PRTODAY / NewswireToday Free press release distribution service network

Agency / Source: SafeNet, Inc.

Check Ads Availability|e-mail Article
This article was published free of charge. Only PREMIUM Articles are 3rd party Ads-Free!

Latest Breaches Expose PKI’s Greatest Weakness – Encryption Keys - SafeNet’s Experts offer guidelines to re-establishing trust in PKI - SafeNet-Inc.com
Latest Breaches Expose PKI’s Greatest Weakness – Encryption Keys

 

NewswireToday - /newswire/ - Baltimore, MD, United States, 09/22/2011 - SafeNet’s Experts offer guidelines to re-establishing trust in PKI - SafeNet-Inc.com.

   
 


Rank or share this free Newswire Press Release Distribution content. Join the network! Learn How!


Your Banner Ad Here instead - Showing along with ALL Articles covering IT Security/Anti-Spam Announcements

Replace these Affiliate Programs at ANYTIME! Your banner here within the next hour.


 

As a direct result of the recent security breaches impacting organizations that rely on Public Key Infrastructure (PKI) to encrypt and authenticate online communications and transactions, SafeNet, Inc., a worldwide leader in data protection, today issued several security guidelines to better secure PKI-based transactions.

For all the infrastructure advantages and business benefits of PKI, recent breaches clearly indicate that the way in which PKI is implemented may not be as inherently secure as most organizations have mistakenly assumed. What hasn’t been clearly understood is that the private key system used by PKI to encrypt and decrypt messages creates a single and significant point of vulnerability. A recent flurry of breaches involving certificate authorities have exposed this weakness, and have shaken the very foundation of trust that organizations have in PKI.

In order to help enterprises build greater integrity and reliability into their PKI deployments, eliminate unwanted exposure and close security gaps, SafeNet’s cryptographic experts advise the following actions:

1. Know your options for securing keys, weigh the risks, and choose wisely. All recent breaches have had a common theme –private keys and certificates were protected in software, and were left vulnerable. Software-based security has many benefits – it’s portable and offers great flexibility. Software can be copied easily and live in multiple locations at the same time, making the very benefits of software the areas of greatest security risk. A hardware-based security module (HSM) creates the trust anchor that locks the private keys and only allows access to vital information from an authorized source. Similarly, hardware based tokens and cards lock the certificates and avoid software based certificate risks.

2. Don’t assume that because you are working with a certificate authority your infrastructure is secure. If you rely on the certificate authority to authenticate, authorize, and secure application services, understand that the certificate itself is the vital piece within PKI. If the certificate private key is compromised, the entire PKI environment is compromised. Utilize layers of secure cryptography and select hardware-based options when securing your critical processing PKI end points.

3. Plan for the next generation of critical applications. Traditional PKI end points have historically included certificate authorities, registration authorities, SSL servers, and applications servers. These have now expanded to include mission-critical business processing applications, such as the smart grid, financial transactions, digital invoices, code signing, and secure device manufacturing. The nature of advanced PKI applications demands greater diligence, given the risk profile of the applications it enables. It is critical to establish a trust anchor for the protection and issuance of keys and certificates within these vital applications, ensuring that keys cannot be stolen, and the operations/transactions performed by those keys are auditable.

“PKI is many beneficial things, but standalone security isn’t one of them,” said Mark Yakabuski, vice president, product management for SafeNet. “It is important to realize the certificate identity itself is the vital piece within PKI – if the certificate identity is compromised, the PKI environment is compromised. The good news is that critical certificate identities can be secured with the proper hardware-based security mechanisms.”

Yakabuski is available for additional commentary. He can also provide examples of HSMs could have mitigated the damage done by recent security events, including APT attacks on certificate authorities, SSL certificate attacks, device code signing, and even the Stuxnet Worm.

About Hardware Security Modules
HSMs are defined as an anchor of trust, providing protection for applications, transactions, authorizations and information assets by safeguarding the cryptographic keys that are at the heart of any digital identity environment. An HSM can ensure the certificate private keys it protects are maintained in physical hardware, throughout the lifecycle of the private key.

With hardware-based protection, an HSM adds multiple layers of security and protects keys against the threats that software-based servers are susceptible to. For example, an HSM:

1. Encrypts the keys themselves;
2. Ensures that the keys remain within the secure hardware device throughout the key management lifecycle;
3. Ensures that only authorized applications and users can access and use the HSM-protected critical private keys; and
4. Ensures the logging and auditing of the certificate private keys.

HSMs only allow for the copying of keys from hardware to hardware. Keys exist solely in the restricted HSMs, and are under the control of defined custodians, allowing for tracking and auditing assurance of the certificate private keys they create.

About SafeNet, Inc.
Founded in 1983, SafeNet, Inc. (safenet-inc.com) is one of the largest information security companies in the world, and is trusted to protect the most sensitive data for market-leading organizations around the globe. SafeNet’s data-centric approach focuses on the protection of high value information throughout its lifecycle, from the data center to the cloud. More than 25,000 customers across commercial enterprises and government agencies trust SafeNet to protect and control access to sensitive data, manage risk, ensure compliance, and secure virtual and cloud environments.

 
 


Rank or share this free Newswire Press Release Distribution content. Join the network! Learn How!


Your Banner Ad Here instead - Showing along with ALL Articles covering IT Security/Anti-Spam Announcements

Replace these Affiliate Programs at ANYTIME! Your banner here within the next hour.


 

Agency / Source: SafeNet, Inc.

 
 

Availability: All Regions (Including Int'l)

 

Traffic Booster: [/] Quick Newswire Today Visibility Checker

 

Distribution / Indexing: [+] / [Content made possible by PRZOOM / PRTODAY indexing services]

 
 
# # #
 
IT Security Anti-Spam Computer Security - Purchase keywords tags antivirus software firewall spyware removal virus scan computer security IT Security Anti-Spam malware / Banner Ads!.

 
  Your Banner Ad showing on ALL
IT Security/Anti-Spam articles,
CATCH Visitors via Your Competitors Announcements!


Latest Breaches Expose PKI’s Greatest Weakness – Encryption Keys

Non-featured company website links are shown on a random basis
It is OK to republish and/or LINK any newswire for any legitimate media purpose as long as you name Newswire Today and LINK as the source.
 
  For more information, please visit:
Links are available on a random basis for non premium members
|
Contact: SafeNet-Inc.com 
410-931-7500 investor[.]safenet-inc.com
 
Newswire Today - PRZOOM / PRTODAY disclaims any content contained in this article. If you need/wish to contact the company who published the current release, you will need to contact them - NOT us. Issuers of articles are solely responsible for the accuracy of their content. Our complete disclaimer appears here.
IMPORTANT INFORMATION: Issuance, publication or distribution of this press release in certain jurisdictions could be subject to restrictions. The recipient of this press release is responsible for using this press release and the information herein in accordance with the applicable rules and regulations in the particular jurisdiction. This press release does not constitute an offer or an offering to acquire or subscribe for any SafeNet, Inc. securities in any jurisdiction including any other companies listed or named in this release.

IT Security/Anti-Spam via RSS
AddThis press release: Latest Breaches Expose PKI’s Greatest Weakness – Encryption KeysAdd IT Security/Anti-Spam News to My MSNAdd IT Security/Anti-Spam News to My Yahoo!Add NewswireToday IT Security/Anti-Spam Press Release Headline News to Your Google homepage or Google ReaderAdd NewswireToday - PRZOOM Headline News to FeedBurner
Find who Retweet

This article was published free of charge. Only PREMIUM Articles are 3rd party Ads-Free!


Read Latest Articles From SafeNet, Inc. / Company Profile



SafeNet’s Luna EFT Hardware Security Module Achieves PCI HSM Compliance
SafeNet Delivers Industry’s First Licensing and Monetization Solution for Hybrid On-Premise and Cloud-based Software Portfolios
SafeNet to Present at the 2012 All About the Cloud Conference
SafeNet Named to CRN’s 2012 5-Star Partner Programs Guide for Fourth Consecutive Year
SafeNet Thinks Outside the ‘Black Box’ with Industry’s First White Box Cryptography Software Protection Solution
O’Neill Europe Selects SafeNet to Enable Multi-factor Authentication for Mobile Workers
Ciena and SafeNet Join Forces to Protect Data and Reduce Security Breaches in Commercial and Government Networks
SafeNet Deepens Cloud Capabilities with Acquisition of Cryptocard
SafeNet Appoints Mark S. Molina SVP, Chief Legal Officer and Secretary
SafeNet Provides Integration-Ready Key Management for Quantum
SafeNet and ServiceMesh Secure Keys in the Cloud
SafeNet to Present at RSA Conference 2012
Frost & Sullivan Honors SafeNet’s Software Monetization Product Line Strategy
SafeNet Sentinel Cloud Receives 2012 CODiE Award for Best Digital Rights Management Solution
SafeNet Announces Executive Appointments

Reserve This Permanent SPACE

Your LOGO permanently HERE on Newswire Today most visited Page start at $295 per month

 
Sponsored Links


Visit  JobsWare.com

Visit  BizJobs.com










 
  ©2012 Newswire Today — Limelon Advertising, Co.
Home | About | Advertise | Contact | Investors | Sitemap | FRANCAIS
newswire, PR free press releases distribution magazines engine news alert newsroom press room breaking news public relations articles company news alerts blogsIt younews.me newswiredistribution ezine younews.asia bizentrepreneur biznewstoday digital business report market search pr firms agencies reports distri- bution today investor relation successful internet entrepreneur free newswire distribution prtoday.com freenewswiredistribution asianewstoday bizwiretoday USA pr UK today
 
PRTODAY & NewswireTODAY are NOT affiliated with USA TODAY (usatoday.com)