federal Information Processing Standard (FIPS) 140-2 Level 3 certification from the National Institute of Standards and Technology (NIST), which is part of the U.S. Department of Commerce. 


This achievement enables businesses to replace legacy encryption technologies, including Hardware Security Modules (HSMs), with the Fortanix SDKMS encryption platform for protecting the most sensitive data in the U.S. Government, technology, financial services and healthcare industries.




SDKMS has been built on HSM-grade security, secures any KMS use case including TDE, storage multi-cloud and blockchain. SDKMS also delivers tokenization, secrets management and HSM; central management, audit and control. It also comes secured with Intel SGX, built for cloud scale/resiliency, SDKMS reduces threats and consolidates costs.​


As part of the certification, Fortanix passed strict government requirements for Level 3 certifications, validating the Fortanix SDKMS cryptographic protections and ability to maintain the confidentiality and integrity of protected information. Customers in the U.S. Government, financial services, healthcare and other regulated industries have specific private data such as passwords and PIN numbers that must be encrypted using FIPS 140-2 Level 3 certified cryptographic modules.



For decades, businesses in highly regulated industries have been locked into HSM appliances that are costly to operate, difficult to scale, and lack the modern RESTful programming interfaces required by application developers to bring new applications to market and migrate them to the public cloud. 


With Fortanix SDKMS, businesses can lower their operating costs up to 70 percent, scale across multi-site and multi-cloud environments, and accelerate application development through modern cryptographic services.

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...